|
265251
|
7.5 |
HIGH
Network
|
cloudera
|
manager
|
Cloudera Manager 5.5 and earlier allows remote attackers to obtain sensitive information via a (1) stderr.log or (2) stdout.log value in the filename parameter to /cmf/process/<process_id>/logs.
|
CWE-200
Information Exposure
|
CVE-2016-4949
|
2024-11-21 11:53 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265252
|
6.1 |
MEDIUM
Network
|
cloudera
|
manager
|
Multiple cross-site scripting (XSS) vulnerabilities in Cloudera Manager 5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Template Name field when renaming a t…
|
CWE-79
Cross-site Scripting
|
CVE-2016-4948
|
2024-11-21 11:53 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265253
|
5.3 |
MEDIUM
Network
|
cloudera
|
hue
|
Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete.
|
CWE-200
Information Exposure
|
CVE-2016-4947
|
2024-11-21 11:53 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265254
|
6.1 |
MEDIUM
Network
|
cloudera
|
hue
|
Multiple cross-site scripting (XSS) vulnerabilities in Cloudera HUE 3.9.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) First name or (2) Last name field in th…
|
CWE-79
Cross-site Scripting
|
CVE-2016-4946
|
2024-11-21 11:53 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265255
|
5.5 |
MEDIUM
Local
|
graphicsmagick
|
graphicsmagick
|
The DrawDashPolygon function in magick/render.c in GraphicsMagick before 1.3.24 and the SVG renderer in ImageMagick allow remote attackers to cause a denial of service (infinite loop) by converting a…
|
CWE-20
Improper Input Validation
|
CVE-2016-5240
|
2024-11-21 11:53 |
2017-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265256
|
5.5 |
MEDIUM
Local
|
libdwarf_project
|
libdwarf
|
dwarf_form.c in libdwarf 20160115 allows remote attackers to cause a denial of service (crash) via a crafted elf file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-5027
|
2024-11-21 11:53 |
2017-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265257
|
7.5 |
HIGH
Network
|
libdwarf_project
|
libdwarf
|
The WRITE_UNALIGNED function in dwarf_elf_access.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via a crafted DWARF section.
|
CWE-787
Out-of-bounds Write
|
CVE-2016-5044
|
2024-11-21 11:53 |
2017-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265258
|
7.5 |
HIGH
Network
|
libdwarf_project
|
libdwarf
|
The dwarf_dealloc function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted DWARF section.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-5043
|
2024-11-21 11:53 |
2017-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265259
|
7.5 |
HIGH
Network
|
libdwarf_project
|
libdwarf
|
The dwarf_get_aranges_list function in libdwarf before 20160923 allows remote attackers to cause a denial of service (infinite loop and crash) via a crafted DWARF section.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2016-5042
|
2024-11-21 11:53 |
2017-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265260
|
7.5 |
HIGH
Network
|
libdwarf_project
|
libdwarf
|
libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a large length value in a compilation unit header.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-5040
|
2024-11-21 11:53 |
2017-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|