|
266681
|
8.8 |
HIGH
Network
|
hp
|
version_control_repository_manager
|
A remote malicious file upload vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2016-8515
|
2024-11-21 11:59 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266682
|
6.5 |
MEDIUM
Network
|
hp
|
version_control_repository_manager
|
A remote information disclosure in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6.
|
CWE-200
Information Exposure
|
CVE-2016-8514
|
2024-11-21 11:59 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266683
|
8.0 |
HIGH
Network
|
hp
|
version_control_repository_manager
|
A Cross-Site Request Forgery (CSRF) vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6.
|
CWE-352
Origin Validation Error
|
CVE-2016-8513
|
2024-11-21 11:59 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266684
|
9.8 |
CRITICAL
Network
|
hp
|
performance_center loadrunner
|
A Remote Code Execution vulnerability in all versions of HPE LoadRunner and Performance Center was found.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-8512
|
2024-11-21 11:59 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266685
|
9.8 |
CRITICAL
Network
|
hp
|
network_automation
|
A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x, v9.2x, v10.00, v10.00.01, v10.00.02, v10.10, v10.11, v10.11.01, v10.20 was fou…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-8511
|
2024-11-21 11:59 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266686
|
7.8 |
HIGH
Local
|
apache
|
couchdb
|
The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file permissions of the parent directory and therefore a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-8742
|
2024-11-21 11:59 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266687
|
7.5 |
HIGH
Network
|
openssl debian redhat netapp paloaltonetworks oracle fujitsu
|
openssl debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_server…
|
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote…
|
-
|
CVE-2016-8610
|
2024-11-21 11:59 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266688
|
5.4 |
MEDIUM
Network
|
apache
|
nifi
|
In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not bein…
|
CWE-79
Cross-site Scripting
|
CVE-2016-8748
|
2024-11-21 11:59 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266689
|
6.5 |
MEDIUM
Network
|
apache debian
|
subversion debian_linux
|
Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The a…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-8734
|
2024-11-21 11:59 |
2017-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266690
|
9.8 |
CRITICAL
Network
|
apache
|
openmeetings
|
Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-8736
|
2024-11-21 11:59 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|