CVE-2016-0227
published 2016-03-03CVE-2016-0227: Cross-site scripting (XSS) vulnerability in the document-list control implementation in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through…
PriorityP423medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.92%
56.6th percentile
Cross-site scripting (XSS) vulnerability in the document-list control implementation in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, and 8.5.5 and 8.5.6 through 8.5.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
| ibm | business_process_manager | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8714 R: Buffer overflow in the LoadEncoding functionality
bugzilla·2017-03-10·CVSS 8.8
CVE-2016-8714 [HIGH] CVE-2016-8714 R: Buffer overflow in the LoadEncoding functionality
CVE-2016-8714 R: Buffer overflow in the LoadEncoding functionality
An exploitable buffer overflow vulnerability exists in the LoadEncoding functionality of the R programming language version. A specially crafted R script can cause a buffer overflow resulting in a memory corruption. An attacker can send a malicious R script to trigger this vulnerability.
External References:
http://www.talosintelligence.com/reports/TALOS-2016-0227/
Discussion:
Created R tracking bugs for this issue:
Affects: epel-all [bug 1431174]
Affects: fedora-all [bug 1431173]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
Talos
Vulnerability Spotlight: R - PDF LoadEncoding Code Execution Vulnerability
blogs_talos·2017-03-09·CVSS 8.8
CVE-2016-8714 [HIGH] Vulnerability Spotlight: R - PDF LoadEncoding Code Execution Vulnerability
Vulnerability Discovered by Cory Duplantis of Cisco Talos
### Overview Talos is disclosing TALOS-2016-0227 / CVE-2016-8714 which is a buffer overflow vulnerability in the LoadEncoding functionality of the R programming language version 3.3.0. TheR programming languageis commonly used in statistical computing and is supported by the R Foundation for Statistical Computing. R is praised for having a large variety of statistical and graphical features. The vulnerability is specifically related to the creation of a PDF document.
### Details This vulnerability specifically affects the PDF creation capabilities of R. During the creation of a PDF document, the file containing the encoding array can be specified by the user. The following command can specify the encoding file for a PDF.
While lo
http://www-01.ibm.com/support/docview.wss?uid=swg1JR55152http://www-01.ibm.com/support/docview.wss?uid=swg21978058http://www.securitytracker.com/id/1035175http://www-01.ibm.com/support/docview.wss?uid=swg1JR55152http://www-01.ibm.com/support/docview.wss?uid=swg21978058http://www.securitytracker.com/id/1035175
2016-03-03
Published