|
267701
|
5.3 |
MEDIUM
Network
|
haproxy
|
haproxy
|
HAProxy statistics in openstack-tripleo-image-elements are non-authenticated over the network.
|
CWE-287
Improper Authentication
|
CVE-2016-2102
|
2024-11-21 11:47 |
2017-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267702
|
7.5 |
HIGH
Network
|
apache
|
http_server
|
In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.
|
CWE-20
Improper Input Validation
|
CVE-2016-2161
|
2024-11-21 11:47 |
2017-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267703
|
9.8 |
CRITICAL
Network
|
arubanetworks
|
clearpass
|
SQL injection vulnerability in ClearPass Policy Manager 6.5.x through 6.5.6 and 6.6.0.
|
CWE-89
SQL Injection
|
CVE-2016-2034
|
2024-11-21 11:47 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267704
|
6.5 |
MEDIUM
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cf-release
|
The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5.19 AND 1.6.x versions prior to 1.6.20 are not cleansing request URL paths when…
|
CWE-20
Improper Input Validation
|
CVE-2016-2165
|
2024-11-21 11:47 |
2017-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267705
|
7.8 |
HIGH
Local
|
lenovo
|
solution_center
|
The backend service process in Lenovo Solution Center (aka LSC) before 3.3.0002 allows local users to gain SYSTEM privileges via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1876
|
2024-11-21 11:47 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267706
|
6.5 |
MEDIUM
Network
|
samba
|
samba
|
Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Attribute Certificate) checksum. A remote, authenticated, attacker can cause the w…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2126
|
2024-11-21 11:47 |
2017-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267707
|
9.8 |
CRITICAL
Network
|
fedoraproject vmware
|
fedora spring_advanced_message_queuing_protocol
|
org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.
|
CWE-20
Improper Input Validation
|
CVE-2016-2173
|
2024-11-21 11:47 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267708
|
5.5 |
MEDIUM
Local
|
samsung
|
galaxy_s6_firmware galaxy_note_3_firmware
|
The getURL function in drivers/secfilter/urlparser.c in secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allow…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-2036
|
2024-11-21 11:47 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267709
|
6.1 |
MEDIUM
Network
|
redhat
|
satellite
|
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the label parameter to admin/BunchDetail.do; (2) the p…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2104
|
2024-11-21 11:47 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267710
|
6.1 |
MEDIUM
Network
|
blackberry
|
blackberry_enterprise_service
|
Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to inject arbitrary web script or HTML via the locale pa…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1915
|
2024-11-21 11:47 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|