|
265791
|
5.4 |
MEDIUM
Network
|
ibm
|
inotes domino
|
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5880
|
2024-11-21 11:55 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265792
|
5.9 |
MEDIUM
Network
|
openvpn
|
openvpn
|
OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-ov…
|
CWE-310 CWE-200
Cryptographic Issues Information Exposure
|
CVE-2016-6329
|
2024-11-21 11:55 |
2017-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265793
|
6.1 |
MEDIUM
Network
|
atlassian
|
jira
|
Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6285
|
2024-11-21 11:55 |
2017-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265794
|
8.8 |
HIGH
Network
|
trendmicro
|
virtual_mobile_infrastructure
|
The handle_certificate function in /vmi/manager/engine/management/commands/apns_worker.py in Trend Micro Virtual Mobile Infrastructure before 5.1 allows remote authenticated users to execute arbitrar…
|
CWE-77
Command Injection
|
CVE-2016-6270
|
2024-11-21 11:55 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265795
|
9.1 |
CRITICAL
Network
|
trendmicro
|
smart_protection_server
|
Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allow remote attackers to read and delete a…
|
CWE-22
Path Traversal
|
CVE-2016-6269
|
2024-11-21 11:55 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265796
|
7.8 |
HIGH
Local
|
trendmicro
|
smart_protection_server
|
Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows local webserv users to execute arbitrary code with root privileges via a Trojan hors…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6268
|
2024-11-21 11:55 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265797
|
8.8 |
HIGH
Network
|
trendmicro
|
smart_protection_server
|
SnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated users to execute arbitrary commands via shell meta…
|
CWE-20
Improper Input Validation
|
CVE-2016-6267
|
2024-11-21 11:55 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265798
|
8.8 |
HIGH
Network
|
trendmicro
|
smart_protection_server
|
ccca_ajaxhandler.php in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated users to execute arbitrary commands via…
|
CWE-20
Improper Input Validation
|
CVE-2016-6266
|
2024-11-21 11:55 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265799
|
7.8 |
HIGH
Local
|
putty
|
putty
|
Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) UxTheme.dll or (2) ntmarta.dll f…
|
CWE-426
Untrusted Search Path
|
CVE-2016-6167
|
2024-11-21 11:55 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265800
|
7.5 |
HIGH
Network
|
uclibc uclibc-ng_project
|
uclibc uclibc-ng
|
Integer signedness error in libc/string/arm/memset.S in uClibc and uClibc-ng before 1.0.16 allows context-dependent attackers to cause a denial of service (crash) via a negative length value to the m…
|
NVD-CWE-Other
|
CVE-2016-6264
|
2024-11-21 11:55 |
2017-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|