CVE-2016-2011
published 2016-05-07CVE-2016-2011: Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to…
PriorityP423medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.93%
56.4th percentile
Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2010.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| drupal | phpmailer_3rd_party_library | — | — |
| hackerone | webdriver-launcher_node_module | 0 – 0.1.3 | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| msrc | microsoft_excel_for_mac_2011 | — | — |
| msrc | microsoft_office_2010_service_pack_2 | — | — |
| msrc | microsoft_office_compatibility_pack_service_pack_3 | — | — |
| msrc | microsoft_office_web_apps_2010_service_pack_2 | — | — |
| msrc | microsoft_office_word_viewer | — | — |
| msrc | microsoft_outlook_2016_for_mac | — | — |
| msrc | microsoft_word_2007_service_pack_3 | — | — |
| msrc | microsoft_word_2010_service_pack_2 | — | — |
| msrc | microsoft_word_for_mac_2011 | — | — |
| msrc | word_automation_services_on_microsoft_sharepoint_server_2013_service_pack_1 | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat6.8MEDIUM
vendor_msrc6.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fp3x-3m47-hqv3: Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9
ghsa_unreviewed·2022-05-17·CVSS 5.4
CVE-2016-2010 [MEDIUM] CWE-79 GHSA-fp3x-3m47-hqv3: Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9
Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2011.
GHSA
GHSA-m63p-gcqw-3rr6: Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9
ghsa_unreviewed·2022-05-17·CVSS 5.4
CVE-2016-2011 [MEDIUM] CWE-79 GHSA-m63p-gcqw-3rr6: Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9
Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2010.
GHSA
Downloads Resources over HTTP in webdriver-launcher
ghsa·2019-02-18
CVE-2016-10651 [HIGH] CWE-311 Downloads Resources over HTTP in webdriver-launcher
Downloads Resources over HTTP in webdriver-launcher
Affected versions of `webdriver-launcher` insecurely download an executable over an unencrypted HTTP connection.
In scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `webdriver-launcher`.
## Recommendation
No patch is currently available for this vulnerability, and the package has not seen an update since 2011.
The best mitigation is currently to avoid using this package, using a different package if available.
Alternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a p
Kernel
namei: allow restricted O_CREAT of FIFOs and regular files
kernel_security·2018-08-23·CVSS 7.2
CVE-2000-1134 [HIGH] namei: allow restricted O_CREAT of FIFOs and regular files
namei: allow restricted O_CREAT of FIFOs and regular files
Disallows open of FIFOs or regular files not owned by the user in world
writable sticky directories, unless the owner is the same as that of the
directory or the file is opened without the O_CREAT flag. The purpose
is to make data spoofing attacks harder. This protection can be turned
on and off separately for FIFOs and regular files via sysctl, just like
the symlinks/hardlinks protection. This patch is based on Openwall's
"HARDEN_FIFO" feature by Solar Designer.
This is a brief list of old vulnerabilities that could have been prevented
by this feature, some of them even allow for privilege escalation:
CVE-2000-1134
CVE-2007-3852
CVE-2008-0525
CVE-2009-0416
CVE-2011-4834
CVE-2015-1838
CVE-2015-7442
CVE-2016-7489
This list is no
GHSA
Downloads Resources over HTTP in jstestdriver
ghsa·2018-08-15
CVE-2016-10643 [HIGH] CWE-311 Downloads Resources over HTTP in jstestdriver
Downloads Resources over HTTP in jstestdriver
Affected versions of `jstestdriver` insecurely download an executable over an unencrypted HTTP connection.
In scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `jstestdriver`.
## Recommendation
No patch is currently available for this vulnerability, and the package has not seen an update since 2011.
The best mitigation is currently to avoid using this package, using a different package if available.
Alternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, th
Microsoft
Microsoft Outlook for Mac Spoofing Vulnerability
vendor_msrc·2017-06-13·CVSS 6.5
CVE-2017-8545 [MEDIUM] Microsoft Outlook for Mac Spoofing Vulnerability
Microsoft Outlook for Mac Spoofing Vulnerability
Description: A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html or treat it in a safe manner. An attacker who successfully tricked the user could gain access to the user's authentication information or login credentials.
In an email attack scenario an attacker could exploit the vulnerability by sending an email with specific HTML tags, that could display a malicious authentication prompt.
The security update addresses the vulnerability by correcting how Outlook for Mac validates and sanitizes html input.
FAQ: Microsoft has released an update for Microsoft Office for Mac 2011 and Microsoft Office for Mac 2016 as a defense-in-depth measure.
Microsoft Office: Microsoft Office
Impact: Spoofing
Exploit S
Drupal
PHPmailer 3rd party library - PSA-2016-004
vendor_drupal·2016-12-26·CVSS 9.8
CVE-2016-10033 [CRITICAL] PHPmailer 3rd party library - PSA-2016-004
Title: PHPmailer 3rd party library - PSA-2016-004
Vulnerability Type: PHPmailer 3rd party library
Description: Advisory ID: DRUPAL-SA-PSA-2016-004 Project: PHPMailer (third-party library) Version: 7.x, 8.x Date: 2016-December-26 Security risk: 23/25 ( Highly Critical ) AC:None/A:User/CI:All/II:All/E:Exploit/TD:All Vulnerability: Arbitrary PHP code execution Description The PHPMailer and SMTP modules (and maybe others) add support for sending e-mails using the 3rd party PHPMailer library. In general the Drupal project does not create advisories for 3rd party libraries. Drupal site maintainers should pay attention to the notifications provided by those 3rd party libraries as outlined in PSA-2011-002 - External libraries and plugins . However, given the extreme criticality of this issue and
Red Hat
jasper: heap buffer overflow in jpc_dec_cp_setfromcox() (rejected duplicate of CVE-2011-4516)
vendor_redhat·2016-10-17·CVSS 6.8
CVE-2016-8880 [MEDIUM] CWE-122 jasper: heap buffer overflow in jpc_dec_cp_setfromcox() (rejected duplicate of CVE-2011-4516)
jasper: heap buffer overflow in jpc_dec_cp_setfromcox() (rejected duplicate of CVE-2011-4516)
[REJECTED CVE] A heap-based buffer overflow flaw was found in the way JasPer decoded JPEG 2000 compressed image files. An attacker could create a malicious JPEG 2000 compressed image file that, when opened, would cause applications that use JasPer (such as Nautilus) to crash or, potentially, execute arbitrary code.
Statement: This flaw was found to be a duplicate of CVE-2011-4516. Please see https://access.redhat.com/security/cve/CVE-2011-4516 for information about affected products and security errata.
Package: netpbm (Red Hat Enterprise Linux 5) - Not affected
Package: jasper (Red Hat Enterprise Linux 6) - Not affected
Package: jasper (Red Hat Enterprise Linux 7) - Not affected
Package: mi
Red Hat
jasper: insufficient memory allocation in jpc_crg_getparms() (rejected duplicate of CVE-2011-4517)
vendor_redhat·2016-10-17·CVSS 6.8
CVE-2016-8881 [MEDIUM] CWE-122 jasper: insufficient memory allocation in jpc_crg_getparms() (rejected duplicate of CVE-2011-4517)
jasper: insufficient memory allocation in jpc_crg_getparms() (rejected duplicate of CVE-2011-4517)
[REJECTED CVE] A heap-based buffer overflow flaw was found in the way JasPer decoded JPEG 2000 compressed image files. An attacker could create a malicious JPEG 2000 compressed image file that, when opened, would cause applications that use JasPer (such as Nautilus) to crash or, potentially, execute arbitrary code.
Statement: This flaw was found to be a duplicate of CVE-2011-4517. Please see https://access.redhat.com/security/cve/CVE-2011-4517 for information about affected products and security errata.
Package: netpbm (Red Hat Enterprise Linux 5) - Not affected
Package: jasper (Red Hat Enterprise Linux 6) - Not affected
Package: jasper (Red Hat Enterprise Linux 7) - Not affected
Packag
No detection rules found.
Exploit-DB
Microsoft Windows (x86) - 'NDISTAPI' Local Privilege Escalation (MS11-062)
exploitdb·2016-10-24
CVE-2011-1974 Microsoft Windows (x86) - 'NDISTAPI' Local Privilege Escalation (MS11-062)
Microsoft Windows (x86) - 'NDISTAPI' Local Privilege Escalation (MS11-062)
---
/*
################################################################
# Exploit Title: Windows x86 (all versions) NDISTAPI privilege escalation (MS11-062)
# Date: 2016-10-24
# Exploit Author: Tomislav Paskalev
# Vulnerable Software:
# Windows XP SP3 x86
# Windows XP Pro SP2 x64
# Windows Server 2003 SP2 x86
# Windows Server 2003 SP2 x64
# Windows Server 2003 SP2 Itanium-based Systems
# Supported Vulnerable Software:
# Windows XP SP3 x86
# Windows Server 2003 SP2 x86
# Tested Software:
# Windows XP Pro SP3 x86 EN [5.1.2600]
# Windows Server 2003 Ent SP2 EN [5.2.3790]
# CVE ID: 2011-1974
################################################################
# Vulnerability description:
# An elevation of privilege vulner
Exploit-DB
Microsoft Windows (x86) - 'afd.sys' Local Privilege Escalation (MS11-046)
exploitdb·2016-10-18
CVE-2011-1249 Microsoft Windows (x86) - 'afd.sys' Local Privilege Escalation (MS11-046)
Microsoft Windows (x86) - 'afd.sys' Local Privilege Escalation (MS11-046)
---
/*
################################################################
# Exploit Title: Windows x86 (all versions) AFD privilege escalation (MS11-046)
# Date: 2016-10-16
# Exploit Author: Tomislav Paskalev
# Vulnerable Software:
# Windows XP SP3 x86
# Windows XP Pro SP2 x64
# Windows Server 2003 SP2 x86
# Windows Server 2003 SP2 x64
# Windows Server 2003 SP2 Itanium-based Systems
# Windows Vista SP1 x86
# Windows Vista SP2 x86
# Windows Vista SP1 x64
# Windows Vista SP2 x64
# Windows Server 2008 x86
# Windows Server 2008 SP2 x86
# Windows Server 2008 x64
# Windows Server 2008 SP2 x64
# Windows Server 2008 Itanium-based Systems
# Windows Server 2008 SP2 Itanium-based Systems
# Windows 7 x86
# Windows 7 SP1 x86
# Wi
Metasploit
AF_PACKET chocobo_root Privilege Escalation
metasploit·CVSS 7.8
CVE-2016-8655 [HIGH] AF_PACKET chocobo_root Privilege Escalation
AF_PACKET chocobo_root Privilege Escalation
This module exploits a race condition and use-after-free in the packet_set_ring function in net/packet/af_packet.c (AF_PACKET) in the Linux kernel to execute code as root (CVE-2016-8655). The bug was initially introduced in 2011 and patched in 2016 in version 4.4.0-53.74, potentially affecting a large number of kernels; however this exploit targets only systems using Ubuntu (Trusty / Xenial) kernels 4.4.0 < 4.4.0-53, including Linux distros based on Ubuntu, such as Linux Mint. The target system must have unprivileged user namespaces enabled, two or more CPU cores, and SMAP must be disabled. Bypasses for SMEP and KASLR are included. Failed exploitation may crash the kernel. This module has been tested successfully on Linux Mint 17.3 (x86_64); Lin
Bugzilla
CVE-2011-2715 drupal: SQL injection due to insufficient sanitization of table names or column names
bugzilla·2020-02-06·CVSS 9.8
CVE-2011-2715 [CRITICAL] CVE-2011-2715 drupal: SQL injection due to insufficient sanitization of table names or column names
CVE-2011-2715 drupal: SQL injection due to insufficient sanitization of table names or column names
An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.
Reference:
https://www.drupal.org/node/1056470
Discussion:
Created drupal6 tracking bugs for this issue:
Affects: epel-6 [bug 1799484]
---
This CVE is for 6.20. EPEL6 has already been at 6.38 for about 4 years (https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-00c45982f6) and in addition several security backports for about a year (https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-67b3f85ea0).
Dependent bug is closed. Please close this bug as well.
---
See previous comment... please close this bug
Bugzilla
CVE-2011-2714 drupal: XSS due to insufficient sanitization of table descriptions, field names, or labels before display
bugzilla·2020-01-28·CVSS 6.1
CVE-2011-2714 [MEDIUM] CVE-2011-2714 drupal: XSS due to insufficient sanitization of table descriptions, field names, or labels before display
CVE-2011-2714 drupal: XSS due to insufficient sanitization of table descriptions, field names, or labels before display
A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.
Reference:
https://www.drupal.org/node/1056470
Discussion:
Created drupal6 tracking bugs for this issue:
Affects: epel-6 [bug 1795699]
---
This CVE is for 6.20. EPEL6 has already been at 6.38 for about 4 years (https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-00c45982f6) and in addition several security backports for about a year (https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-67b3f85ea0).
Dependent bug is closed. Please close this bug as well.
---
Can this bug be clo
Bugzilla
CVE-2011-5326 imlib2: divide by zero on 2x1 ellipse
bugzilla·2016-04-01·CVSS 7.5
CVE-2011-5326 [HIGH] CVE-2011-5326 imlib2: divide by zero on 2x1 ellipse
CVE-2011-5326 imlib2: divide by zero on 2x1 ellipse
A vulnerability was found in imlib2. Attempting to draw a 2x1 radi ellipse with imlib_image_draw_ellipse() will result in a floating point exception.
Original bug report (reproducer attached):
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=639414
Discussion:
Created imlib2 tracking bugs for this issue:
Affects: fedora-all [bug 1323082]
Affects: epel-6 [bug 1323083]
Affects: epel-7 [bug 1323084]
---
Upstream fix:
https://git.enlightenment.org/legacy/imlib2.git/commit/?id=c94d83ccab15d5ef02f88d42dce38ed3f0892882
CVE assignment:
http://seclists.org/oss-sec/2016/q2/49
---
imlib2-1.4.8-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
---
imlib2-1.
2016-05-07
Published