Unknown · CVSS Not scored
An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31. A command injection vulnerability was discovered in a common script used by many Cloud Foundry components. A malicious user may exploit numerous vectors to execute arbitrary commands on servers running Cloud Foundry.
Published Jun 13, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requests, user authentication, and payload scanning.
Published Jun 8, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
elog 3.1.1 allows remote attackers to post data as any username in the logbook.
Published Jun 27, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to improper access controls. IBM X-Force ID: 117926.
Published Jun 7, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
Published Jun 8, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could contain sensitive information. IBM X-Force ID: 117696.
Published Jun 27, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Published Jun 8, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM Domino 8.5 and 9.0 could allow an attacker to steal credentials using multiple sessions and large amounts of data using Domino TLS Key Exchange validation. IBM X-Force ID: 117918.
Published Jun 7, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.
Published Jun 29, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.
Published Jun 29, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 116171.
Published Jun 7, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 115336.
Published Jun 23, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local users to cause a denial of service or possibly have unspecified other impact via a crafted (1) HIDIOCGUSAGES or (2) HIDIOCSUSAGES ioctl call.
Published Jun 27, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.
Published Jun 29, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction before an exec system call.
Published Jun 27, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 116136.
Published Jun 7, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.
Published Jun 29, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.
Published Jun 29, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.
Published Jun 29, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors.
Published Jun 29, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header.
Published Jun 30, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.
Published Jun 29, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
SolarWinds Virtualization Manager 6.3.1 and earlier uses weak encryption to store passwords in /etc/shadow, which allows local users with superuser privileges to obtain user passwords via a brute force attack.
Published Jun 24, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Huawei FusionInsight HD before V100R002C60SPC200 allows local users to gain root privileges via unspecified vectors.
Published Jun 24, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Race condition in the vop_ioctl function in drivers/misc/mic/vop/vop_vringh.c in the MIC VOP driver in the Linux kernel before 4.6.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (memory corruption and system crash) by changing a certain header, aka a "double fetch" vulnerability.
Published Jun 27, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Lenovo BIOS EFI Driver allows local administrators to execute arbitrary code with System Management Mode (SMM) privileges via unspecified vectors.
Published Jun 30, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Huawei OceanStor 5300 V3, 5500 V3, 5600 V3, 5800 V3, 6800 V3, 18800 V3, and 18500 V3 before V300R003C10 sends the plaintext session token in the HTTP header, which allows remote attackers to conduct replay attacks and obtain sensitive information by sniffing the network.
Published Jun 24, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Acer Portal app before 3.9.4.2000 for Android does not properly validate SSL certificates, which allows remote attackers to perform a Man-in-the-middle attack via a crafted SSL certificate.
Published Jun 8, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to read the default Access Control Instructions.
Published Jun 8, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to obtain sensitive information via unspecified vectors, aka HWPSIRT-2016-05053.
Published Jun 14, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed UDP packet. NOTE: the original behavior complies with the IKEv1 protocol, but has a required security update from the libreswan vendor; as of 2016-06-10, it is expected that several other IKEv1 implementations will have vendor-required security updates, with separate CVE IDs assigned to each.
Published Jun 16, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Memory leak in Huawei IPS Module, NGFW Module, NIP6300, NIP6600, and Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS8000 V500R001C00 before V500R001C20SPC100, when in hot standby networking where two devices are not directly connected, allows remote attackers to cause a denial of service (memory consumption and reboot) via a crafted packet.
Published Jun 24, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended DHCP-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via a crafted DHCP discovery message.
Published Jun 17, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to modify configuration data via vectors related to a "file injection vulnerability," aka HWPSIRT-2016-05052.
Published Jun 14, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QEMU host via vectors related to the information transfer buffer.
Published Jun 14, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow in Huawei Honor WS851 routers with software 1.1.21.1 and earlier allows remote attackers to execute arbitrary commands with root privileges via unspecified vectors, aka HWPSIRT-2016-05051.
Published Jun 14, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.
Published Jun 27, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords.
Published Jun 8, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors.
Published Jun 17, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).
Published Jun 13, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the root password of the deployed system.
Published Jun 13, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Memory leak in Huawei AR3200 before V200R007C00SPC900 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted Multiprotocol Label Switching (MPLS) packets.
Published Jun 30, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via (1) a crafted DHCP discovery message or (2) crafted non-IP traffic.
Published Jun 17, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memory access and crash) or possibly have unspecified other impact via unknown vectors.
Published Jun 30, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information.
Published Jun 14, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Open redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Published Jun 30, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to read arbitrary files in the web-root directory tree via unspecified vectors.
Published Jun 30, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allow remote authenticated users to inject arbitrary web script or HTML via a "DOM link manipulation" attack.
Published Jun 30, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HTTP traffic on port 8445.
Published Jun 30, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876.
Published Jun 16, 2016 · Updated Aug 6, 2024