|
267741
|
7.8 |
HIGH
Local
|
apache
|
openoffice
|
The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operation that allows execution of arbitrary code with elevated pr…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6804
|
2024-11-21 11:56 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267742
|
7.8 |
HIGH
Local
|
apache
|
openoffice
|
An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3 installers for Windows. The PC must have previously been infected by a Trojan …
|
CWE-426
Untrusted Search Path
|
CVE-2016-6803
|
2024-11-21 11:56 |
2017-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267743
|
6.5 |
MEDIUM
Network
|
apache
|
ranger
|
In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.
|
CWE-255
Credentials Management
|
CVE-2016-6815
|
2024-11-21 11:56 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267744
|
8.8 |
HIGH
Network
|
apache
|
wicket
|
Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only check the Origin HTT…
|
CWE-352
Origin Validation Error
|
CVE-2016-6806
|
2024-11-21 11:56 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267745
|
9.8 |
CRITICAL
Network
|
apache
|
struts
|
In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on…
|
CWE-22
Path Traversal
|
CVE-2016-6795
|
2024-11-21 11:56 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267746
|
6.1 |
MEDIUM
Network
|
apache
|
ofbiz
|
The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creatio…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6800
|
2024-11-21 11:56 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267747
|
7.5 |
HIGH
Network
|
apache
|
tomcat
|
The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of s…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-6817
|
2024-11-21 11:56 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267748
|
7.5 |
HIGH
Network
|
apache debian netapp canonical oracle redhat
|
tomcat debian_linux snap_creator_framework oncommand_insight oncommand_shift ubuntu_linux tekelec_platform_distribution enterprise_linux_desktop enterprise_linux_workstation
|
A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via…
|
NVD-CWE-noinfo
|
CVE-2016-6796
|
2024-11-21 11:56 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267749
|
7.5 |
HIGH
Network
|
apache oracle debian netapp canonical redhat
|
tomcat tekelec_platform_distribution debian_linux snap_creator_framework oncommand_insight oncommand_shift ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation
|
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global J…
|
CWE-863
Incorrect Authorization
|
CVE-2016-6797
|
2024-11-21 11:56 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267750
|
6.1 |
MEDIUM
Network
|
apache
|
cxf
|
The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the availa…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6812
|
2024-11-21 11:56 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|