|
266991
|
6.1 |
MEDIUM
Network
|
manageengine
|
applications_manager
|
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Manager is prone to a Cross-Site Scripting vulnerabili…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9490
|
2024-11-21 12:01 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266992
|
9.8 |
CRITICAL
Network
|
manageengine
|
applications_manager
|
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerSer…
|
CWE-89
SQL Injection
|
CVE-2016-9488
|
2024-11-21 12:01 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266993
|
8.8 |
HIGH
Network
|
qemu debian
|
qemu debian_linux
|
Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder …
|
CWE-59
Link Following
|
CVE-2016-9602
|
2024-11-21 12:01 |
2018-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266994
|
6.5 |
MEDIUM
Network
|
openstack redhat
|
puppet-swift openstack
|
puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet s…
|
CWE-200
Information Exposure
|
CVE-2016-9590
|
2024-11-21 12:01 |
2018-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266995
|
8.1 |
HIGH
Network
|
redhat ansible
|
ansible openstack
|
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed …
|
CWE-20
Improper Input Validation
|
CVE-2016-9587
|
2024-11-21 12:01 |
2018-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266996
|
5.5 |
MEDIUM
Local
|
artifex debian
|
gpl_ghostscript debian_linux jbig2dec
|
ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_image function which is used to decode halftone segments in a J…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-9601
|
2024-11-21 12:01 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266997
|
7.5 |
HIGH
Network
|
openstack redhat
|
puppet-tripleo openstack
|
puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is ena…
|
CWE-284
Improper Access Control
|
CVE-2016-9599
|
2024-11-21 12:01 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266998
|
8.1 |
HIGH
Network
|
haxx
|
curl
|
curl before version 7.52.1 is vulnerable to an uninitialized random in libcurl's internal function that returns a good 32bit random value. Having a weak or virtually non-existent random value makes …
|
CWE-665
Improper Initialization
|
CVE-2016-9594
|
2024-11-21 12:01 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266999
|
8.1 |
HIGH
Network
|
haxx
|
curl
|
curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl's implementation of the printf() functions. If there are any application that accepts…
|
-
|
CVE-2016-9586
|
2024-11-21 12:01 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267000
|
8.8 |
HIGH
Network
|
theforeman redhat
|
foreman satellite
|
foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those …
|
CWE-255
Credentials Management
|
CVE-2016-9593
|
2024-11-21 12:01 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|