|
265481
|
5.4 |
MEDIUM
Network
|
symantec
|
it_management_suite
|
A Cross-Site Scripting (XSS) vulnerability exists in the ITMS workflow process manager console in Symantec IT Management Suite 8.0.
|
CWE-79
Cross-site Scripting
|
CVE-2016-6588
|
2024-11-21 11:56 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265482
|
3.7 |
LOW
Network
|
symantec
|
norton_mobile_security
|
A security bypass vulnerability exists in Symantec Norton Mobile Security for Android before 3.16, which could let a malicious user conduct a man-in-the-middle via specially crafted JavaScript to add…
|
CWE-20
Improper Input Validation
|
CVE-2016-6586
|
2024-11-21 11:56 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265483
|
7.8 |
HIGH
Local
|
symantec
|
vip_access_desktop
|
A code-execution vulnerability exists during startup in jhi.dll and otpiha.dll in Symantec VIP Access Desktop before 2.2.2, which could let local malicious users execute arbitrary code.
|
CWE-426
Untrusted Search Path
|
CVE-2016-6593
|
2024-11-21 11:56 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265484
|
7.1 |
HIGH
Physics
|
symantec
|
norton_app_lock
|
A security bypass vulnerability exists in Symantec Norton App Lock 1.0.3.186 and earlier if application pinning is enabled, which could let a local malicious user bypass security restrictions.
|
CWE-863
Incorrect Authorization
|
CVE-2016-6591
|
2024-11-21 11:56 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265485
|
7.8 |
HIGH
Local
|
symantec
|
it_management_suite ghost_solution_suite endpoint_encryption encryption_desktop
|
A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Su…
|
CWE-269
Improper Privilege Management
|
CVE-2016-6590
|
2024-11-21 11:56 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265486
|
6.5 |
MEDIUM
Network
|
symantec
|
it_management_suite
|
A Denial of Service vulnerability exists in the ITMS workflow process manager login window in Symantec IT Management Suite 8.0.
|
CWE-20
Improper Input Validation
|
CVE-2016-6589
|
2024-11-21 11:56 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265487
|
8.8 |
HIGH
Network
|
filecloud
|
filecloud
|
CodeLathe FileCloud, version 13.0.0.32841 and earlier, contains a global cross-site request forgery (CSRF) vulnerability. An attacker can perform actions with the same permissions as a victim user, p…
|
CWE-352
Origin Validation Error
|
CVE-2016-6578
|
2024-11-21 11:56 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265488
|
9.8 |
CRITICAL
Network
|
sungardas
|
etrakit3
|
The valueAsString parameter inside the JSON payload contained by the ucLogin_txtLoginId_ClientStat POST parameter of the Sungard eTRAKiT3 software version 3.2.1.17 is not properly validated. An unaut…
|
CWE-89
SQL Injection
|
CVE-2016-6566
|
2024-11-21 11:56 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265489
|
7.5 |
HIGH
Network
|
imagely
|
nextgen_gallery
|
The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user t…
|
CWE-20
Improper Input Validation
|
CVE-2016-6565
|
2024-11-21 11:56 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265490
|
7.5 |
HIGH
Adjacent
|
mitel
|
shortel_mobility_client
|
On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificates provided by HTTPS connections, which means that an attacker in the position …
|
CWE-295
Improper Certificate Validation
|
CVE-2016-6562
|
2024-11-21 11:56 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|