CVE Feed

    Dashboard / CVE

    3.3
    Low

    CVE-2016-0202

    Last Modified: 20 Apr 2025

    A vulnerability has been identified in tasks, backend object generated for handling any action performed by the application in IBM Cloud Orchestrator. It is possible for an authenticated user to view any task of the current users domain.

    Published: 8 Feb 2017
    3.3
    Low

    CVE-2016-0206

    Last Modified: 20 Apr 2025

    IBM Cloud Orchestrator could allow a local authenticated attacker to cause the server to slow down for a short period of time by using a specially crafted and malformed URL.

    Published: 8 Feb 2017
    4.3
    Medium

    CVE-2016-0308

    Last Modified: 20 Apr 2025

    IBM Connections 5.5 and earlier is vulnerable to possible link manipulation attack that could result in the display of inappropriate background images.

    Published: 8 Feb 2017
    9.8
    Critical

    CVE-2016-8954

    Last Modified: 20 Apr 2025

    IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container or database.

    Published: 8 Feb 2017
    5.9
    Medium

    CVE-2016-5900

    Last Modified: 20 Apr 2025

    IBM Tealeaf Customer Experience on Cloud Network Capture Add-On could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the TLS certificate. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

    Published: 8 Feb 2017
    2.8
    Low

    CVE-2015-7494

    Last Modified: 20 Apr 2025

    A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API call, provided it would have been possible for the domain admin user to gain access to a resource identifier of the other domain.

    Published: 8 Feb 2017
    5.3
    Medium

    CVE-2016-0210

    Last Modified: 20 Apr 2025

    IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive information. By allowing HTTP OPTIONS method, a remote attacker could send a specially-crafted query to a vulnerable server running to cause the server to disclose sensitive information in the HTTP response.

    Published: 8 Feb 2017
    5.4
    Medium

    CVE-2016-0305

    Last Modified: 20 Apr 2025

    IBM Connections is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

    Published: 8 Feb 2017
    5.5
    Medium

    CVE-2016-0203

    Last Modified: 20 Apr 2025

    A vulnerability has been identified in the IBM Cloud Orchestrator task API. The task API might allow an authenticated user to view background information associated with actions performed on virtual machines in projects where the user belongs to.

    Published: 8 Feb 2017
    5.4
    Medium

    CVE-2016-0310

    Last Modified: 20 Apr 2025

    IBM Connections 5.5 and earlier is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain.

    Published: 8 Feb 2017
    5.5
    Medium

    CVE-2015-1976

    Last Modified: 20 Apr 2025

    IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to crash.

    Published: 8 Feb 2017
    4.4
    Medium

    CVE-2015-7418

    Last Modified: 20 Apr 2025

    IBM WebSphere eXtreme Scale and the WebSphere DataPower XC10 Appliance allow some sensitive data to linger in memory instead of being overwritten which could allow a local user with administrator privileges to obtain sensitive information.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2016-0214

    Last Modified: 20 Apr 2025

    IBM Tivoli Endpoint Manager could allow a remote attacker to upload arbitrary files. A remote attacker could exploit this vulnerability to upload a malicious file. The only way that file would be executed would be through a phishing attack to trick an unsuspecting victim to execute the file.

    Published: 8 Feb 2017
    4.3
    Medium

    CVE-2016-0307

    Last Modified: 20 Apr 2025

    IBM Connections 5.5 and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned responses.

    Published: 8 Feb 2017
    6.1
    Medium

    CVE-2016-5902

    Last Modified: 20 Apr 2025

    IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 8 Feb 2017
    4.7
    Medium

    CVE-2016-5918

    Last Modified: 20 Apr 2025

    IBM Tivoli Storage Manager HSM for Windows displays the encrypted Tivoli Storage Manager password in application trace output if the password access option is prompt and the password is changed.

    Published: 8 Feb 2017
    7.3
    High

    CVE-2016-5934

    Last Modified: 20 Apr 2025

    IBM Tivoli Storage Manager FastBack installer could allow a remote attacker to execute arbitrary code on the system. By placing a specially-crafted DLL in the victim's path, an attacker could exploit this vulnerability when the installer is executed to run arbitrary code on the system with privileges of the victim.

    Published: 8 Feb 2017
    9.8
    Critical

    CVE-2016-9005

    Last Modified: 20 Apr 2025

    IBM System Storage TS3100-TS3200 Tape Library could allow an unauthenticated user with access to the company network, to change a user's password and gain remote access to the system.

    Published: 8 Feb 2017
    5.3
    Medium

    CVE-2016-9686

    Last Modified: 20 Apr 2025

    The Puppet Communications Protocol (PCP) Broker incorrectly validates message header sizes. An attacker could use this to crash the PCP Broker, preventing commands from being sent to agents. This is resolved in Puppet Enterprise 2016.4.3 and 2016.5.2.

    Published: 8 Feb 2017
    5.5
    Medium

    CVE-2015-5013

    Last Modified: 20 Apr 2025

    The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can access.

    Published: 8 Feb 2017
    4.3
    Medium

    CVE-2016-2866

    Last Modified: 20 Apr 2025

    An unspecified vulnerability in IBM Jazz Team Server may disclose some deployment information to an authenticated user.

    Published: 8 Feb 2017
    5.4
    Medium

    CVE-2016-6032

    Last Modified: 20 Apr 2025

    IBM Rational Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 8 Feb 2017
    4.3
    Medium

    CVE-2016-9748

    Last Modified: 20 Apr 2025

    IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be used for further attacks against the system.

    Published: 8 Feb 2017
    5.4
    Medium

    CVE-2017-1127

    Last Modified: 20 Apr 2025

    IBM Rational DOORS Next Generation 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 8 Feb 2017
    5.4
    Medium

    CVE-2017-1128

    Last Modified: 20 Apr 2025

    IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 8 Feb 2017
    9.8
    Critical

    CVE-2017-2765

    Last Modified: 20 Apr 2025

    EMC Isilon InsightIQ 4.1.0, 4.0.1, 4.0.0, 3.2.2, 3.2.1, 3.2.0, 3.1.1, 3.1.0, 3.0.1, 3.0.0 is affected by an authentication bypass vulnerability that could potentially be exploited by attackers to compromise the affected system.

    Published: 8 Feb 2017
    5.9
    Medium

    CVE-2016-0270

    Last Modified: 20 Apr 2025

    IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging the reuse of a nonce in a session and a "forbidden attack." NOTE: this CVE has been incorrectly used for GCM nonce reuse issues in other products; see CVE-2016-10213 for the A10 issue, CVE-2016-10212 for the Radware issue, and CVE-2017-5933 for the Citrix issue.

    Published: 8 Feb 2017
    5.9
    Medium

    CVE-2016-10212

    Last Modified: 20 Apr 2025

    Radware devices use the same value for the first two GCM nonces, which allows remote attackers to obtain the authentication key and spoof data via a "forbidden attack," a similar issue to CVE-2016-0270. NOTE: this issue may be due to the use of a third-party Cavium product.

    Published: 8 Feb 2017
    5.9
    Medium

    CVE-2016-10213

    Last Modified: 20 Apr 2025

    A10 AX1030 and possibly other devices with software before 2.7.2-P8 uses random GCM nonce generations, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging a reused nonce in a session and a "forbidden attack," a similar issue to CVE-2016-0270.

    Published: 8 Feb 2017
    5.9
    Medium

    CVE-2016-8492

    Last Modified: 20 Apr 2025

    The implementation of an ANSI X9.31 RNG in Fortinet FortiGate allows attackers to gain unauthorized read access to data handled by the device via IPSec/TLS decryption.

    Published: 8 Feb 2017
    5.9
    Medium

    CVE-2017-5933

    Last Modified: 20 Apr 2025

    Citrix NetScaler ADC and NetScaler Gateway 10.5 before Build 65.11, 11.0 before Build 69.12/69.123, and 11.1 before Build 51.21 randomly generates GCM nonces, which makes it marginally easier for remote attackers to obtain the GCM authentication key and spoof data by leveraging a reused nonce in a session and a "forbidden attack," a similar issue to CVE-2016-0270.

    Published: 8 Feb 2017
    7
    High

    CVE-2016-8421

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32451104. References: QC-CR#1087797.

    Published: 8 Feb 2017
    4.7
    Medium

    CVE-2016-8414

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the Qualcomm Secure Execution Environment Communicator could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31704078. References: QC-CR#1076407.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2017-0405

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in Surfaceflinger could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Surfaceflinger process. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-31960359.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2017-0407

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. This affects the libhevc library. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32873375.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2017-0408

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in libgdx could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 7.1.1. Android ID: A-32769670.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2017-0409

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in libstagefright could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-31999646.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2017-0410

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-31929765.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2017-0411

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-33042690.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2017-0412

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-33039926.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2017-0415

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32706020.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2017-0416

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32886609.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2017-0417

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32705438.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2017-0418

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32703959.

    Published: 8 Feb 2017
    7.8
    High

    CVE-2017-0419

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32220769.

    Published: 8 Feb 2017
    5.5
    Medium

    CVE-2017-0420

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in AOSP Mail could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32615212.

    Published: 8 Feb 2017
    5.5
    Medium

    CVE-2017-0421

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the Framework APIs could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain access to data that the application does not have access to. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32555637.

    Published: 8 Feb 2017
    7.5
    High

    CVE-2017-0422

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in Bionic DNS could enable a remote attacker to use a specially crafted network packet to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32322088.

    Published: 8 Feb 2017
    5.5
    Medium

    CVE-2017-0424

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its permission levels. This issue is rated as Moderate because it is a general bypass for a user level defense in depth or exploit mitigation technology in a privileged process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32322450.

    Published: 8 Feb 2017
    5.5
    Medium

    CVE-2017-0426

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the Filesystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-32799236.

    Published: 8 Feb 2017