Unknown · CVSS Not scored
Unspecified vulnerability in Oracle MySQL 5.6.31 and earlier and 5.7.13 and earlier allows remote authenticated users to affect availability via vectors related to Server: InnoDB.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: DML.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier allows remote administrators to affect availability via vectors related to Server: Federated.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Oracle MySQL 5.6.31 and earlier and 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: InnoDB.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: Memcached.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Oracle MySQL 5.7.14 and earlier allows remote administrators to affect availability via vectors related to Server: Optimizer.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: Performance Schema, a different vulnerability than CVE-2016-8290.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to RBR.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: Security: Audit.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-5536.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier allows remote authenticated users to affect availability via vectors related to Server: Types.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Oracle MySQL 5.6.31 and earlier and 5.7.13 and earlier allows local users to affect availability via vectors related to Server: Replication.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote administrators to affect confidentiality and integrity via vectors related to Candidate Gateway.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Oracle MySQL 5.7.14 and earlier allows remote authenticated users to affect confidentiality via vectors related to Server: Security: Privileges.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: Replication.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect integrity via vectors related to Server: InnoDB Plugin.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows local users to affect integrity and availability via vectors related to Server: InnoDB.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: Performance Schema, a different vulnerability than CVE-2016-5633.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Mobile Application Platform.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to Talent Acquisition Manager.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Integration Broker, a different vulnerability than CVE-2016-5529 and CVE-2016-5530.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect confidentiality via unknown vectors.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality via unknown vectors.
Published Oct 25, 2016 · Updated Oct 10, 2024
Unknown · CVSS Not scored
In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.
Published Oct 13, 2017 · Updated Sep 17, 2024
Unknown · CVSS Not scored
In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM.
Published Oct 19, 2017 · Updated Sep 17, 2024
High · CVSS 7.5
By flooding a Juniper Networks router running Junos OS with specially crafted IPv6 traffic, all available resources can be consumed, leading to the inability to store next hop information for legitimate traffic. In extreme cases, the crafted IPv6 traffic may result in a total resource exhaustion and kernel panic. The issue is triggered by traffic destined to the router. Transit traffic does not trigger the vulnerability. This issue only affects devices with IPv6 enabled and configured. Devices not configured to process IPv6 traffic are unaffected by this vulnerability. This issue was found during internal product security testing. Juniper SIRT is not aware of any malicious exploitation of this vulnerability. Affected releases are Juniper Networks Junos OS 11.4 prior to 11.4R13-S3; 12.3 prior to 12.3R3-S4; 12.3X48 prior to 12.3X48-D30; 13.3 prior to 13.3R10, 13.3R4-S11; 14.1 prior to 14.1R2-S8, 14.1R4-S12, 14.1R8; 14.1X53 prior to 14.1X53-D28, 14.1X53-D40; 14.1X55 prior to 14.1X55-D35; 14.2 prior to 14.2R3-S10, 14.2R4-S7, 14.2R6; 15.1 prior to 15.1F2-S5, 15.1F5-S2, 15.1F6, 15.1R3; 15.1X49 prior to 15.1X49-D40; 15.1X53 prior to 15.1X53-D57, 15.1X53-D70.
Published Oct 13, 2017 · Updated Sep 17, 2024
Unknown · CVSS Not scored
The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows man-in-the-middle attackers to cause a denial of service (memory consumption, and device hang or reboot) via a large xtra.bin or xtra2.bin file on a spoofed Qualcomm gpsonextra.net or izatcloud.net host, aka internal bug 29555864.
Published Oct 10, 2016 · Updated Sep 17, 2024
Critical · CVSS 9.8
A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentials, information leak and command injection attack vectors. All versions of Juniper Networks Junos Space prior to 15.1R3 are affected.
Published Oct 13, 2017 · Updated Sep 17, 2024
Unknown · CVSS Not scored
url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that contains a " character, or a URL beginning with a substring other than the http:// or https:// substring.
Published Oct 10, 2017 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Under some circumstances on BIG-IP 12.0.0-12.1.0, 11.6.0-11.6.1, or 11.4.0-11.5.4 HF1, the Traffic Management Microkernel (TMM) may not properly clean-up pool member network connections when using SPDY or HTTP/2 virtual server profiles.
Published Oct 8, 2018 · Updated Sep 17, 2024
High · CVSS 7.1
J-Web does not validate certain input that may lead to cross-site request forgery (CSRF) issues or cause a denial of J-Web service (DoS).
Published Oct 13, 2017 · Updated Sep 16, 2024
High · CVSS 8.4
An incorrect permissions vulnerability in Juniper Networks Junos OS on vMX may allow local unprivileged users on a host system read access to vMX or vPFE images and obtain sensitive information contained in them such as private cryptographic keys. This issue was found during internal product security testing. Juniper SIRT is not aware of any malicious exploitation of this vulnerability. No other Juniper Networks products or platforms are affected by this issue. Affected releases are Juniper Networks Junos OS 15.1 prior to 15.1F5; 14.1 prior to 14.1R8
Published Oct 13, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only check the Origin HTTP header, but also take the Referer HTTP header into account when no Origin was provided. Furthermore, not all Wicket server side targets were subjected to the CSRF check. This was also fixed.
Published Oct 2, 2017 · Updated Sep 16, 2024
High · CVSS 7.5
Receipt of a specifically malformed IPv6 packet processed by the router may trigger a line card reset: processor exception 0x68616c74 (halt) in task: scheduler. The line card will reboot and recover without user interaction. However, additional specifically malformed packets may cause follow-on line card resets and lead to an extended service outage. This issue only affects E Series routers with IPv6 licensed and enabled. Routers not configured to process IPv6 traffic are unaffected by this vulnerability. Juniper SIRT is not aware of any malicious exploitation of this vulnerability. No other Juniper Networks products or platforms are affected by this issue.
Published Oct 13, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.
Published Oct 16, 2017 · Updated Sep 16, 2024
High · CVSS 8
Insufficient cross site scripting protection in J-Web component in Juniper Networks Junos OS may potentially allow a remote unauthenticated user to inject web script or HTML and steal sensitive data and credentials from a J-Web session and to perform administrative actions on the Junos device. Juniper SIRT is not aware of any malicious exploitation of this vulnerability. Affected releases are Juniper Networks Junos OS 11.4 prior to 11.4R13-S3; 12.1X44 prior to 12.1X44-D60; 12.1X46 prior to 12.1X46-D40; 12.1X47 prior to 12.1X47-D30; 12.3 prior to 12.3R11; 12.3X48 prior to 12.3X48-D20; 13.2X51 prior to 13.2X51-D39, 13.2X51-D40; 13.3 prior to 13.3R9; 14.1 prior to 14.1R6; 14.2 prior to 14.2R6; 15.1 prior to 15.1R3; 15.1X49 prior to 15.1X49-D20; 15.1X53 prior to 15.1X53-D57.
Published Oct 13, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclosing too much information during authentication. An attacker could gain user or administrative access to the TSM server. IBM X-Force ID: 118750.
Published Oct 5, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc.php.
Published Oct 10, 2017 · Updated Sep 16, 2024
High · CVSS 8.4
Certain combinations of Junos OS CLI commands and arguments have been found to be exploitable in a way that can allow unauthorized access to the operating system. This may allow any user with permissions to run these CLI commands the ability to achieve elevated privileges and gain complete control of the device. Affected releases are Juniper Networks Junos OS 11.4 prior to 11.4R13-S3; 12.1X46 prior to 12.1X46-D60; 12.1X47 prior to 12.1X47-D45; 12.3 prior to 12.3R12; 12.3X48 prior to 12.3X48-D35; 13.2 prior to 13.2R9; 13.3 prior to 13.3R4-S11, 13.3R9; 14.1 prior to 14.1R4-S12, 14.1R7; 14.1X53 prior to 14.1X53-D28, 14.1X53-D40; 14.1X55 prior to 14.1X55-D35; 14.2 prior to 14.2R3-S10, 14.2R4-S7, 14.2R5; 15.1 prior to 15.1F4, 15.1R3; 15.1X49 prior to 15.1X49-D60; 15.1X53 prior to 15.1X53-D57, 15.1X53-D70.
Published Oct 13, 2017 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Improper file verification vulnerability in SaAT Netizen installer ver.1.2.0.424 and earlier, and SaAT Netizen ver.1.2.0.8 (Build427) and earlier allows a remote unauthenticated attacker to conduct a man-in-the-middle attack. A successful exploitation may result in a malicious file being downloaded and executed.
Published Oct 31, 2023 · Updated Sep 6, 2024
Unknown · CVSS Not scored
Reflected XSS in wordpress plugin pondol-formmail v1.1
Published Oct 10, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Reflected XSS in wordpress plugin recipes-writer v1.0.4
Published Oct 10, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Reflected XSS in wordpress plugin photoxhibit v2.1.8
Published Oct 10, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
Published Oct 21, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Ruckus Wireless H500 web management interface authenticated command injection
Published Oct 10, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Reflected XSS in wordpress plugin tidio-gallery v1.1
Published Oct 10, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Ruckus Wireless H500 web management interface CSRF
Published Oct 25, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Reflected XSS in wordpress plugin ajax-random-post v2.00
Published Oct 10, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Ruckus Wireless H500 web management interface authentication bypass
Published Oct 25, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Reflected XSS in wordpress plugin tidio-form v1.0
Published Oct 10, 2016 · Updated Aug 6, 2024