|
265641
|
8.8 |
HIGH
Network
|
theforeman redhat
|
foreman satellite
|
foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those …
|
CWE-255
Credentials Management
|
CVE-2016-9593
|
2024-11-21 12:01 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265642
|
4.3 |
MEDIUM
Network
|
redhat
|
openshift
|
openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes the delete operation to fail with 'VolumeInUse' error. Since the delete operation…
|
CWE-399
Resource Management Errors
|
CVE-2016-9592
|
2024-11-21 12:01 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265643
|
5.3 |
MEDIUM
Network
|
ikiwiki debian
|
ikiwiki debian_linux
|
ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata fo…
|
CWE-287
Improper Authentication
|
CVE-2016-9646
|
2024-11-21 12:01 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265644
|
6.5 |
MEDIUM
Network
|
ikiwiki
|
ikiwiki
|
The fix for ikiwiki for CVE-2016-10026 was incomplete resulting in editing restriction bypass for git revert when using git versions older than 2.8.0. This has been fixed in 3.20161229.
|
CWE-284
Improper Access Control
|
CVE-2016-9645
|
2024-11-21 12:01 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265645
|
5.3 |
MEDIUM
Network
|
ibm
|
cognos_analytics
|
IBM Predictive Solutions Foundation (IBM Cognos Analytics 11.0) reveals sensitive information in detailed error messages that could aid an attacker in further attacks against the system. IBM X-Force …
|
CWE-200
Information Exposure
|
CVE-2016-9711
|
2024-11-21 12:01 |
2018-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265646
|
9.8 |
CRITICAL
Network
|
pivotal_software
|
gemfire_for_pivotal_cloud_foundry
|
The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed b…
|
CWE-287
Improper Authentication
|
CVE-2016-9880
|
2024-11-21 12:01 |
2018-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265647
|
6.3 |
MEDIUM
Network
|
freeipa
|
freeipa
|
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, un…
|
CWE-285
Improper Authorization
|
CVE-2016-9575
|
2024-11-21 12:01 |
2018-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265648
|
6.5 |
MEDIUM
Network
|
jasper_project canonical redhat
|
jasper ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_server_…
|
JasPer before version 2.0.10 is vulnerable to a null pointer dereference was found in the decoded creation of JPEG 2000 image files. A specially crafted file could cause an application using JasPer t…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-9600
|
2024-11-21 12:01 |
2018-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265649
|
7.5 |
HIGH
Network
|
redhat
|
jboss_wildfly_application_server
|
Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cache of seen HTTP headers in persistent connections.…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-9589
|
2024-11-21 12:01 |
2018-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265650
|
8.1 |
HIGH
Network
|
redhat
|
resteasy
|
JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitra…
|
CWE-20
Improper Input Validation
|
CVE-2016-9606
|
2024-11-21 12:01 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|