CVE-2016-0241
published 2016-10-22CVE-2016-0241: IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated…
PriorityP348high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.80%
75.9th percentile
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to spoof administrator accounts by sending a modified login request over HTTP.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_guardium_database_activity_monitor | — | — |
| ibm | security_guardium_database_activity_monitor | — | — |
| ibm | security_guardium_database_activity_monitor | — | — |
| ibm | security_guardium_database_activity_monitor | — | — |
| ibm | security_guardium_database_activity_monitor | — | — |
| ibm | security_guardium_database_activity_monitor | — | — |
| ibm | security_guardium_database_activity_monitor | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1628 chromium-browser: out-of-bounds read in PDFium
bugzilla·2016-02-22·CVSS 6.3
CVE-2016-1628 [MEDIUM] CVE-2016-1628 chromium-browser: out-of-bounds read in PDFium
CVE-2016-1628 chromium-browser: out-of-bounds read in PDFium
A out-of-bounds read flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=571479
External References:
http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0241 https://rhn.redhat.com/errata/RHSA-2016-0241.html
Bugzilla
CVE-2016-1627 chromium-browser: various fixes from internal audits
bugzilla·2016-02-10·CVSS 8.8
CVE-2016-1627 [HIGH] CVE-2016-1627 chromium-browser: various fixes from internal audits
CVE-2016-1627 chromium-browser: various fixes from internal audits
Various fixes from internal audits, fuzzing and other initiatives.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=585517
External References:
http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0241 https://rhn.redhat.com/errata/RHSA-2016-0241.html
Bugzilla
CVE-2016-1622 chromium-browser: same-origin bypass in Extensions
bugzilla·2016-02-10·CVSS 8.8
CVE-2016-1622 [HIGH] CVE-2016-1622 chromium-browser: same-origin bypass in Extensions
CVE-2016-1622 chromium-browser: same-origin bypass in Extensions
A same-origin bypass flaw was found in the Extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=546677
External References:
http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0241 https://rhn.redhat.com/errata/RHSA-2016-0241.html
Bugzilla
CVE-2016-1626 chromium-browser: out-of-bounds read in PDFium
bugzilla·2016-02-10·CVSS 4.3
CVE-2016-1626 [MEDIUM] CVE-2016-1626 chromium-browser: out-of-bounds read in PDFium
CVE-2016-1626 chromium-browser: out-of-bounds read in PDFium
A out-of-bounds read flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=571480
External References:
http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0241 https://rhn.redhat.com/errata/RHSA-2016-0241.html
Bugzilla
CVE-2016-1625 chromium-browser: navigation bypass in Chrome Instant
bugzilla·2016-02-10·CVSS 4.3
CVE-2016-1625 [MEDIUM] CVE-2016-1625 chromium-browser: navigation bypass in Chrome Instant
CVE-2016-1625 chromium-browser: navigation bypass in Chrome Instant
A navigation bypass flaw was found in the Chrome Instant component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=509313
External References:
http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0241 https://rhn.redhat.com/errata/RHSA-2016-0241.html
Bugzilla
CVE-2016-1624 chromium-browser: buffer overflow in Brotli
bugzilla·2016-02-10·CVSS 8.8
CVE-2016-1624 [HIGH] CVE-2016-1624 chromium-browser: buffer overflow in Brotli
CVE-2016-1624 chromium-browser: buffer overflow in Brotli
A buffer overflow flaw was found in the Brotli component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=583607
External References:
http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0241 https://rhn.redhat.com/errata/RHSA-2016-0241.html
Bugzilla
CVE-2016-1623 chromium-browser: same-origin bypass in DOM
bugzilla·2016-02-10·CVSS 8.8
CVE-2016-1623 [HIGH] CVE-2016-1623 chromium-browser: same-origin bypass in DOM
CVE-2016-1623 chromium-browser: same-origin bypass in DOM
A same-origin bypass flaw was found in the DOM component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=577105
External References:
http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0241 https://rhn.redhat.com/errata/RHSA-2016-0241.html
2016-10-22
Published