|
265241
|
5.5 |
MEDIUM
Local
|
apache
|
ambari
|
Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive information via a process listing.
|
CWE-200
Information Exposure
|
CVE-2016-4976
|
2024-11-21 11:53 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265242
|
7.5 |
HIGH
Network
|
openslp
|
openslp
|
The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a large number of crafted packets, which trigge…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-4912
|
2024-11-21 11:53 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265243
|
6.5 |
MEDIUM
Network
|
juniper
|
junos_space
|
XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service.
|
CWE-611
XXE
|
CVE-2016-4931
|
2024-11-21 11:53 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265244
|
6.1 |
MEDIUM
Network
|
juniper
|
junos_space
|
Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2 allows remote attackers to steal sensitive information or perform certain administrative actions.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4930
|
2024-11-21 11:53 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265245
|
8.8 |
HIGH
Network
|
juniper
|
junos_space
|
Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary code as a root user.
|
CWE-77
Command Injection
|
CVE-2016-4929
|
2024-11-21 11:53 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265246
|
8.8 |
HIGH
Network
|
juniper
|
junos_space
|
Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Space.
|
CWE-352
Origin Validation Error
|
CVE-2016-4928
|
2024-11-21 11:53 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265247
|
8.1 |
HIGH
Network
|
juniper
|
junos_space
|
Insufficient validation of SSH keys in Junos Space before 15.2R2 allows man-in-the-middle (MITM) type of attacks while a Space device is communicating with managed devices.
|
CWE-20
Improper Input Validation
|
CVE-2016-4927
|
2024-11-21 11:53 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265248
|
9.8 |
CRITICAL
Network
|
juniper
|
junos_space
|
Insufficient authentication vulnerability in Junos Space before 15.2R2 allows remote network based users with access to Junos Space web interface to perform certain administrative tasks without authe…
|
CWE-287
Improper Authentication
|
CVE-2016-4926
|
2024-11-21 11:53 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265249
|
9.8 |
CRITICAL
Network
|
imagemagick
|
imagemagick
|
The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMagick allows remote attackers to execute arbitrary commands via unspecified vectors.
|
CWE-284
Improper Access Control
|
CVE-2016-5239
|
2024-11-21 11:53 |
2017-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265250
|
7.5 |
HIGH
Network
|
cloudera
|
manager
|
Cloudera Manager 5.5 and earlier allows remote attackers to enumerate user sessions via a request to /api/v11/users/sessions.
|
CWE-200
Information Exposure
|
CVE-2016-4950
|
2024-11-21 11:53 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|