|
266211
|
7.5 |
HIGH
Network
|
openssl
|
openssl
|
The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a denial of service (infinite loop) by triggering a zero-length record in an SSL_…
|
CWE-20
Improper Input Validation
|
CVE-2016-6305
|
2024-11-21 11:55 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266212
|
7.5 |
HIGH
Network
|
openssl nodejs novell
|
openssl node.js suse_linux_enterprise_module_for_web_scripting
|
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2016-6304
|
2024-11-21 11:55 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266213
|
6.5 |
MEDIUM
Network
|
ibm
|
aix
|
Directory traversal vulnerability in Eclipse Help in IBM Tivoli Lightweight Infrastructure (aka LWI), as used in AIX 5.3, 6.1, and 7.1, allows remote authenticated users to read arbitrary files via a…
|
CWE-22
Path Traversal
|
CVE-2016-6038
|
2024-11-21 11:55 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266214
|
6.8 |
MEDIUM
Network
|
opensuse powerdns
|
leap opensuse authoritative_server
|
PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXF…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-6172
|
2024-11-21 11:55 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266215
|
5.9 |
MEDIUM
Local
|
sqlite fedoraproject opensuse
|
sqlite fedora leap
|
os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application…
|
CWE-20
Improper Input Validation
|
CVE-2016-6153
|
2024-11-21 11:55 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266216
|
7.5 |
HIGH
Network
|
sap
|
hana
|
SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to inject arbitrary audit trail fields into the SYSLOG via vectors related to the SQL protocol, aka SAP Security Note 2197459.
|
NVD-CWE-Other
|
CVE-2016-6142
|
2024-11-21 11:55 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266217
|
7.8 |
HIGH
Local
|
citrix
|
linux_virtual_delivery_agent
|
Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain root privileges via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6276
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266218
|
6.5 |
MEDIUM
Network
|
ibm
|
tealeaf_customer_experience
|
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.122…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2016-5997
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266219
|
7.5 |
HIGH
Network
|
ibm
|
tealeaf_customer_experience
|
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.122…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2016-5996
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266220
|
5.4 |
MEDIUM
Network
|
ibm
|
tealeaf_customer_experience
|
Cross-site scripting (XSS) vulnerability in the Web UI in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5978
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|