cisco — email_security_appliance |
A vulnerability in the display of email messages in the Messages in Quarantine (MIQ) view in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a user to click a malicious link in the MIQ view. The malicious link could be used to facilitate a cross-site scripting (XSS) or HTML injection attack. More Information: CSCuz02235. Known Affected Releases: 8.0.2-069. Known Fixed Releases: 9.1.1-038 9.7.2-047. |
2016-10-28 |
4.3 |
CVE-2016-1423 CONFIRM |
cisco — email_security_appliance |
A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. Affected Products: all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco ESA and Cisco WSA, both virtual and hardware appliances, if the software is configured with message or content filters to scan incoming email attachments. More Information: CSCuw03606, CSCux59734. Known Affected Releases: 8.0.0-000 8.5.6-106 9.0.0-000 9.1.0-032 9.6.0-042 9.5.0-444 WSA10.0.0-000. Known Fixed Releases: 9.1.1-038 9.7.1-066. |
2016-10-28 |
5.0 |
CVE-2016-1480 CONFIRM |
cisco — email_security_appliance |
A vulnerability in the configured security policies, including drop email filtering, in Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass a configured drop filter by using an email with a corrupted attachment. More Information: CSCuz01651. Known Affected Releases: 10.0.9-015 9.7.1-066 9.9.6-026. |
2016-10-28 |
5.0 |
CVE-2016-6357 CONFIRM |
cisco — email_security_appliance |
A vulnerability in local FTP to the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition when the FTP application unexpectedly quits. More Information: CSCux68539. Known Affected Releases: 9.1.0-032 9.7.1-000. Known Fixed Releases: 9.1.1-038. |
2016-10-28 |
5.0 |
CVE-2016-6358 CONFIRM |
cisco — email_security_appliance |
A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to the AMP process unexpectedly restarting. Affected Products: Cisco AsyncOS Software for Email Security Appliances (ESA) versions 9.5 and later up to the first fixed release, Cisco AsyncOS Software for Web Security Appliances (WSA) all versions prior to the first fixed release. More Information: CSCux56406, CSCux59928. Known Affected Releases: 9.6.0-051 9.7.0-125 8.8.0-085 9.5.0-444 WSA10.0.0-000. Known Fixed Releases: 9.7.1-066 WSA10.0.0-233. |
2016-10-28 |
5.0 |
CVE-2016-6360 CONFIRM |
cisco — email_security_appliance |
A vulnerability in the email message and content filtering for malformed Multipurpose Internet Mail Extensions (MIME) headers of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of the targeted device. Emails that should have been quarantined could instead be processed. Affected Products: This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco ESA and Cisco WSA on both virtual and hardware appliances that are configured with message or content filters to scan incoming email attachments. More Information: CSCuy54740, CSCuy75174. Known Affected Releases: 9.7.1-066 9.5.0-575 WSA10.0.0-000. Known Fixed Releases: 10.0.0-125 9.1.1-038 9.7.2-047. |
2016-10-28 |
5.0 |
CVE-2016-6372 CONFIRM |
cisco — meeting_server |
A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server. More Information: CSCvb03308. Known Affected Releases: 1.8, 1.9, 2.0. |
2016-10-27 |
5.0 |
CVE-2016-6446 CONFIRM |
citrix — netscaler_application_delivery_controller_firmware |
Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header. |
2016-10-28 |
5.8 |
CVE-2016-9028 CONFIRM |
huge-it — catalog |
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla |
2016-10-27 |
6.5 |
CVE-2016-1000120 MISC MISC |
huge-it — slider |
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension |
2016-10-27 |
6.5 |
CVE-2016-1000122 MISC MISC |
ibm — security_guardium_database_activity_monitor |
IBM Security Guardium Database Activity Monitor 9.x through 9.5 before p700 and 10.x through 10.0.1 before p100 allows remote authenticated users to make HTTP requests with administrator privileges via unspecified vectors. |
2016-10-21 |
6.5 |
CVE-2016-0239 CONFIRM |
ibm — security_guardium_database_activity_monitor |
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP. |
2016-10-21 |
4.3 |
CVE-2016-0240 CONFIRM |
ibm — security_guardium_database_activity_monitor |
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to spoof administrator accounts by sending a modified login request over HTTP. |
2016-10-21 |
6.5 |
CVE-2016-0241 CONFIRM |
ibm — security_guardium |
IBM Security Guardium 10.x through 10.1 before p100 allows remote authenticated users to obtain sensitive information by reading an Application Error message. |
2016-10-21 |
4.0 |
CVE-2016-0242 CONFIRM |
ibm — security_guardium |
Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. |
2016-10-21 |
4.3 |
CVE-2016-0246 CONFIRM |
ibm — rational_collaborative_lifecycle_management |
IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iFix17, and 6.x before 6.0.1 ifix3 allow remote authenticated users to execute arbitrary OS commands via a crafted “HTML request.” |
2016-10-21 |
6.5 |
CVE-2016-0326 CONFIRM |
ibm — websphere_application_server |
The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, and 8.5.x before 8.5.5.10 mishandles CSRFtoken cookies, which allows remote authenticated users to obtain sensitive information via unspecified vectors. |
2016-10-21 |
4.0 |
CVE-2016-0377 CONFIRM |
microfocus — rumba_ftp |
Micro Focus Rumba FTP 4.X client buffer overflow makes it possible to corrupt the stack and allow arbitrary code execution. Fixed in: Rumba FTP 4.5 (HF 14668). This can only occur if a client connects to a malicious server. |
2016-10-27 |
6.8 |
CVE-2016-5764 CONFIRM |
novell — identity_manager |
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI. |
2016-10-27 |
4.3 |
CVE-2015-0787 CONFIRM |
novell — identity_manager |
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI. |
2016-10-27 |
4.3 |
CVE-2016-1592 CONFIRM |
oracle — business_intelligence_publisher |
Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality via unknown vectors. |
2016-10-25 |
4.0 |
CVE-2016-3473 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier allows remote authenticated users to affect availability via vectors related to Server: Optimizer. |
2016-10-25 |
6.8 |
CVE-2016-3492 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: InnoDB. |
2016-10-25 |
6.8 |
CVE-2016-3495 CONFIRM |
oracle — database_server |
Unspecified vulnerability in the RDBMS Security and SQL*Plus components in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows remote administrators to affect confidentiality via vectors related to DBA. |
2016-10-25 |
4.3 |
CVE-2016-3562 CONFIRM |
oracle — flexcube_universal_banking |
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, and 12.0.1 allows remote authenticated users to affect confidentiality via vectors related to INFRA. |
2016-10-25 |
4.0 |
CVE-2016-5479 CONFIRM |
oracle — sun_zfs_storage_appliance_kit |
Unspecified vulnerability in the Sun ZFS Storage Appliance Kit (AK) component in Oracle Sun Systems Products Suite AK 2013 allows remote attackers to affect confidentiality via vectors related to Core Services. |
2016-10-25 |
4.3 |
CVE-2016-5481 CONFIRM |
oracle — commerce_guided_search |
Unspecified vulnerability in the Oracle Commerce Guided Search component in Oracle Commerce 6.2.2, 6.3.0, 6.4.1.2, and 6.5.0 through 6.5.2 allows remote attackers to affect confidentiality and integrity via unknown vectors. |
2016-10-25 |
5.8 |
CVE-2016-5482 CONFIRM |
oracle — sun_zfs_storage_appliance_kit |
Unspecified vulnerability in the Sun ZFS Storage Appliance Kit (AK) component in Oracle Sun Systems Products Suite AK 2013 allows local users to affect confidentiality via vectors related to Core Services. |
2016-10-25 |
4.9 |
CVE-2016-5486 CONFIRM |
oracle — solaris |
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors. |
2016-10-25 |
4.6 |
CVE-2016-5487 CONFIRM |
oracle — weblogic_server |
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0 and 12.1.3.0 allows remote attackers to affect availability via vectors related to Web Container. |
2016-10-25 |
5.0 |
CVE-2016-5488 CONFIRM |
oracle — commerce_service_center |
Unspecified vulnerability in the Oracle Commerce Service Center component in Oracle Commerce 10.0.3.5 and 10.2.0.5 allows remote attackers to affect confidentiality and integrity via unknown vectors. |
2016-10-25 |
5.8 |
CVE-2016-5491 CONFIRM |
oracle — flexcube_private_banking |
Unspecified vulnerability in the Oracle FLEXCUBE Private Banking component in Oracle Financial Services Applications 12.0.1 through 12.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. |
2016-10-25 |
4.9 |
CVE-2016-5493 CONFIRM |
oracle — discoverer |
Unspecified vulnerability in the Oracle Discoverer component in Oracle Fusion Middleware 11.1.1.7.0 allows remote attackers to affect confidentiality via vectors related to EUL Code & Schema. |
2016-10-25 |
5.0 |
CVE-2016-5495 CONFIRM |
oracle — database |
Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors. |
2016-10-25 |
4.4 |
CVE-2016-5497 CONFIRM |
oracle — discoverer |
Unspecified vulnerability in the Oracle Discoverer component in Oracle Fusion Middleware 11.1.1.7.0 allows remote attackers to affect confidentiality via vectors related to Viewer. |
2016-10-25 |
5.0 |
CVE-2016-5500 CONFIRM |
oracle — flexcube_universal_banking |
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to INFRA. |
2016-10-25 |
5.5 |
CVE-2016-5502 CONFIRM |
oracle — sun_zfs_storage_appliance_kit |
Unspecified vulnerability in the Sun ZFS Storage Appliance Kit (AK) component in Oracle Sun Systems Products Suite AK 2013 allows local users to affect confidentiality, integrity, and availability via vectors related to Core Services. |
2016-10-25 |
4.6 |
CVE-2016-5503 CONFIRM |
oracle — agile_product_supplier_collaboration_for_process |
Unspecified vulnerability in the Oracle Agile Product Lifecycle Management for Process component in Oracle Supply Chain Products Suite 6.1.0.4, 6.1.1.6, and 6.2.0.0 allows local users to affect confidentiality via vectors related to Supplier Portal. |
2016-10-25 |
4.7 |
CVE-2016-5504 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.6.32 and earlier and 5.7.14 and earlier allows remote administrators to affect availability via vectors related to Server: InnoDB. |
2016-10-25 |
6.8 |
CVE-2016-5507 CONFIRM |
oracle — agile_product_lifecycle_management_framework |
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality via unknown vectors. |
2016-10-25 |
5.0 |
CVE-2016-5510 CONFIRM |
oracle — webcenter_sites |
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 12.2.1.0.0, 12.2.1.1.0, and 12.2.1.2.0 allows remote attackers to affect integrity via unknown vectors. |
2016-10-25 |
4.3 |
CVE-2016-5511 CONFIRM |
oracle — agile_product_lifecycle_management_framework |
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5521. |
2016-10-25 |
4.3 |
CVE-2016-5512 CONFIRM |
oracle — agile_product_lifecycle_management_framework |
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality via vectors related to File Manager. |
2016-10-25 |
4.0 |
CVE-2016-5513 CONFIRM |
oracle — agile_product_lifecycle_management_framework |
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to ExportServlet. |
2016-10-25 |
6.5 |
CVE-2016-5514 CONFIRM |
oracle — agile_product_lifecycle_management_framework |
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to RMIServlet. |
2016-10-25 |
6.5 |
CVE-2016-5515 CONFIRM |
oracle — database_server |
Unspecified vulnerability in the Kernel PDB component in Oracle Database Server 12.1.0.2 allows local users to affect availability via unknown vectors. |
2016-10-25 |
4.7 |
CVE-2016-5516 CONFIRM |
oracle — agile_engineering_data_management |
Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to webfileservices. |
2016-10-25 |
6.8 |
CVE-2016-5518 CONFIRM |
oracle — glassfish_server |
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to Java Server Faces. |
2016-10-25 |
6.5 |
CVE-2016-5519 CONFIRM |
oracle — agile_product_lifecycle_management_framework |
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality via unknown vectors. |
2016-10-25 |
4.0 |
CVE-2016-5522 CONFIRM |
oracle — agile_product_lifecycle_management_framework |
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to AutoVue Java Applet. |
2016-10-25 |
6.5 |
CVE-2016-5523 CONFIRM |
oracle — agile_product_lifecycle_management_framework |
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2016-5527. |
2016-10-25 |
5.0 |
CVE-2016-5524 CONFIRM |
oracle — agile_product_lifecycle_management_framework |
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2016-5524. |
2016-10-25 |
4.3 |
CVE-2016-5527 CONFIRM |
oracle — peoplesoft_enterprise_peopletools |
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Integration Broker, a different vulnerability than CVE-2016-5530 and CVE-2016-8293. |
2016-10-25 |
5.8 |
CVE-2016-5529 CONFIRM |
oracle — peoplesoft_enterprise_peopletools |
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Integration Broker, a different vulnerability than CVE-2016-5529 and CVE-2016-8293. |
2016-10-25 |
5.8 |
CVE-2016-5530 CONFIRM |
oracle — shipping_execution |
Unspecified vulnerability in the Oracle Shipping Execution component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote attackers to affect confidentiality via vectors related to Workflow Events. |
2016-10-25 |
5.0 |
CVE-2016-5532 CONFIRM |
oracle — primavera_p6_enterprise_ project_portfolio_management |
Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.4, 15.x, and 16.x allows remote authenticated users to affect confidentiality and integrity via unknown vectors. |
2016-10-25 |
5.5 |
CVE-2016-5533 CONFIRM |
oracle — siebel_user_interface_framework |
Unspecified vulnerability in the Siebel Apps – Customer Order Management component in Oracle Siebel CRM 16.1 allows remote authenticated users to affect confidentiality via unknown vectors. |
2016-10-25 |
4.0 |
CVE-2016-5534 CONFIRM |
oracle — platform_security_for_java |
Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. |
2016-10-25 |
6.5 |
CVE-2016-5536 CONFIRM |
oracle — netbeans |
Unspecified vulnerability in the NetBeans component in Oracle Fusion Middleware 8.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors. |
2016-10-25 |
4.6 |
CVE-2016-5537 CONFIRM |
oracle — micros_xstore_payment |
Unspecified vulnerability in the Oracle Retail Xstore Payment component in Oracle Retail Applications 1.x allows local users to affect confidentiality, integrity, and availability via unknown vectors. |
2016-10-25 |
4.6 |
CVE-2016-5539 CONFIRM |
oracle — jdk |
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to Libraries. |
2016-10-25 |
4.3 |
CVE-2016-5542 CONFIRM |
oracle — flexcube_enterprise_limits_and_ collateral_management |
Unspecified vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component in Oracle Financial Services Applications 12.0.0 and 12.1.0 allows remote attackers to affect confidentiality and integrity via vectors related to INFRA. |
2016-10-25 |
5.8 |
CVE-2016-5543 CONFIRM |
oracle — solaris |
Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows local users to affect availability via unknown vectors. |
2016-10-25 |
4.7 |
CVE-2016-5553 CONFIRM |
oracle — jdk |
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to JMX. |
2016-10-25 |
4.3 |
CVE-2016-5554 CONFIRM |
oracle — database_server |
Unspecified vulnerability in the OJVM component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows remote administrators to affect confidentiality, integrity, and availability via unknown vectors. |
2016-10-25 |
6.5 |
CVE-2016-5555 CONFIRM |
oracle — advanced_pricing |
Unspecified vulnerability in the Oracle Advanced Pricing component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote attackers to affect confidentiality and integrity via unknown vectors. |
2016-10-25 |
5.8 |
CVE-2016-5557 CONFIRM |
oracle — solaris |
Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows local users to affect integrity via vectors related to Kernel. |
2016-10-25 |
4.0 |
CVE-2016-5559 CONFIRM |
oracle — siebel_customer_order_management |
Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 16.1 allows remote authenticated users to affect confidentiality and integrity via vectors related to OpenUI. |
2016-10-25 |
5.5 |
CVE-2016-5560 CONFIRM |
oracle — iprocurement |
Unspecified vulnerability in the Oracle iProcurement component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. |
2016-10-25 |
4.9 |
CVE-2016-5562 CONFIRM |
oracle — hospitality_opera_5_property_services |
Unspecified vulnerability in the Oracle Hospitality OPERA 5 Property Services component in Oracle Hospitality Applications 5.4.0.0 through 5.4.3.0, 5.5.0.0, and 5.5.1.0 allows remote administrators to affect confidentiality, integrity, and availability via vectors related to OPERA. |
2016-10-25 |
6.0 |
CVE-2016-5563 CONFIRM |
oracle — hospitality_opera_5_property_services |
Unspecified vulnerability in the Oracle Hospitality OPERA 5 Property Services component in Oracle Hospitality Applications 5.4.0.0 through 5.4.3.0, 5.5.0.0, and 5.5.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to OPERA. |
2016-10-25 |
6.5 |
CVE-2016-5564 CONFIRM |
oracle — hospitality_opera_5_property_services |
Unspecified vulnerability in the Oracle Hospitality OPERA 5 Property Services component in Oracle Hospitality Applications 5.4.0.0 through 5.4.3.0, 5.5.0.0, and 5.5.1.0 allows remote authenticated users to affect confidentiality via vectors related to OPERA. |
2016-10-25 |
4.0 |
CVE-2016-5565 CONFIRM |
oracle — solaris |
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows remote attackers to affect confidentiality via unknown vectors. |
2016-10-25 |
5.0 |
CVE-2016-5566 CONFIRM |
oracle — applications_dba |
Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 12.1.3 and 12.2.3 through 12.2.6 allows remote administrators to affect confidentiality and integrity via vectors related to AD Utilities, a different vulnerability than CVE-2016-5571. |
2016-10-25 |
5.5 |
CVE-2016-5567 CONFIRM |
oracle — flexcube_enterprise_limits_and_ collateral_management |
Unspecified vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component in Oracle Financial Services Applications 12.0.0 and 12.1.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. |
2016-10-25 |
5.5 |
CVE-2016-5569 CONFIRM |
oracle — applications_dba |
Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 12.2.3 through 12.2.6 allows remote administrators to affect confidentiality and integrity via vectors related to AD Utilities. |
2016-10-25 |
5.5 |
CVE-2016-5570 CONFIRM |
oracle — applications_dba |
Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 12.1.3 and 12.2.3 through 12.2.6 allows remote administrators to affect confidentiality and integrity via vectors related to AD Utilities, a different vulnerability than CVE-2016-5567. |
2016-10-25 |
5.5 |
CVE-2016-5571 CONFIRM |
oracle — database |
Unspecified vulnerability in the Kernel PDB component in Oracle Database Server 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors. |
2016-10-25 |
4.4 |
CVE-2016-5572 CONFIRM |
oracle — jdk |
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5582. |
2016-10-25 |
6.8 |
CVE-2016-5573 CONFIRM |
oracle — common_applications |
Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote attackers to affect confidentiality via vectors related to Resources Module. |
2016-10-25 |
5.0 |
CVE-2016-5575 CONFIRM |
oracle — solaris |
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Kernel Zones. |
2016-10-25 |
4.9 |
CVE-2016-5576 CONFIRM |
oracle — secure_global_desktop |
Unspecified vulnerability in the Secure Global Desktop component in Oracle Virtualization 4.7 and 5.2 allows remote authenticated users to affect confidentiality and availability via vectors through Web Services. |
2016-10-25 |
5.5 |
CVE-2016-5580 CONFIRM |
oracle — irecruitment |
Unspecified vulnerability in the Oracle iRecruitment component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows local users to affect confidentiality, integrity, and availability via unknown vectors. |
2016-10-25 |
4.6 |
CVE-2016-5581 CONFIRM |
oracle — one-to-one_fulfillment |
Unspecified vulnerability in the Oracle One-to-One Fulfillment component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote attackers to affect integrity via unknown vectors. |
2016-10-25 |
5.0 |
CVE-2016-5583 CONFIRM |
oracle — interaction_center_intelligence |
Unspecified vulnerability in the Oracle Interaction Center Intelligence component in Oracle E-Business Suite 12.1.1 through 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors. |
2016-10-25 |
6.4 |
CVE-2016-5585 CONFIRM |
oracle — email_center |
Unspecified vulnerability in the Oracle Email Center component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote attackers to affect confidentiality and integrity via unknown vectors. |
2016-10-25 |
6.4 |
CVE-2016-5586 CONFIRM |
oracle — customer_interaction_history |
Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5591 and CVE-2016-5593. |
2016-10-25 |
6.4 |
CVE-2016-5587 CONFIRM |
oracle — customer_relationship_ management_technical_foundation |
Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote attackers to affect confidentiality and integrity via unknown vectors. |
2016-10-25 |
6.4 |
CVE-2016-5589 CONFIRM |
oracle — customer_interaction_history |
Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5587 and CVE-2016-5593. |
2016-10-25 |
6.4 |
CVE-2016-5591 CONFIRM |
oracle — customer_interaction_history |
Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5595. |
2016-10-25 |
6.4 |
CVE-2016-5592 CONFIRM |
oracle — customer_interaction_history |
Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5587 and CVE-2016-5591. |
2016-10-25 |
6.4 |
CVE-2016-5593 CONFIRM |
oracle — flexcube_universal_banking |
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, and 12.0.1 through 12.0.3 allows remote authenticated users to affect confidentiality via vectors related to INFRA. |
2016-10-25 |
4.0 |
CVE-2016-5594 CONFIRM |
oracle — customer_interaction_history |
Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5592. |
2016-10-25 |
6.4 |
CVE-2016-5595 CONFIRM |
oracle — customer_relationship_ management_technical_foundation |
Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote authenticated users to affect confidentiality via unknown vectors. |
2016-10-25 |
4.0 |
CVE-2016-5596 CONFIRM |
oracle — jdk |
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vectors related to Networking. |
2016-10-25 |
4.3 |
CVE-2016-5597 CONFIRM |
oracle — mysql_connectors |
Unspecified vulnerability in the MySQL Connector component 2.1.3 and earlier and 2.0.4 and earlier in Oracle MySQL allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Connector/Python. |
2016-10-25 |
6.8 |
CVE-2016-5598 CONFIRM |
oracle — advanced_supply_chain_planning |
Unspecified vulnerability in the Oracle Advanced Supply Chain Planning component in Oracle Supply Chain Products Suite 12.2.3 through 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to MscObieeSrvlt. |
2016-10-25 |
6.4 |
CVE-2016-5599 CONFIRM |
oracle — peoplesoft_enterprise_supply_chain_ management_services_procurement |
Unspecified vulnerability in the PeopleSoft Enterprise SCM Services Procurement component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. |
2016-10-25 |
5.5 |
CVE-2016-5600 CONFIRM |
oracle — flexcube_universal_banking |
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect confidentiality via vectors related to INFRA, a different vulnerability than CVE-2016-5621. |
2016-10-25 |
4.0 |
CVE-2016-5603 CONFIRM |
oracle — vm_virtualbox |
Unspecified vulnerability in the Oracle VM VirtualBox component before 5.1.4 in Oracle Virtualization allows remote attackers to affect confidentiality and integrity via vectors related to VRDE. |
2016-10-25 |
6.4 |
CVE-2016-5605 CONFIRM |
oracle — solaris |
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect integrity and availability via vectors related to Kernel Zones. |
2016-10-25 |
5.6 |
CVE-2016-5606 CONFIRM |
oracle — flexcube_universal_banking |
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to INFRA. |
2016-10-25 |
6.5 |
CVE-2016-5607 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.6.31 and earlier and 5.7.13 and earlier allows remote authenticated users to affect availability via vectors related to DML. |
2016-10-25 |
4.0 |
CVE-2016-5609 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.5.50 and earlier, 5.6.31 and earlier, and 5.7.13 and earlier allows remote authenticated users to affect availability via vectors related to DML. |
2016-10-25 |
4.0 |
CVE-2016-5612 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier allows local users to affect confidentiality, integrity, and availability via vectors related to Server: MyISAM. |
2016-10-25 |
4.4 |
CVE-2016-5616 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier allows local users to affect confidentiality, integrity, and availability via vectors related to Server: Error Handling. |
2016-10-25 |
4.4 |
CVE-2016-5617 CONFIRM |
oracle — flexcube_universal_banking |
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to INFRA, a different vulnerability than CVE-2016-5620. |
2016-10-25 |
5.5 |
CVE-2016-5619 CONFIRM |
oracle — flexcube_universal_banking |
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to INFRA, a different vulnerability than CVE-2016-5619. |
2016-10-25 |
5.5 |
CVE-2016-5620 CONFIRM |
oracle — flexcube_universal_banking |
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 and 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect confidentiality via vectors related to INFRA, a different vulnerability than CVE-2016-5603. |
2016-10-25 |
4.0 |
CVE-2016-5621 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier allows remote authenticated users to affect availability via vectors related to DML. |
2016-10-25 |
4.0 |
CVE-2016-5624 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.7.14 and earlier allows local users to affect confidentiality, integrity, and availability via vectors related to Server: Packaging. |
2016-10-25 |
4.4 |
CVE-2016-5625 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier allows remote authenticated users to affect availability via vectors related to GIS. |
2016-10-25 |
4.0 |
CVE-2016-5626 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.6.31 and earlier and 5.7.13 and earlier allows remote authenticated users to affect availability via vectors related to Server: InnoDB. |
2016-10-25 |
4.0 |
CVE-2016-5627 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: DML. |
2016-10-25 |
4.0 |
CVE-2016-5628 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier allows remote administrators to affect availability via vectors related to Server: Federated. |
2016-10-25 |
4.0 |
CVE-2016-5629 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.6.31 and earlier and 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: InnoDB. |
2016-10-25 |
4.0 |
CVE-2016-5630 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: Memcached. |
2016-10-25 |
4.0 |
CVE-2016-5631 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.7.14 and earlier allows remote administrators to affect availability via vectors related to Server: Optimizer. |
2016-10-25 |
4.0 |
CVE-2016-5632 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: Performance Schema, a different vulnerability than CVE-2016-8290. |
2016-10-25 |
4.0 |
CVE-2016-5633 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to RBR. |
2016-10-25 |
4.0 |
CVE-2016-5634 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: Security: Audit. |
2016-10-25 |
4.0 |
CVE-2016-5635 CONFIRM |
oracle — platform_security_for_java |
Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. |
2016-10-25 |
6.5 |
CVE-2016-8281 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier allows remote authenticated users to affect availability via vectors related to Server: Types. |
2016-10-25 |
4.0 |
CVE-2016-8283 CONFIRM |
oracle — peoplesoft_enterprise_human_capital_ management_candidate_gateway |
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote administrators to affect confidentiality and integrity via vectors related to Candidate Gateway. |
2016-10-25 |
4.9 |
CVE-2016-8285 CONFIRM |
oracle — mysql |
Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect integrity via vectors related to Server: InnoDB Plugin. |
2016-10-25 |
4.9 |
CVE-2016-8288 CONFIRM |
oracle — peoplesoft_enterprise_peopletools |
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Mobile Application Platform. |
2016-10-25 |
5.8 |
CVE-2016-8291 CONFIRM |
oracle — peoplesoft_enterprise_human_capital_ management_talent_acquisition_manager |
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to Talent Acquisition Manager. |
2016-10-25 |
5.8 |
CVE-2016-8292 CONFIRM |
oracle — peoplesoft_enterprise_peopletools |
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Integration Broker, a different vulnerability than CVE-2016-5529 and CVE-2016-5530. |
2016-10-25 |
5.8 |
CVE-2016-8293 CONFIRM |
oracle — peoplesoft_enterprise_peopletools |
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect confidentiality via unknown vectors. |
2016-10-25 |
4.0 |
CVE-2016-8294 CONFIRM |
oracle — peoplesoft_enterprise_human_capital_ management_time_and_labor |
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality via unknown vectors. |
2016-10-25 |
4.0 |
CVE-2016-8295 CONFIRM |
oracle — peoplesoft_enterprise_peopletools |
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to LDAP. |
2016-10-25 |
4.9 |
CVE-2016-8296 CONFIRM |
python — tgcaptcha2 |
TGCaptcha2 version 0.3.0 is vulnerable to a replay attack due to a missing nonce allowing attackers to use a single solved CAPTCHA multiple times. |
2016-10-25 |
5.0 |
CVE-2016-1000032 MISC MISC |
ruckus — wireless_h500 |
Ruckus Wireless H500 web management interface CSRF |
2016-10-25 |
6.8 |
CVE-2016-1000213 MISC |
ruckus — wireless_h500 |
Ruckus Wireless H500 web management interface authentication bypass |
2016-10-25 |
5.0 |
CVE-2016-1000214 MISC |
ruckus — wireless_h500 |
Ruckus Wireless H500 web management interface denial of service |
2016-10-25 |
5.0 |
CVE-2016-1000215 MISC |
shotwell_project — shotwell |
Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks. |
2016-10-25 |
4.3 |
CVE-2016-1000033 MISC. MISC |
yandex — yandex_browser |
Security WiFi bypass in Yandex Browser from version 15.10 to 15.12 allows remote attacker to sniff traffic in open or WEP-protected wi-fi networks despite of special security mechanism is enabled. |
2016-10-26 |
5.0 |
CVE-2016-8501 CONFIRM |
yandex — yandex_browser |
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript. |
2016-10-26 |
5.0 |
CVE-2016-8502 CONFIRM |
yandex — yandex_browser |
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript. |
2016-10-26 |
5.0 |
CVE-2016-8503 CONFIRM |
yandex — yandex_browser |
CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile. |
2016-10-26 |
4.3 |
CVE-2016-8504 CONFIRM |
yandex — yandex.browser |
XSS in Yandex Browser BookReader in Yandex browser for desktop for versions before 16.6. could be used by remote attacker for evaluation arbitrary javascript code. |
2016-10-26 |
4.3 |
CVE-2016-8505 CONFIRM |
yandex — yandex_browser |
XSS in Yandex Browser Translator in Yandex browser for desktop for versions from 15.12 to 16.2 could be used by remote attacker for evaluation arbitrary javascript code. |
2016-10-26 |
4.3 |
CVE-2016-8506 CONFIRM |