|
266811
|
7.5 |
HIGH
Network
|
netapp
|
data_ontap
|
NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the S…
|
CWE-254
7PK - Security Features
|
CVE-2016-3400
|
2024-11-21 11:49 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266812
|
7.5 |
HIGH
Network
|
redhat
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to force the u…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2016-3099
|
2024-11-21 11:49 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266813
|
5.5 |
MEDIUM
Local
|
fedoraproject pulpproject
|
fedora pulp
|
server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.
|
CWE-200
Information Exposure
|
CVE-2016-3095
|
2024-11-21 11:49 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266814
|
7.5 |
HIGH
Network
|
pulpproject
|
pulp
|
client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows remote authenticated users to obtain the consumer p…
|
CWE-284
Improper Access Control
|
CVE-2016-3112
|
2024-11-21 11:49 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266815
|
5.5 |
MEDIUM
Local
|
pulpproject
|
pulp
|
pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp consumers in a directory that is world-readable before late…
|
CWE-200
Information Exposure
|
CVE-2016-3111
|
2024-11-21 11:49 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266816
|
7.1 |
HIGH
Local
|
pulpproject
|
pulp
|
The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack.
|
CWE-59
Link Following
|
CVE-2016-3108
|
2024-11-21 11:49 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266817
|
5.5 |
MEDIUM
Local
|
pulpproject
|
pulp
|
The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" directory, which allows local users to gain access to sensitiv…
|
CWE-284
Improper Access Control
|
CVE-2016-3107
|
2024-11-21 11:49 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266818
|
7.5 |
HIGH
Network
|
cloud_foundry
|
diego
|
Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service.
|
CWE-19
Data Processing Errors
|
CVE-2016-3091
|
2024-11-21 11:49 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266819
|
4.3 |
MEDIUM
Network
|
ibm
|
security_access_manager_9.0_firmware
|
IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privileged functionality of the server. IBM X-Force ID: 114714.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3051
|
2024-11-21 11:49 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266820
|
6.5 |
MEDIUM
Network
|
ibm
|
security_access_manager_9.0_firmware
|
IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 114462.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2016-3019
|
2024-11-21 11:49 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|