|
265131
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to delete other operational administrators' MultiReport filters via unspecified vectors.
|
CWE-284
Improper Access Control
|
CVE-2016-4910
|
2024-11-21 11:53 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265132
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site request forgery (CSRF) vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to hijack the authentication of a logged in user to force a logout via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4909
|
2024-11-21 11:53 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265133
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to alter or delete another user's private RSS settings via unspecified vectors.
|
CWE-284
Improper Access Control
|
CVE-2016-4908
|
2024-11-21 11:53 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265134
|
8.8 |
HIGH
Network
|
cybozu
|
garoon
|
Cybozu Garoon 3.0.0 to 4.2.2 allow remote attackers to obtain CSRF tokens via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2016-4907
|
2024-11-21 11:53 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265135
|
6.1 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to inject arbitrary web script or HTML via "Messages" function of Cybozu Garoon Keitai.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4906
|
2024-11-21 11:53 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265136
|
7.8 |
HIGH
Local
|
jpki
|
the_public_certification_service_for_individuals the_public_certification_service_for_individuals_for_windows_vista the_public_certification_service_for_individuals_for_windows_7
|
Untrusted search path vulnerability in The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.0.1 and earlier, The Public Certification Service for…
|
CWE-426
Untrusted Search Path
|
CVE-2016-4902
|
2024-11-21 11:53 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265137
|
7.5 |
HIGH
Network
|
redhat
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstat…
|
CWE-200
Information Exposure
|
CVE-2016-4992
|
2024-11-21 11:53 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265138
|
7.8 |
HIGH
Local
|
gnu
|
libssp
|
Binaries compiled against targets that use the libssp library in GCC for stack smashing protection (SSP) might allow local users to perform buffer overflow attacks by leveraging lack of the Object Si…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4973
|
2024-11-21 11:53 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265139
|
6.5 |
MEDIUM
Network
|
apache
|
ws-xmlrpc
|
The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing a large file contain…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-5004
|
2024-11-21 11:53 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265140
|
8.8 |
HIGH
Network
|
pivotal
|
spring_security_oauth
|
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabl…
|
CWE-19
Data Processing Errors
|
CVE-2016-4977
|
2024-11-21 11:53 |
2017-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|