|
265831
|
5.9 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform
|
Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via…
|
CWE-399
Resource Management Errors
|
CVE-2016-7046
|
2024-11-21 11:57 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265832
|
6.5 |
MEDIUM
Network
|
libgd opensuse
|
libgd leap opensuse
|
The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA image.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-6905
|
2024-11-21 11:57 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265833
|
9.8 |
CRITICAL
Network
|
adodb_project fedoraproject
|
adodb fedora
|
The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.
|
CWE-89
SQL Injection
|
CVE-2016-7405
|
2024-11-21 11:57 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265834
|
7.5 |
HIGH
Network
|
canonical djangoproject debian
|
ubuntu_linux django debian_linux
|
The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting …
|
CWE-254
7PK - Security Features
|
CVE-2016-7401
|
2024-11-21 11:57 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265835
|
7.5 |
HIGH
Network
|
redhat ceph_project
|
ceph_storage ceph
|
The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.
|
CWE-200 CWE-254
Information Exposure 7PK - Security Features
|
CVE-2016-7031
|
2024-11-21 11:57 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265836
|
4.4 |
MEDIUM
Local
|
sophos
|
unified_threat_management_software
|
The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the SMTP user settings in t…
|
CWE-200
Information Exposure
|
CVE-2016-7397
|
2024-11-21 11:57 |
2016-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265837
|
4.0 |
MEDIUM
Network
|
siemens
|
scalance_m-800_firmware scalance_s615_firmware
|
The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4.02 does not set the secure flag for the session cookie in an https session, which makes it easier for remot…
|
CWE-200
Information Exposure
|
CVE-2016-7090
|
2024-11-21 11:57 |
2016-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265838
|
8.1 |
HIGH
Network
|
microsoft
|
azure_active_directory_passport
|
The Microsoft Azure Active Directory Passport (aka Passport-Azure-AD) library 1.x before 1.4.6 and 2.x before 2.0.1 for Node.js does not recognize the validateIssuer setting, which allows remote atta…
|
CWE-287
Improper Authentication
|
CVE-2016-7191
|
2024-11-21 11:57 |
2016-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265839
|
7.5 |
HIGH
Network
|
irssi debian canonical
|
irssi debian_linux ubuntu_linux
|
The format_send_to_gui function in the format parsing code in Irssi before 0.8.20 allows remote attackers to cause a denial of service (heap corruption and crash) via vectors involving the length of …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7045
|
2024-11-21 11:57 |
2016-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265840
|
7.5 |
HIGH
Network
|
irssi debian canonical
|
irssi debian_linux ubuntu_linux
|
The unformat_24bit_color function in the format parsing code in Irssi before 0.8.20, when compiled with true-color enabled, allows remote attackers to cause a denial of service (heap corruption and c…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7044
|
2024-11-21 11:57 |
2016-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|