|
265551
|
9.8 |
CRITICAL
Network
|
hp
|
arcsight_winc_connector
|
A remote code execution security vulnerability has been identified in all versions of the HP ArcSight WINC Connector prior to v7.3.0.
|
CWE-94
Code Injection
|
CVE-2016-4391
|
2024-11-21 11:52 |
2018-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265552
|
8.8 |
HIGH
Network
|
apache netapp
|
struts oncommand_balance
|
Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. NOTE: this vulnerability exists because …
|
CWE-20
Improper Input Validation
|
CVE-2016-4461
|
2024-11-21 11:52 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265553
|
7.8 |
HIGH
Local
|
apache
|
tika
|
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) sprea…
|
CWE-611
XXE
|
CVE-2016-4434
|
2024-11-21 11:52 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265554
|
8.8 |
HIGH
Network
|
apache
|
ofbiz
|
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Fr…
|
CWE-20
Improper Input Validation
|
CVE-2016-4462
|
2024-11-21 11:52 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265555
|
9.8 |
CRITICAL
Network
|
apache
|
pony_mail
|
Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.
|
CWE-287
Improper Authentication
|
CVE-2016-4460
|
2024-11-21 11:52 |
2017-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265556
|
7.5 |
HIGH
Network
|
gnu
|
gnutls
|
The "GNUTLS_KEYLOGFILE" environment variable in gnutls 3.4.12 allows remote attackers to overwrite and corrupt arbitrary files in the filesystem.
|
CWE-20
Improper Input Validation
|
CVE-2016-4456
|
2024-11-21 11:52 |
2017-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265557
|
8.4 |
HIGH
Network
|
hp
|
helion_openstack_glance
|
The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated users to cause other users to boot into a modified ima…
|
CWE-284
Improper Access Control
|
CVE-2016-4383
|
2024-11-21 11:52 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265558
|
9.8 |
CRITICAL
Network
|
php suse
|
php linux_enterprise_software_development_kit linux_enterprise_module_for_web_scripting
|
/ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to CVE-2015-6833.
|
CWE-416
Use After Free
|
CVE-2016-4473
|
2024-11-21 11:52 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265559
|
8.8 |
HIGH
Network
|
redhat
|
cloudforms
|
ManageIQ in CloudForms before 4.1 allows remote authenticated users to execute arbitrary code.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-4471
|
2024-11-21 11:52 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265560
|
7.5 |
HIGH
Network
|
redhat
|
cloudforms_management_engine
|
CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.
|
CWE-310
Cryptographic Issues
|
CVE-2016-4457
|
2024-11-21 11:52 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|