|
265191
|
8.8 |
HIGH
Network
|
apache
|
hadoop
|
In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6811
|
2024-11-21 11:56 |
2017-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265192
|
7.5 |
HIGH
Network
|
cloudera
|
cdh
|
Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.
|
CWE-284
Improper Access Control
|
CVE-2016-6605
|
2024-11-21 11:56 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265193
|
7.5 |
HIGH
Network
|
opmantek
|
network_management_information_system
|
Opmantek NMIS before 4.3.7c has command injection via man, finger, ping, trace, and nslookup in the tools.pl CGI script. Versions before 8.5.12G might be affected in non-default configurations.
|
CWE-77
Command Injection
|
CVE-2016-6534
|
2024-11-21 11:56 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265194
|
5.9 |
MEDIUM
Network
|
apache
|
ignite
|
Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.
|
CWE-611
XXE
|
CVE-2016-6805
|
2024-11-21 11:56 |
2017-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265195
|
9.8 |
CRITICAL
Network
|
apache
|
tika nutch
|
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-6809
|
2024-11-21 11:56 |
2017-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265196
|
7.5 |
HIGH
Network
|
illumos
|
illumos
|
illumos smbsrv NULL pointer dereference allows system crash.
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-6561
|
2024-11-21 11:56 |
2017-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265197
|
8.6 |
HIGH
Network
|
illumos
|
illumos
|
illumos osnet-incorporation bcopy() and bzero() implementations make signed instead of unsigned comparisons allowing a system crash.
|
CWE-20
Improper Input Validation
|
CVE-2016-6560
|
2024-11-21 11:56 |
2017-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265198
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite_backend documentconverter-api office_web open-xchange_appsuite_frontend
|
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 befor…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6846
|
2024-11-21 11:56 |
2017-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265199
|
9.8 |
CRITICAL
Network
|
apache
|
ambari
|
Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying system. Such operations …
|
CWE-284
Improper Access Control
|
CVE-2016-6807
|
2024-11-21 11:56 |
2017-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265200
|
7.5 |
HIGH
Network
|
emc
|
recoverpoint_for_virtual_machines recoverpoint
|
EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may potentially be exploited by malicious users to comp…
|
CWE-200
Information Exposure
|
CVE-2016-6650
|
2024-11-21 11:56 |
2017-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|