|
265631
|
9.8 |
CRITICAL
Network
|
debian redhat mozilla
|
debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux enterprise_linux_server_aus enterprise_linux_server_eus thunderbird
|
Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbit…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-9893
|
2024-11-21 12:01 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265632
|
6.1 |
MEDIUM
Network
|
manageengine
|
applications_manager
|
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Manager is prone to a Cross-Site Scripting vulnerabili…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9490
|
2024-11-21 12:01 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265633
|
9.8 |
CRITICAL
Network
|
manageengine
|
applications_manager
|
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerSer…
|
CWE-89
SQL Injection
|
CVE-2016-9488
|
2024-11-21 12:01 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265634
|
8.8 |
HIGH
Network
|
qemu debian
|
qemu debian_linux
|
Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder …
|
CWE-59
Link Following
|
CVE-2016-9602
|
2024-11-21 12:01 |
2018-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265635
|
6.5 |
MEDIUM
Network
|
openstack redhat
|
puppet-swift openstack
|
puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet s…
|
CWE-200
Information Exposure
|
CVE-2016-9590
|
2024-11-21 12:01 |
2018-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265636
|
8.1 |
HIGH
Network
|
redhat ansible
|
ansible openstack
|
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed …
|
CWE-20
Improper Input Validation
|
CVE-2016-9587
|
2024-11-21 12:01 |
2018-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265637
|
5.5 |
MEDIUM
Local
|
artifex debian
|
gpl_ghostscript debian_linux jbig2dec
|
ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_image function which is used to decode halftone segments in a J…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-9601
|
2024-11-21 12:01 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265638
|
7.5 |
HIGH
Network
|
openstack redhat
|
puppet-tripleo openstack
|
puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is ena…
|
CWE-284
Improper Access Control
|
CVE-2016-9599
|
2024-11-21 12:01 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265639
|
8.1 |
HIGH
Network
|
haxx
|
curl
|
curl before version 7.52.1 is vulnerable to an uninitialized random in libcurl's internal function that returns a good 32bit random value. Having a weak or virtually non-existent random value makes …
|
CWE-665
Improper Initialization
|
CVE-2016-9594
|
2024-11-21 12:01 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265640
|
8.1 |
HIGH
Network
|
haxx
|
curl
|
curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl's implementation of the printf() functions. If there are any application that accepts…
|
-
|
CVE-2016-9586
|
2024-11-21 12:01 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|