|
266851
|
5.5 |
MEDIUM
Local
|
uclouvain
|
openjpeg
|
The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg2000 file.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-3183
|
2024-11-21 11:49 |
2017-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266852
|
5.4 |
MEDIUM
Network
|
ibm
|
biginsights
|
IBM Infosphere BigInsights is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2992
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266853
|
7.5 |
HIGH
Network
|
ibm
|
urbancode_deploy
|
IBM UrbanCode Deploy could allow an authenticated attacker with special permissions to craft a script on the server in a way that will cause processes to run on a remote UCD agent machine.
|
CWE-284
Improper Access Control
|
CVE-2016-2942
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266854
|
5.5 |
MEDIUM
Local
|
ibm
|
urbancode_deploy
|
IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including passwords that could be read by a local user.
|
CWE-200
Information Exposure
|
CVE-2016-2941
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266855
|
5.4 |
MEDIUM
Network
|
ibm
|
biginsights
|
IBM Infosphere BigInsights is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted UR…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2924
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266856
|
7.8 |
HIGH
Local
|
ibm
|
aix
|
IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3053
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266857
|
2.7 |
LOW
Network
|
ibm
|
security_access_manager_for_web_8.0_firmware security_access_manager_for_mobile security_access_manager_9.0_firmware
|
IBM Security Access Manager for Web is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements which could allow the attacker to view information in the back-end da…
|
CWE-89
SQL Injection
|
CVE-2016-3046
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266858
|
3.7 |
LOW
Network
|
ibm
|
security_access_manager security_access_manager_for_mobile security_access_manager_for_web
|
IBM Security Access Manager for Web stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer he…
|
CWE-200
Information Exposure
|
CVE-2016-3045
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266859
|
5.9 |
MEDIUM
Network
|
ibm
|
security_access_manager_for_web_7.0_firmware security_access_manager_for_web_8.0_firmware security_access_manager_for_mobile security_access_manager_9.0_firmware
|
IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit t…
|
CWE-200
Information Exposure
|
CVE-2016-3043
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266860
|
5.3 |
MEDIUM
Network
|
ibm
|
security_appscan_source
|
IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server.
|
CWE-200
Information Exposure
|
CVE-2016-3035
|
2024-11-21 11:49 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|