|
268841
|
6.1 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1 allows remote attackers to inject arbitrary web script or HTML via the FirstNa…
|
CWE-79
Cross-site Scripting
|
CVE-2016-3670
|
2024-11-21 11:50 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268842
|
9.8 |
CRITICAL
Network
|
fedoraproject fasterxml
|
fedora jackson-dataformat-xml
|
XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2016-3720
|
2024-11-21 11:50 |
2016-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268843
|
7.5 |
HIGH
Network
|
opensuse gnu
|
opensuse glibc
|
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vecto…
|
CWE-20
Improper Input Validation
|
CVE-2016-3706
|
2024-11-21 11:50 |
2016-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268844
|
8.8 |
HIGH
Network
|
redhat
|
openshift
|
Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket and gain privileges via vectors related to build-…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3738
|
2024-11-21 11:50 |
2016-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268845
|
3.3 |
LOW
Local
|
redhat
|
openshift openshift_origin
|
HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the internal IP address of a pod by reading the "OPENSHIFT_[namespace]_SERVERID" cookie.
|
CWE-200
Information Exposure
|
CVE-2016-3711
|
2024-11-21 11:50 |
2016-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268846
|
7.1 |
HIGH
Network
|
redhat
|
openshift
|
Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in other namespaces, allows remote authenticated users t…
|
CWE-284
Improper Access Control
|
CVE-2016-3708
|
2024-11-21 11:50 |
2016-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268847
|
5.3 |
MEDIUM
Network
|
redhat
|
openshift
|
Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/proxy API for a specific pod, which allows remote …
|
CWE-284
Improper Access Control
|
CVE-2016-3703
|
2024-11-21 11:50 |
2016-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268848
|
7.5 |
HIGH
Network
|
lenovo
|
accelerator_application
|
UpdateAgent in Lenovo Accelerator Application allows man-in-the-middle attackers to execute arbitrary code by spoofing an update response from susapi.lenovomm.com.
|
CWE-20
Improper Input Validation
|
CVE-2016-3944
|
2024-11-21 11:50 |
2016-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268849
|
7.8 |
HIGH
Local
|
docker linuxfoundation opensuse
|
docker runc opensuse
|
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric use…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3697
|
2024-11-21 11:50 |
2016-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268850
|
7.8 |
HIGH
Local
|
huawei
|
mate_8_firmware
|
Buffer overflow in the Wi-Fi driver in Huawei Mate 8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3681
|
2024-11-21 11:50 |
2016-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|