Show filters
774 Total Results
Displaying 541-550 of 774
Sort by:
Attacker Value
Unknown

CVE-2016-3507

Disclosure Date: July 21, 2016 (last updated November 25, 2024)
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect integrity via vectors related to WebClient / Admin.
0
Attacker Value
Unknown

CVE-2016-3450

Disclosure Date: July 21, 2016 (last updated November 25, 2024)
Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote attackers to affect confidentiality via vectors related to Services, a different vulnerability than CVE-2016-5460 and CVE-2016-5466.
0
Attacker Value
Unknown

CVE-2016-3100

Disclosure Date: July 13, 2016 (last updated November 25, 2024)
kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of other users and consequently capture keystrokes and possibly gain privileges by reading the file.
0
Attacker Value
Unknown

CVE-2016-3255

Disclosure Date: July 13, 2016 (last updated November 25, 2024)
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability."
0
Attacker Value
Unknown

CVE-2015-3192

Disclosure Date: July 12, 2016 (last updated November 25, 2024)
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
0
Attacker Value
Unknown

CVE-2016-1183

Disclosure Date: June 19, 2016 (last updated November 25, 2024)
NTT Data TERASOLUNA Server Framework for Java(WEB) 2.0.0.1 through 2.0.6.1, as used in Fujitsu Interstage Business Application Server and other products, allows remote attackers to bypass a file-extension protection mechanism, and consequently read arbitrary files, via a crafted pathname.
0
Attacker Value
Unknown

CVE-2015-5723

Disclosure Date: June 07, 2016 (last updated November 08, 2023)
Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.
0
Attacker Value
Unknown

CVE-2015-7695

Disclosure Date: June 07, 2016 (last updated November 25, 2024)
The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query.
0
Attacker Value
Unknown

CVE-2016-0149

Disclosure Date: May 11, 2016 (last updated November 25, 2024)
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitive cleartext information via vectors involving injection of cleartext data into the client-server data stream, aka "TLS/SSL Information Disclosure Vulnerability."
0
Attacker Value
Unknown

CVE-2016-3420

Disclosure Date: April 21, 2016 (last updated November 25, 2024)
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.1.1, 9.3.1.2, 9.3.2, and 9.3.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to Security, a different vulnerability than CVE-2016-3431.
0