|
266231
|
6.5 |
MEDIUM
Network
|
ibm
|
spectrum_control tivoli_storage_productivity_center
|
Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to read arbitrary files via a .. (dot dot…
|
CWE-200
Information Exposure
|
CVE-2016-5946
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266232
|
4.3 |
MEDIUM
Network
|
ibm
|
spectrum_control tivoli_storage_productivity_center
|
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to upload non-executable files via a crafted HTTP request.
|
CWE-284
Improper Access Control
|
CVE-2016-5945
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266233
|
5.4 |
MEDIUM
Network
|
ibm
|
spectrum_control tivoli_storage_productivity_center
|
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to inject arbitrary …
|
CWE-79
Cross-site Scripting
|
CVE-2016-5944
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266234
|
5.4 |
MEDIUM
Network
|
ibm
|
spectrum_control
|
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to bypass intended access restrictions, and read task details or edit properti…
|
CWE-284
Improper Access Control
|
CVE-2016-5943
|
2024-11-21 11:55 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266235
|
8.8 |
HIGH
Local
|
moxa
|
active_opc_server
|
Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory.
|
CWE-428
Unquoted Search Path or Element
|
CVE-2016-5793
|
2024-11-21 11:55 |
2016-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266236
|
8.4 |
HIGH
Local
|
redhat
|
quickstart_cloud_installer
|
The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers to determine cleartext passwords via a brute-force …
|
CWE-254
7PK - Security Features
|
CVE-2016-6340
|
2024-11-21 11:55 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266237
|
8.4 |
HIGH
Local
|
redhat
|
quickstart_cloud_installer
|
Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password for the deployed system by reading the file.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6322
|
2024-11-21 11:55 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266238
|
5.5 |
MEDIUM
Local
|
artifex opensuse
|
mupdf leap opensuse
|
Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file.
|
CWE-416
Use After Free
|
CVE-2016-6265
|
2024-11-21 11:55 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266239
|
9.8 |
CRITICAL
Network
|
debian westes
|
debian_linux flex
|
Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-6354
|
2024-11-21 11:55 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266240
|
8.6 |
HIGH
Network
|
oracle libarchive
|
linux libarchive
|
Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying f…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-6250
|
2024-11-21 11:55 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|