|
264361
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute ar…
|
CWE-89
SQL Injection
|
CVE-2016-9019
|
2024-11-21 12:00 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264362
|
9.8 |
CRITICAL
Network
|
libupnp_project debian
|
libupnp debian_linux
|
Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-8863
|
2024-11-21 12:00 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264363
|
7.5 |
HIGH
Network
|
ca
|
unified_infrastructure_management
|
Directory traversal vulnerability in diag.jsp file in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) 8.4 SP1 and earlier and CA Unified Infrastructure Management Snap (formerly CA…
|
CWE-22
Path Traversal
|
CVE-2016-9164
|
2024-11-21 12:00 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264364
|
6.1 |
MEDIUM
Network
|
ca
|
service_desk_manager
|
Cross-site scripting (XSS) vulnerability in CA Service Desk Manager (formerly CA Service Desk) 12.9 and 14.1 allows remote attackers to inject arbitrary web script or HTML via the QBE.EQ.REF_NUM para…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9148
|
2024-11-21 12:00 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264365
|
5.4 |
MEDIUM
Network
|
tenable
|
log_correlation_engine
|
Cross-site scripting (XSS) vulnerability in Tenable Log Correlation Engine (aka LCE) before 4.8.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-9261
|
2024-11-21 12:00 |
2017-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264366
|
5.4 |
MEDIUM
Network
|
tenable
|
nessus
|
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-9259
|
2024-11-21 12:00 |
2017-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264367
|
3.1 |
LOW
Network
|
ibm
|
websphere_mq
|
IBM WebSphere MQ 8.0 could allow an authenticated user with authority to create a cluster object to cause a denial of service to MQ clustering. IBM Reference #: 1998647.
|
CWE-264 CWE-20
Permissions, Privileges, and Access Controls Improper Input Validation
|
CVE-2016-9009
|
2024-11-21 12:00 |
2017-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264368
|
7.2 |
HIGH
Network
|
ibm
|
tivoli_storage_manager
|
IBM Tivoli Storage Manager Server 7.1 could allow an authenticated user with TSM administrator privileges to cause a buffer overflow using a specially crafted SQL query and execute arbitrary code on …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-8998
|
2024-11-21 12:00 |
2017-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264369
|
8.1 |
HIGH
Network
|
ibm
|
rational_rhapsody_design_manager
|
IBM Rhapsody DM 4.0, 5.0 and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerabil…
|
CWE-611
XXE
|
CVE-2016-8974
|
2024-11-21 12:00 |
2017-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264370
|
6.5 |
MEDIUM
Network
|
ibm
|
websphere_mq
|
IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using specially crafted HTTP requests. IBM Reference #: 1998648.
|
CWE-284
Improper Access Control
|
CVE-2016-8986
|
2024-11-21 12:00 |
2017-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|