Latest CVE Feed
-
9.0
HIGHCVE-2016-7071
It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems managed by CloudForms if they know... Read more
- EPSS Score: %0.49
- Published: Sep. 10, 2018
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2016-7070
A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the datab... Read more
Affected Products : ansible_tower- EPSS Score: %0.09
- Published: Sep. 11, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2016-7069
An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a backend. When dnsdist is configured to add EDNS Client Subnet to a query, the response may contain an EDNS0 OPT record that has to be re... Read more
Affected Products : dnsdist- EPSS Score: %0.02
- Published: Sep. 11, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2016-7068
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacker to cause an abnormal CPU usage load on the PowerDNS server by sending crafted DNS queries, which might r... Read more
- EPSS Score: %0.08
- Published: Sep. 11, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2016-7067
Monit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an attacker to disable/enable all monitoring for a particular host or disable/enable monitoring for a specific service.... Read more
Affected Products : monit- EPSS Score: %0.27
- Published: Sep. 10, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2016-7066
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.... Read more
Affected Products : jboss_enterprise_application_platform- EPSS Score: %0.03
- Published: Sep. 11, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2016-7064
A flaw was found in pritunl-client before version 1.0.1116.6. A lack of signature verification leads to sensitive information leakage... Read more
Affected Products : pritunl-client- EPSS Score: %0.15
- Published: Jul. 21, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-7063
A flaw was found in pritunl-client before version 1.0.1116.6. Arbitrary write to user specified path may lead to privilege escalation.... Read more
Affected Products : pritunl-client- EPSS Score: %0.75
- Published: Jul. 21, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2016-7061
An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive informatio... Read more
- EPSS Score: %0.59
- Published: Sep. 10, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2016-7056
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.... Read more
- EPSS Score: %0.12
- Published: Sep. 10, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-7048
The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download software.... Read more
Affected Products : postgresql- EPSS Score: %9.57
- Published: Aug. 20, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-7047
A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.... Read more
- EPSS Score: %0.33
- Published: Sep. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-7043
It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther servi... Read more
Affected Products : kie-server- EPSS Score: %0.30
- Published: May. 15, 2019
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2016-7041
Drools Workbench contains a path traversal vulnerability. The vulnerability allows a remote, authenticated attacker to bypass the directory restrictions and retrieve arbitrary files from the affected host.... Read more
- EPSS Score: %0.97
- Published: Sep. 10, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-7035
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to exe... Read more
- EPSS Score: %0.10
- Published: Sep. 10, 2018
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2016-6918
Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. (... Read more
Affected Products : markvision_enterprise- EPSS Score: %1.10
- Published: Mar. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-6814
When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was possible for an... Read more
- EPSS Score: %4.12
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-6813
Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is able to determine the ID of another (non-"root") CloudStack user, the malicious user may be able to reset t... Read more
Affected Products : cloudstack- EPSS Score: %1.53
- Published: Feb. 06, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-6810
In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output validation.... Read more
Affected Products : activemq- EPSS Score: %1.79
- Published: Jan. 10, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2016-6658
Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (basic auth or OAuth) to access the ... Read more
- EPSS Score: %0.31
- Published: Mar. 29, 2018
- Modified: Nov. 21, 2024