CVE-2016-0707
published 2016-05-18CVE-2016-0707: The agent in Apache Ambari before 2.1.2 uses weak permissions for the (1) /var/lib/ambari-agent/data and (2) /var/lib/ambari-agent/keys directories, which…
PriorityP49low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.40%
32.8th percentile
The agent in Apache Ambari before 2.1.2 uses weak permissions for the (1) /var/lib/ambari-agent/data and (2) /var/lib/ambari-agent/keys directories, which allows local users to obtain sensitive information by reading files in the directories.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ambari | <= 2.1.1 | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1665 chromium-browser: information leak in v8
bugzilla·2016-04-29·CVSS 6.5
CVE-2016-1665 [MEDIUM] CVE-2016-1665 chromium-browser: information leak in v8
CVE-2016-1665 chromium-browser: information leak in v8
An information leak flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=606181
External References:
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_28.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0707 https://rhn.redhat.com/errata/RHSA-2016-0707.html
Bugzilla
CVE-2016-1664 chromium-browser: address bar spoofing
bugzilla·2016-04-29·CVSS 4.3
CVE-2016-1664 [MEDIUM] CVE-2016-1664 chromium-browser: address bar spoofing
CVE-2016-1664 chromium-browser: address bar spoofing
An address bar spoofing flaw flaw was identified in the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=597322
External References:
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_28.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0707 https://rhn.redhat.com/errata/RHSA-2016-0707.html
Bugzilla
CVE-2016-1660 chromium-browser: out-of-bounds write in blink
bugzilla·2016-04-29·CVSS 8.8
CVE-2016-1660 [HIGH] CVE-2016-1660 chromium-browser: out-of-bounds write in blink
CVE-2016-1660 chromium-browser: out-of-bounds write in blink
An out-of-bounds write flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=574802
External References:
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_28.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0707 https://rhn.redhat.com/errata/RHSA-2016-0707.html
Bugzilla
CVE-2016-1663 chromium-browser: use-after-free in blink's v8 bindings
bugzilla·2016-04-29·CVSS 8.8
CVE-2016-1663 [HIGH] CVE-2016-1663 chromium-browser: use-after-free in blink's v8 bindings
CVE-2016-1663 chromium-browser: use-after-free in blink's v8 bindings
A use-after-free flaw was found in the Blink's V8 bindings in the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=603987
External References:
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_28.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0707 https://rhn.redhat.com/errata/RHSA-2016-0707.html
Bugzilla
CVE-2016-1661 chromium-browser: memory corruption in cross-process frames
bugzilla·2016-04-29·CVSS 8.0
CVE-2016-1661 [HIGH] CVE-2016-1661 chromium-browser: memory corruption in cross-process frames
CVE-2016-1661 chromium-browser: memory corruption in cross-process frames
A memory corruption flaw was found in the cross-process frames component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=601629
External References:
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_28.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0707 https://rhn.redhat.com/errata/RHSA-2016-0707.html
Bugzilla
CVE-2016-1666 chromium-browser: various fixes from internal audits
bugzilla·2016-04-29·CVSS 9.8
CVE-2016-1666 [CRITICAL] CVE-2016-1666 chromium-browser: various fixes from internal audits
CVE-2016-1666 chromium-browser: various fixes from internal audits
Various fixes from internal audits, fuzzing and other initiatives.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=607652
External References:
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_28.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0707 https://rhn.redhat.com/errata/RHSA-2016-0707.html
Bugzilla
CVE-2016-1662 chromium-browser: use-after-free in extensions
bugzilla·2016-04-29·CVSS 9.8
CVE-2016-1662 [CRITICAL] CVE-2016-1662 chromium-browser: use-after-free in extensions
CVE-2016-1662 chromium-browser: use-after-free in extensions
An use-after-free flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=603732
External References:
http://googlechromereleases.blogspot.com/2016/04/stable-channel-update_28.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:0707 https://rhn.redhat.com/errata/RHSA-2016-0707.html
2016-05-18
Published