|
266931
|
9.8 |
CRITICAL
Network
|
rest\/json_project
|
rest\/json
|
The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
|
CWE-863
Incorrect Authorization
|
CVE-2016-20002
|
2024-11-21 11:47 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266932
|
9.8 |
CRITICAL
Network
|
rest\/json_project
|
rest\/json
|
The REST/JSON project 7.x-1.x for Drupal allows node access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
|
CWE-863
Incorrect Authorization
|
CVE-2016-20001
|
2024-11-21 11:47 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266933
|
7.5 |
HIGH
Network
|
rest\/json_project
|
rest\/json
|
The REST/JSON project 7.x-1.x for Drupal allows session enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
|
NVD-CWE-Other
|
CVE-2016-20008
|
2024-11-21 11:47 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266934
|
7.5 |
HIGH
Network
|
rest\/json_project
|
rest\/json
|
The REST/JSON project 7.x-1.x for Drupal allows session name guessing, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
|
CWE-613
Insufficient Session Expiration
|
CVE-2016-20007
|
2024-11-21 11:47 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266935
|
7.5 |
HIGH
Network
|
rest\/json_project
|
rest\/json
|
The REST/JSON project 7.x-1.x for Drupal allows blockage of user logins, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
|
NVD-CWE-noinfo
|
CVE-2016-20006
|
2024-11-21 11:47 |
2021-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266936
|
7.5 |
HIGH
Network
|
arubanetworks
|
arubaos aruba_instant airwave
|
A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain…
|
CWE-287
Improper Authentication
|
CVE-2016-2032
|
2024-11-21 11:47 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266937
|
9.8 |
CRITICAL
Network
|
arubanetworks siemens
|
arubaos aruba_instant airwave scalance_w1750d_firmware
|
Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a maliciou…
|
CWE-20
Improper Input Validation
|
CVE-2016-2031
|
2024-11-21 11:47 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266938
|
8.8 |
HIGH
Network
|
samba
|
samba
|
A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses…
|
-
|
CVE-2016-2123
|
2024-11-21 11:47 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266939
|
6.5 |
MEDIUM
Network
|
powerdns debian
|
authoritative debian_linux
|
An issue has been found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 allowing an authorized user to crash the server by inserting a specially crafted record in a zone u…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-2120
|
2024-11-21 11:47 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266940
|
6.5 |
MEDIUM
Adjacent
|
samba redhat
|
samba enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_server_eus gluster_st…
|
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subse…
|
CWE-20
Improper Input Validation
|
CVE-2016-2125
|
2024-11-21 11:47 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|