|
271041
|
7.2 |
HIGH
Network
|
apache redhat
|
activemq_artemis jboss_enterprise_application_platform
|
The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote aut…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2016-4978
|
2024-11-21 11:53 |
2016-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271042
|
9.8 |
CRITICAL
Network
|
openstack
|
python-muranoclient mitaka-murano murano-dashboard murano
|
OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), and python-muranoclient before 0.7.3 (liberty) and 0.8.x …
|
CWE-20
Improper Input Validation
|
CVE-2016-4972
|
2024-11-21 11:53 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271043
|
6.1 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform jboss_wildfly_application_server
|
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary…
|
CWE-93 CWE-113
CRLF Injection HTTP Response Splitting
|
CVE-2016-4993
|
2024-11-21 11:53 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271044
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.113 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2016-5175
|
2024-11-21 11:53 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271045
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
browser/ui/cocoa/browser_window_controller_private.mm in Google Chrome before 53.0.2785.113 does not process fullscreen toggle requests during a fullscreen transition, which allows remote attackers t…
|
CWE-20
Improper Input Validation
|
CVE-2016-5174
|
2024-11-21 11:53 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271046
|
7.1 |
HIGH
Network
|
google
|
chrome
|
The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, and consequently trig…
|
CWE-284
Improper Access Control
|
CVE-2016-5173
|
2024-11-21 11:53 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271047
|
6.5 |
MEDIUM
Network
|
google nodejs debian
|
chrome node.js debian_linux
|
The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted Ja…
|
CWE-200
Information Exposure
|
CVE-2016-5172
|
2024-11-21 11:53 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271048
|
8.8 |
HIGH
Network
|
google
|
chrome
|
WebKit/Source/bindings/templates/interface.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not prevent certain constructor calls, which allows remote attackers to cause a denial of …
|
CWE-416
Use After Free
|
CVE-2016-5171
|
2024-11-21 11:53 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271049
|
8.8 |
HIGH
Network
|
google
|
chrome
|
WebKit/Source/bindings/modules/v8/V8BindingForModules.cpp in Blink, as used in Google Chrome before 53.0.2785.113, does not properly consider getter side effects during array key conversion, which al…
|
CWE-416
Use After Free
|
CVE-2016-5170
|
2024-11-21 11:53 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271050
|
8.8 |
HIGH
Network
|
google
|
chrome_os
|
Format string vulnerability in Google Chrome OS before 53.0.2785.103 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2016-5169
|
2024-11-21 11:53 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|