|
265461
|
6.1 |
MEDIUM
Network
|
otrs
|
otrs
|
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.3.x before 3.3.16, 4.0.x before 4.0.19, and 5.0.x before 5.0.14 allows remote attackers to inject arbitrary web script …
|
CWE-79
Cross-site Scripting
|
CVE-2016-9139
|
2024-11-21 12:00 |
2017-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265462
|
6.1 |
MEDIUM
Network
|
ibm
|
websphere_message_broker integration_bus
|
IBM WebSphere Message Broker 9.0 and 10.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could expl…
|
CWE-254
7PK - Security Features
|
CVE-2016-9010
|
2024-11-21 12:00 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265463
|
7.8 |
HIGH
Local
|
ibm
|
aix vios
|
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-8972
|
2024-11-21 12:00 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265464
|
5.4 |
MEDIUM
Network
|
ibm
|
rational_collaborative_lifecycle_management
|
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadin…
|
CWE-79
Cross-site Scripting
|
CVE-2016-8968
|
2024-11-21 12:00 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265465
|
5.5 |
MEDIUM
Local
|
ibm
|
aix
|
IBM AIX 7.1 and 7.2 allows a local user to open a file with a specially crafted argument that would crash the system. IBM APARs: IV91488, IV91487, IV91456, IV90234.
|
CWE-20
Improper Input Validation
|
CVE-2016-8944
|
2024-11-21 12:00 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265466
|
8.8 |
HIGH
Network
|
imagemagick opensuse
|
imagemagick leap opensuse
|
The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick 7.0.3.3 before 7.0.3.8 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocatio…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-8866
|
2024-11-21 12:00 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265467
|
8.8 |
HIGH
Network
|
imagemagick debian
|
imagemagick debian_linux
|
The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick before 7.0.3.3 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failur…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-8862
|
2024-11-21 12:00 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265468
|
3.3 |
LOW
Local
|
moxa
|
nport_5100_series_firmware nport_5200_series_firmware nport_5400_series_firmware nport_5600_series_firmware nport_5100a_series_firmware nport_p5150a_series_firmware nport_5200a_seri…
|
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPor…
|
CWE-255
Credentials Management
|
CVE-2016-9348
|
2024-11-21 12:00 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265469
|
5.0 |
MEDIUM
Adjacent
|
emerson
|
se4801t0x_redundant_wireless_i\/o_card_firmware se4801t1x_simplex_wireless_i\/o_card_firmware
|
An issue was discovered in Emerson SE4801T0X Redundant Wireless I/O Card V13.3, and SE4801T1X Simplex Wireless I/O Card V13.3. DeltaV Wireless I/O Cards (WIOC) running the firmware available in the D…
|
CWE-254
7PK - Security Features
|
CVE-2016-9347
|
2024-11-21 12:00 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265470
|
5.3 |
MEDIUM
Network
|
moxa
|
miineport_e1_firmware miineport_e2_firmware miineport_e3_firmware
|
An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. Configuration data are stored in a file that is not encrypted.
|
CWE-310
Cryptographic Issues
|
CVE-2016-9346
|
2024-11-21 12:00 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|