|
267171
|
7.5 |
HIGH
Network
|
apache
|
openmeetings
|
The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the Java URL class without checking the specified pro…
|
CWE-200
Information Exposure
|
CVE-2016-2164
|
2024-11-21 11:47 |
2016-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267172
|
6.1 |
MEDIUM
Network
|
apache
|
openmeetings
|
Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the event description when creating an event.
|
CWE-79
Cross-site Scripting
|
CVE-2016-2163
|
2024-11-21 11:47 |
2016-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267173
|
7.3 |
HIGH
Network
|
debian rubyonrails
|
debian_linux ruby_on_rails rails
|
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of t…
|
CWE-20
Improper Input Validation
|
CVE-2016-2098
|
2024-11-21 11:47 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267174
|
5.3 |
MEDIUM
Network
|
rubyonrails
|
ruby_on_rails rails
|
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary files by leveraging an application's unrestricted u…
|
CWE-22
Path Traversal
|
CVE-2016-2097
|
2024-11-21 11:47 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267175
|
7.5 |
HIGH
Network
|
nodejs fedoraproject
|
node.js fedora
|
Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.
|
CWE-20
Improper Input Validation
|
CVE-2016-2086
|
2024-11-21 11:47 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267176
|
9.8 |
CRITICAL
Network
|
hp
|
asset_manager asset_manager_cloudsystem_chargeback
|
HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache C…
|
CWE-19
Data Processing Errors
|
CVE-2016-2000
|
2024-11-21 11:47 |
2016-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267177
|
5.5 |
MEDIUM
Local
|
apple
|
ibooks_author
|
Apple iBooks Author before 2.4.1 allows remote attackers to read arbitrary files via an iBooks Author file containing an XML external entity declaration in conjunction with an entity reference, relat…
|
NVD-CWE-Other
|
CVE-2016-1789
|
2024-11-21 11:47 |
2016-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267178
|
6.2 |
MEDIUM
Local
|
apple
|
iphone_os
|
The XPC Services API in LaunchServices in Apple iOS before 9.3 allows attackers to bypass intended event-handler restrictions and modify an arbitrary app's events via a crafted app.
|
CWE-284
Improper Access Control
|
CVE-2016-1760
|
2024-11-21 11:47 |
2016-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267179
|
5.9 |
MEDIUM
Network
|
apple
|
watchos iphone_os mac_os_x
|
Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which allows remote attackers to read message attachmen…
|
CWE-310
Cryptographic Issues
|
CVE-2016-1788
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267180
|
5.3 |
MEDIUM
Network
|
apple
|
mac_os_x_server
|
Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2016-1787
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|