|
265841
|
7.8 |
HIGH
Local
|
apache
|
tomcat
|
The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which all…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6325
|
2024-11-21 11:55 |
2016-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265842
|
7.5 |
HIGH
Network
|
gnu opensuse fedoraproject
|
glibc opensuse fedora
|
The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-depe…
|
CWE-284
Improper Access Control
|
CVE-2016-6323
|
2024-11-21 11:55 |
2016-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265843
|
7.5 |
HIGH
Network
|
citrix
|
license_server license_server_vpx
|
The lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) before 2015 SP5 and 2016 before R1 SP1, as used by Citrix License Server for Windows before 11.14.0.1 and Citrix License …
|
NVD-CWE-noinfo
|
CVE-2016-6273
|
2024-11-21 11:55 |
2016-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265844
|
6.1 |
MEDIUM
Network
|
ibm
|
sterling_secure_proxy
|
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 does not enable the HSTS protection mechanism, which makes it easier for remot…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6027
|
2024-11-21 11:55 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265845
|
5.3 |
MEDIUM
Adjacent
|
ibm
|
sterling_secure_proxy
|
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle attackers to obtain sensitive information via an HTTP…
|
CWE-200
Information Exposure
|
CVE-2016-6026
|
2024-11-21 11:55 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265846
|
5.9 |
MEDIUM
Local
|
ibm
|
sterling_secure_proxy
|
The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to obtain access by leveraging an unattended workstati…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6025
|
2024-11-21 11:55 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265847
|
7.5 |
HIGH
Network
|
ibm
|
sterling_secure_proxy
|
Directory traversal vulnerability in the Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attackers to read arbitrary…
|
CWE-22
Path Traversal
|
CVE-2016-6023
|
2024-11-21 11:55 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265848
|
7.5 |
HIGH
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4 allows remote authenticated users to execute arbi…
|
CWE-284
Improper Access Control
|
CVE-2016-5983
|
2024-11-21 11:55 |
2016-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265849
|
5.4 |
MEDIUM
Network
|
ibm
|
business_process_manager
|
Cross-site scripting (XSS) vulnerability in a test page in IBM Business Process Manager Advanced 8.5.6.0 through 8.5.7.0 before cumulative fix 2016.09 allows remote authenticated users to inject arbi…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5901
|
2024-11-21 11:55 |
2016-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265850
|
5.4 |
MEDIUM
Network
|
ibm
|
multi-enterprise_integration_gateway b2b_advanced_communications
|
Cross-site scripting (XSS) vulnerability in IBM 10x, as used in Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications before 1.0.0.5_2, allows remote authenticated …
|
CWE-79
Cross-site Scripting
|
CVE-2016-5892
|
2024-11-21 11:55 |
2016-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|