|
265171
|
5.3 |
MEDIUM
Network
|
bmc
|
server_automation
|
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization checks and make an RPC call via unspecified vecto…
|
CWE-285
Improper Authorization
|
CVE-2016-5063
|
2024-11-21 11:53 |
2017-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265172
|
9.8 |
CRITICAL
Network
|
pivotal_software
|
cloud_foundry_elastic_runtime cloud_foundry
|
The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers to obtain sensitive user credential information via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2016-5006
|
2024-11-21 11:53 |
2017-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265173
|
5.9 |
MEDIUM
Network
|
pivotal_software
|
cloud_foundry_uaa cloud_foundry cloud_foundry_elastic_runtime cloud_foundry_uaa-release
|
Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1…
|
CWE-295
Improper Certificate Validation
|
CVE-2016-5016
|
2024-11-21 11:53 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265174
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Skia, as used in Google Chrome before 50.0.2661.94, allows remote attackers to bypass the Same Origin Policy and obtain sensitive information.
|
CWE-346
Origin Validation Error
|
CVE-2016-5168
|
2024-11-21 11:53 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265175
|
7.8 |
HIGH
Local
|
securebrain
|
phishwall_client
|
Untrusted search path vulnerability in the installer of PhishWall Client Internet Explorer before 3.7.8.2.
|
CWE-426
Untrusted Search Path
|
CVE-2016-4846
|
2024-11-21 11:53 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265176
|
4.3 |
MEDIUM
Network
|
cybozu
|
mailwise
|
Cybozu Mailwise before 5.4.0 allows remote attackers to inject arbitrary email headers.
|
CWE-20
Improper Input Validation
|
CVE-2016-4841
|
2024-11-21 11:53 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265177
|
5.9 |
MEDIUM
Network
|
toshiba
|
coordinate_plus
|
Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2016-4840
|
2024-11-21 11:53 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265178
|
5.9 |
MEDIUM
Network
|
aeon
|
waon
|
WAON "Service Application" for Android 1.4.1 and earlier does not verify SSL certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2016-4832
|
2024-11-21 11:53 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265179
|
5.9 |
MEDIUM
Network
|
akindo-sushiro
|
sushiro
|
Sushiro App for iOS 2.1.16 and earlier and Sushiro App for Android 2.1.16.1 and earlier do not verify SSL certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2016-4830
|
2024-11-21 11:53 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265180
|
5.9 |
MEDIUM
Network
|
dmm
|
ppv_play_player
|
DMM Movie Player App for Android before 1.2.1, and DMM Movie Player App for iPhone/iPad before 2.1.3 does not verify SSL certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2016-4829
|
2024-11-21 11:53 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|