|
266441
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager
|
IBM Rational Quality Manager 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended func…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6031
|
2024-11-21 11:55 |
2017-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266442
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_quality_manager
|
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functio…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6022
|
2024-11-21 11:55 |
2017-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266443
|
6.1 |
MEDIUM
Network
|
nagios
|
nagios
|
Cross-site scripting (XSS) vulnerability in Nagios.
|
CWE-79
Cross-site Scripting
|
CVE-2016-6209
|
2024-11-21 11:55 |
2017-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266444
|
3.3 |
LOW
Local
|
projectatomic
|
oci-register-machine
|
The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by running that command.
|
CWE-200
Information Exposure
|
CVE-2016-6349
|
2024-11-21 11:55 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266445
|
3.7 |
LOW
Network
|
ibm
|
security_key_lifecycle_manager
|
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, r…
|
CWE-200
Information Exposure
|
CVE-2016-6102
|
2024-11-21 11:55 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266446
|
5.4 |
MEDIUM
Network
|
ibm
|
call_center_for_commerce
|
IBM Call Center for Commerce 9.3 and 9.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionali…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6056
|
2024-11-21 11:55 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266447
|
9.8 |
CRITICAL
Network
|
huawei
|
ar3200_firmware
|
Huawei AR3200 routers with software before V200R007C00SPC600 allow remote attackers to cause a denial of service or execute arbitrary code via a crafted packet.
|
CWE-20
Improper Input Validation
|
CVE-2016-6206
|
2024-11-21 11:55 |
2017-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266448
|
5.9 |
MEDIUM
Network
|
percona opensuse fedoraproject
|
xtrabackup leap fedora
|
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain …
|
CWE-326
Inadequate Encryption Strength
|
CVE-2016-6225
|
2024-11-21 11:55 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266449
|
7.8 |
HIGH
Local
|
google
|
android
|
The Qualcomm SPCom driver in Android before 7.0 allows local users to execute arbitrary code within the context of the kernel via a crafted application, aka Android internal bug 34386529 and Qualcomm…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-5857
|
2024-11-21 11:55 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266450
|
4.6 |
MEDIUM
Network
|
ibm
|
tivoli_monitoring
|
IBM Tivoli Monitoring 6.2 and 6.3 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM Reference #: 1997223.
|
CWE-254
7PK - Security Features
|
CVE-2016-5933
|
2024-11-21 11:55 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|