|
265671
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
IBM Connections 4.0, 4.5, 5.0, and 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5932
|
2024-11-21 11:55 |
2017-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265672
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_requirements_composer rational_doors_next_generation
|
IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6055
|
2024-11-21 11:55 |
2017-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265673
|
6.1 |
MEDIUM
Network
|
ibm
|
inotes
|
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5883
|
2024-11-21 11:55 |
2017-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265674
|
5.3 |
MEDIUM
Local
|
f5
|
big-ip_local_traffic_manager big-ip_websafe big-ip_global_traffic_manager big-ip_advanced_firewall_manager big-ip_link_controller big-ip_analytics big-ip_access_policy_manager bi…
|
F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext to /var/log/restjavad.0.log. It may all…
|
CWE-200
Information Exposure
|
CVE-2016-6249
|
2024-11-21 11:55 |
2017-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265675
|
7.8 |
HIGH
Local
|
shadow_project
|
shadow
|
Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-6252
|
2024-11-21 11:55 |
2017-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265676
|
6.1 |
MEDIUM
Network
|
alinto
|
sogo
|
Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Desc…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6191
|
2024-11-21 11:55 |
2017-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265677
|
4.3 |
MEDIUM
Network
|
inverse-inc
|
sogo
|
SOGo before 2.3.12 and 3.x before 3.1.1 does not restrict access to the UID and DTSTAMP attributes, which allows remote authenticated users to obtain sensitive information about appointments with the…
|
CWE-200
Information Exposure
|
CVE-2016-6190
|
2024-11-21 11:55 |
2017-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265678
|
4.3 |
MEDIUM
Network
|
alinto
|
sogo
|
Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds.
|
CWE-184
Incomplete Blacklist
|
CVE-2016-6189
|
2024-11-21 11:55 |
2017-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265679
|
9.8 |
CRITICAL
Network
|
fedoraproject zend
|
fedora zend_framework
|
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pa…
|
CWE-89
SQL Injection
|
CVE-2016-6233
|
2024-11-21 11:55 |
2017-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265680
|
6.1 |
MEDIUM
Network
|
ibm
|
resilient
|
IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality …
|
CWE-79
Cross-site Scripting
|
CVE-2016-6062
|
2024-11-21 11:55 |
2017-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|