|
264701
|
9.8 |
CRITICAL
Network
|
hp
|
network_automation
|
A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x, v9.2x, v10.00, v10.00.01, v10.00.02, v10.10, v10.11, v10.11.01, v10.20 was fou…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-8511
|
2024-11-21 11:59 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264702
|
7.8 |
HIGH
Local
|
apache
|
couchdb
|
The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file permissions of the parent directory and therefore a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-8742
|
2024-11-21 11:59 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264703
|
7.5 |
HIGH
Network
|
openssl debian redhat netapp paloaltonetworks oracle fujitsu
|
openssl debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_server…
|
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote…
|
-
|
CVE-2016-8610
|
2024-11-21 11:59 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264704
|
5.4 |
MEDIUM
Network
|
apache
|
nifi
|
In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not bein…
|
CWE-79
Cross-site Scripting
|
CVE-2016-8748
|
2024-11-21 11:59 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264705
|
6.5 |
MEDIUM
Network
|
apache debian
|
subversion debian_linux
|
Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The a…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-8734
|
2024-11-21 11:59 |
2017-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264706
|
9.8 |
CRITICAL
Network
|
apache
|
openmeetings
|
Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-8736
|
2024-11-21 11:59 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264707
|
5.9 |
MEDIUM
Network
|
apache
|
struts
|
In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overlo…
|
CWE-20
Improper Input Validation
|
CVE-2016-8738
|
2024-11-21 11:59 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264708
|
8.8 |
HIGH
Network
|
apache
|
brooklyn
|
In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site request forgery (CSRF), which could permit a malicious web site to produce a link which, if clicked whilst a user is logg…
|
CWE-352
Origin Validation Error
|
CVE-2016-8737
|
2024-11-21 11:59 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264709
|
8.8 |
HIGH
Network
|
apache
|
brooklyn
|
Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate that SnakeYAML should unmarshal data to a Java type. In the default configuration…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-8744
|
2024-11-21 11:59 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264710
|
7.5 |
HIGH
Network
|
apache
|
atlas
|
Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.
|
CWE-284
Improper Access Control
|
CVE-2016-8752
|
2024-11-21 11:59 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|