|
267931
|
5.3 |
MEDIUM
Network
|
rubyonrails
|
ruby_on_rails rails
|
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary files by leveraging an application's unrestricted u…
|
CWE-22
Path Traversal
|
CVE-2016-2097
|
2024-11-21 11:47 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267932
|
7.5 |
HIGH
Network
|
nodejs fedoraproject
|
node.js fedora
|
Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.
|
CWE-20
Improper Input Validation
|
CVE-2016-2086
|
2024-11-21 11:47 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267933
|
9.8 |
CRITICAL
Network
|
hp
|
asset_manager asset_manager_cloudsystem_chargeback
|
HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache C…
|
CWE-19
Data Processing Errors
|
CVE-2016-2000
|
2024-11-21 11:47 |
2016-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267934
|
5.5 |
MEDIUM
Local
|
apple
|
ibooks_author
|
Apple iBooks Author before 2.4.1 allows remote attackers to read arbitrary files via an iBooks Author file containing an XML external entity declaration in conjunction with an entity reference, relat…
|
NVD-CWE-Other
|
CVE-2016-1789
|
2024-11-21 11:47 |
2016-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267935
|
6.2 |
MEDIUM
Local
|
apple
|
iphone_os
|
The XPC Services API in LaunchServices in Apple iOS before 9.3 allows attackers to bypass intended event-handler restrictions and modify an arbitrary app's events via a crafted app.
|
CWE-284
Improper Access Control
|
CVE-2016-1760
|
2024-11-21 11:47 |
2016-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267936
|
5.9 |
MEDIUM
Network
|
apple
|
watchos iphone_os mac_os_x
|
Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which allows remote attackers to read message attachmen…
|
CWE-310
Cryptographic Issues
|
CVE-2016-1788
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267937
|
5.3 |
MEDIUM
Network
|
apple
|
mac_os_x_server
|
Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2016-1787
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267938
|
5.4 |
MEDIUM
Network
|
apple
|
iphone_os safari
|
The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status code, which allows remote attackers to spoof the …
|
CWE-200
Information Exposure
|
CVE-2016-1786
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267939
|
6.5 |
MEDIUM
Network
|
apple
|
iphone_os safari
|
The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Or…
|
CWE-200
Information Exposure
|
CVE-2016-1785
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267940
|
6.5 |
MEDIUM
Network
|
apple
|
iphone_os tvos safari
|
The History implementation in WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to cause a denial of service (resource consumption and application crash) …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-1784
|
2024-11-21 11:47 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|