Latest CVE Feed
-
6.5
MEDIUMCVE-2016-2950
SQL injection vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : bigfix_remote_control- Published: Nov. 30, 2016
- Modified: Apr. 12, 2025
-
3.3
LOWCVE-2016-2949
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by reading cached web pages from a different user's session.... Read more
Affected Products : bigfix_remote_control- Published: Nov. 30, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-2948
IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.... Read more
Affected Products : bigfix_remote_control- Published: Nov. 30, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-2944
IBM BigFix Remote Control before 9.1.3 does not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.... Read more
Affected Products : bigfix_remote_control- Published: Nov. 30, 2016
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2016-2943
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by leveraging unspecified privileges to read a log file.... Read more
Affected Products : bigfix_remote_control- Published: Nov. 30, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-2940
Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitive information via unknown vectors.... Read more
Affected Products : bigfix_remote_control- Published: Nov. 30, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-2937
IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive information or spoof e-mail transmission via a crafted POST request, related to an "untrusted information vulnerability."... Read more
Affected Products : bigfix_remote_control- Published: Nov. 30, 2016
- Modified: Apr. 12, 2025
-
7.3
HIGHCVE-2016-2936
IBM BigFix Remote Control before 9.1.3 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information via unknown vectors.... Read more
Affected Products : bigfix_remote_control- Published: Nov. 30, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-2935
The broker application in IBM BigFix Remote Control before 9.1.3 allows remote attackers to cause a denial of service via an invalid HTTP request.... Read more
Affected Products : bigfix_remote_control- Published: Nov. 30, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-2934
Cross-site scripting (XSS) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : bigfix_remote_control- Published: Nov. 30, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-2933
Directory traversal vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated administrators to read arbitrary files via a crafted request.... Read more
Affected Products : bigfix_remote_control- Published: Nov. 30, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-2932
IBM BigFix Remote Control before 9.1.3 allows remote attackers to conduct XML injection attacks via unspecified vectors.... Read more
Affected Products : bigfix_remote_control- Published: Nov. 30, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-2931
IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network.... Read more
Affected Products : bigfix_remote_control- Published: Nov. 30, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-9481
In framework/modules/core/controllers/expCommentController.php of Exponent CMS 2.4.0, content_id input is passed into showComments. The method showComments is defined in the expCommentControllercontroller with the parameter '$this->params['content_id']' u... Read more
Affected Products : exponent_cms- Published: Nov. 29, 2016
- Modified: Apr. 12, 2025
-
9.1
CRITICALCVE-2016-9480
libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611... Read more
Affected Products : libdwarf- Published: Nov. 29, 2016
- Modified: Apr. 12, 2025
-
4.6
MEDIUMCVE-2016-8224
A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a deni... Read more
- Published: Nov. 29, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-8223
During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interface Foundation software installed on some Windows 10 PCs where a user with local privileges could run arbitrary code with administrator... Read more
- Published: Nov. 29, 2016
- Modified: Apr. 12, 2025
-
8.1
HIGHCVE-2016-1251
There is a vulnerability of type use-after-free affecting DBD::mysql (aka DBD-mysql or the Database Interface (DBI) MySQL driver for Perl) 3.x and 4.x before 4.041 when used with mysql_server_prepare=1.... Read more
Affected Products : dbd-mysql- Published: Nov. 29, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-1247
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-... Read more
- Published: Nov. 29, 2016
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2016-5685
Dell iDRAC7 and iDRAC8 devices with firmware before 2.40.40.40 allow authenticated users to gain Bash shell access through a string injection.... Read more
- Published: Nov. 29, 2016
- Modified: Apr. 12, 2025