|
266971
|
7.5 |
HIGH
Network
|
redhat fedoraproject
|
jboss_enterprise_application_platform jboss_enterprise_web_server fedora
|
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters …
|
CWE-20
Improper Input Validation
|
CVE-2016-3110
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266972
|
6.8 |
MEDIUM
Network
|
ibm
|
security_privileged_identity_manager_virtual_appliance
|
IBM WebSphere Application Server (WAS) Liberty, as used in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8, allows remote authenticated users to redirect users…
|
CWE-601
Open Redirect
|
CVE-2016-3040
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266973
|
8.8 |
HIGH
Network
|
ibm
|
connections
|
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to hijack the authentication of arbitrary …
|
CWE-352
Origin Validation Error
|
CVE-2016-3007
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266974
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3006
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266975
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3003
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266976
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3001
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266977
|
4.3 |
MEDIUM
Network
|
ibm
|
connections
|
The help service in IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to cause a denial of service (service degradation) via a crafted URL.
|
CWE-20
Improper Input Validation
|
CVE-2016-3000
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266978
|
6.5 |
MEDIUM
Network
|
ibm
|
connections
|
IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unspecified brute-force attack.
|
CWE-200
Information Exposure
|
CVE-2016-2999
|
2024-11-21 11:49 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266979
|
7.8 |
HIGH
Local
|
microsoft
|
excel excel_viewer office_compatibility_pack
|
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3381
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266980
|
6.1 |
MEDIUM
Network
|
microsoft
|
exchange_server
|
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2016 Cumulative Update 1 and 2 allows remote attackers to inject arbitrary web script or HTML via a meeting-invitation request, a…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3379
|
2024-11-21 11:49 |
2016-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|