|
266411
|
5.4 |
MEDIUM
Network
|
redhat
|
jboss_bpm_suite jboss_business_rules_management_system
|
JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remote, authenticated attackers that have privileges t…
|
-
|
CVE-2016-8608
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266412
|
5.4 |
MEDIUM
Network
|
theforeman redhat
|
foreman satellite satellite_capsule
|
It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to di…
|
CWE-79
Cross-site Scripting
|
CVE-2016-8639
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266413
|
7.8 |
HIGH
Local
|
dracut_project
|
dracut
|
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode update…
|
-
|
CVE-2016-8637
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266414
|
5.9 |
MEDIUM
Network
|
mozilla redhat
|
network_security_services enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_serv…
|
It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining t…
|
-
|
CVE-2016-8635
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266415
|
5.4 |
MEDIUM
Network
|
theforeman
|
foreman
|
A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains HTML then the second step of the wizard (/organizations/id/step2) will render t…
|
-
|
CVE-2016-8634
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266416
|
7.5 |
HIGH
Network
|
haxx
|
curl
|
curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong ho…
|
-
|
CVE-2016-8625
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266417
|
7.5 |
HIGH
Network
|
haxx
|
curl
|
A flaw was found in curl before version 7.51.0. The way curl handles cookies permits other threads to trigger a use-after-free leading to information disclosure.
|
-
|
CVE-2016-8623
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266418
|
9.8 |
CRITICAL
Network
|
haxx
|
curl
|
The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2016-8620
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266419
|
9.8 |
CRITICAL
Network
|
haxx
|
curl
|
The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.
|
CWE-415
Double Free
|
CVE-2016-8619
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266420
|
5.9 |
MEDIUM
Network
|
haxx
|
curl
|
A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an u…
|
CWE-255
Credentials Management
|
CVE-2016-8616
|
2024-11-21 11:59 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|