|
266051
|
7.5 |
HIGH
Network
|
nlnetlabs
|
nsd
|
NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.
|
CWE-399
Resource Management Errors
|
CVE-2016-6173
|
2024-11-21 11:55 |
2017-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266052
|
8.6 |
HIGH
Network
|
knot-dns
|
knot_dns
|
Knot DNS before 2.3.0 allows remote DNS servers to cause a denial of service (memory exhaustion and slave server crash) via a large zone transfer for (1) DDNS, (2) AXFR, or (3) IXFR.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-6171
|
2024-11-21 11:55 |
2017-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266053
|
7.3 |
HIGH
Local
|
ibm
|
tivoli_storage_manager_fastback
|
IBM Tivoli Storage Manager FastBack installer could allow a remote attacker to execute arbitrary code on the system. By placing a specially-crafted DLL in the victim's path, an attacker could exploit…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-5934
|
2024-11-21 11:55 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266054
|
4.7 |
MEDIUM
Local
|
ibm
|
tivoli_storage_manager_for_space_management
|
IBM Tivoli Storage Manager HSM for Windows displays the encrypted Tivoli Storage Manager password in application trace output if the password access option is prompt and the password is changed.
|
CWE-200
Information Exposure
|
CVE-2016-5918
|
2024-11-21 11:55 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266055
|
6.1 |
MEDIUM
Network
|
ibm
|
maximo_for_transportation maximo_for_utilities maximo_for_aviation maximo_for_nuclear_power maximo_for_energy_optimization maximo_asset_management maximo_for_life_sciences maximo…
|
IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentiall…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5902
|
2024-11-21 11:55 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266056
|
5.9 |
MEDIUM
Network
|
ibm
|
tealeaf_customer_experience_on_cloud_network_capture_add-on
|
IBM Tealeaf Customer Experience on Cloud Network Capture Add-On could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the TLS certificate. An attac…
|
CWE-200
Information Exposure
|
CVE-2016-5900
|
2024-11-21 11:55 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266057
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_collaborative_lifecycle_management
|
IBM Rational Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functiona…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6032
|
2024-11-21 11:55 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266058
|
7.2 |
HIGH
Network
|
ibm
|
security_key_lifecycle_manager
|
IBM Tivoli Key Lifecycle Manager 2.5, and 2.6 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions, which could allow the attacker to execute …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2016-6104
|
2024-11-21 11:55 |
2017-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266059
|
4.0 |
MEDIUM
Local
|
ibm
|
tivoli_key_lifecycle_manager security_key_lifecycle_manager
|
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another user on the system.
|
CWE-200
Information Exposure
|
CVE-2016-6097
|
2024-11-21 11:55 |
2017-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266060
|
6.1 |
MEDIUM
Network
|
ibm
|
tivoli_key_lifecycle_manager security_key_lifecycle_manager
|
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6096
|
2024-11-21 11:55 |
2017-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|