|
265951
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
Race condition in the audit_log_single_execve_arg function in kernel/auditsc.c in the Linux kernel through 4.7 allows local users to bypass intended character-set restrictions or disrupt system-call …
|
CWE-362
Race Condition
|
CVE-2016-6136
|
2024-11-21 11:55 |
2016-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265952
|
6.1 |
MEDIUM
Network
|
debian djangoproject
|
debian_linux django
|
Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, an…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6186
|
2024-11-21 11:55 |
2016-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265953
|
9.8 |
CRITICAL
Network
|
sap
|
hana
|
The multi-tenant database container feature in SAP HANA does not properly encrypt communications, which allows remote attackers to bypass intended access restrictions and possibly have unspecified ot…
|
CWE-284
Improper Access Control
|
CVE-2016-6150
|
2024-11-21 11:55 |
2016-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265954
|
5.5 |
MEDIUM
Local
|
sap
|
hana_sps09
|
SAP HANA SPS09 1.00.091.00.14186593 allows local users to obtain sensitive information by leveraging the EXPORT statement to export files, aka SAP Security Note 2252941.
|
CWE-200
Information Exposure
|
CVE-2016-6149
|
2024-11-21 11:55 |
2016-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265955
|
7.5 |
HIGH
Network
|
sap
|
hana
|
SAP HANA DB 1.00.73.00.389160 allows remote attackers to cause a denial of service (process termination) or execute arbitrary code via vectors related to an IMPORT statement, aka SAP Security Note 22…
|
CWE-20
Improper Input Validation
|
CVE-2016-6148
|
2024-11-21 11:55 |
2016-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265956
|
9.8 |
CRITICAL
Network
|
sap
|
trex
|
An unspecified interface in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands with SIDadm privileges via unspecified vectors, aka SAP Security Note 2234226.
|
CWE-78
OS Command
|
CVE-2016-6147
|
2024-11-21 11:55 |
2016-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265957
|
5.3 |
MEDIUM
Network
|
sap
|
hana_db
|
The SQL interface in SAP HANA DB 1.00.091.00.1418659308 provides different error messages for failed login attempts depending on whether the username exists and is locked when the detailed_error_on_c…
|
CWE-200
Information Exposure
|
CVE-2016-6145
|
2024-11-21 11:55 |
2016-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265958
|
8.1 |
HIGH
Network
|
sap
|
hana
|
The SQL interface in SAP HANA before Revision 102 does not limit the number of login attempts for the SYSTEM user when the password_lock_for_system_user is not supported or is configured as "False," …
|
CWE-284
Improper Access Control
|
CVE-2016-6144
|
2024-11-21 11:55 |
2016-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265959
|
9.8 |
CRITICAL
Network
|
sap
|
trex
|
SAP TREX 7.10 Revision 63 allows remote attackers to write to arbitrary files via vectors related to RFC-Gateway, aka SAP Security Note 2203591.
|
CWE-284
Improper Access Control
|
CVE-2016-6140
|
2024-11-21 11:55 |
2016-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265960
|
9.8 |
CRITICAL
Network
|
sap
|
trex
|
SAP TREX 7.10 Revision 63 allows remote attackers to read arbitrary files via unspecified vectors, aka SAP Security Note 2203591.
|
NVD-CWE-noinfo
|
CVE-2016-6139
|
2024-11-21 11:55 |
2016-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|