CVE-2016-3072
- EPSS 0.86%
- Published 07.06.2016 18:59:01
- Last modified 12.04.2025 10:46:40
Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated users to execute arbitrary SQL commands via the (1) sort_by or (2) sort_order parameter.
CVE-2015-5041
- EPSS 0.89%
- Published 06.06.2016 17:59:00
- Last modified 12.04.2025 10:46:40
The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods.
CVE-2016-0376
- EPSS 1.93%
- Published 03.06.2016 14:59:02
- Last modified 12.04.2025 10:46:40
The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not pr...
CVE-2016-0363
- EPSS 0.64%
- Published 03.06.2016 14:59:01
- Last modified 12.04.2025 10:46:40
The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke...
CVE-2016-0264
- EPSS 9.84%
- Published 24.05.2016 15:59:00
- Last modified 12.04.2025 10:46:40
Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows re...
- EPSS 93.75%
- Published 21.04.2016 11:00:21
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
CVE-2016-3079
- EPSS 0.43%
- Published 14.04.2016 14:59:08
- Last modified 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to systems/SystemEntitlements.do; (2) the label parameter to ...
CVE-2016-2103
- EPSS 0.24%
- Published 14.04.2016 14:59:07
- Last modified 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the list_1680466951_oldfilterval parameter to systems/PhysicalList.do or (2) unspecified vectors involvin...
CVE-2015-0284
- EPSS 0.41%
- Published 14.04.2016 14:59:00
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vul...
- EPSS 0.13%
- Published 11.04.2016 21:59:01
- Last modified 12.04.2025 10:46:40
Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary hosts or (2) remote authenticated users with the des...