CVE-2016-2013
published 2016-05-07CVE-2016-2013: HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to obtain sensitive information via unspecified…
PriorityP434medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.85%
76.6th percentile
HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to obtain sensitive information via unspecified vectors.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bundler | bundler | >= 1.0.0 < 2.0.0 | 2.0.0 |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| hp | network_node_manager_i | — | — |
| jenkins | async_http_client_plugin | — | — |
| jenkins | build_failure_analyzer_plugin | — | — |
| jenkins | image_gallery_plugin | — | — |
| jenkins | tap_plugin | — | — |
| jenkins | users_of_build_failure_analyzer_plugin | — | — |
| jenkins | users_of_image_gallery_plugin | — | — |
| jenkins | users_of_tap_plugin | — | — |
| msrc | microsoft_exchange_server_2010_service_pack_3 | — | — |
| msrc | microsoft_exchange_server_2013_cumulative_update_21 | — | — |
| msrc | microsoft_exchange_server_2013_cumulative_update_22 | — | — |
| msrc | microsoft_exchange_server_2013_cumulative_update_23 | — | — |
| msrc | microsoft_exchange_server_2013_service_pack_1 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_10 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_11 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_12 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_13 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_14 | — | — |
| msrc | microsoft_exchange_server_2016_cumulative_update_15 | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
ghsa5.0MEDIUM
osv7.5HIGH
vendor_redhat9.3CRITICAL
vendor_msrc9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-46p3-6h94-2rqm: HPE Network Node Manager i (NNMi) 9
ghsa_unreviewed·2022-05-17
CVE-2016-2013 [MEDIUM] CWE-200 GHSA-46p3-6h94-2rqm: HPE Network Node Manager i (NNMi) 9
HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to obtain sensitive information via unspecified vectors.
GHSA
Bundler allows attacker to inject arbitrary code via secondary Gem source
ghsa·2022-05-14·CVSS 5.0
CVE-2016-7954 [MEDIUM] CWE-94 Bundler allows attacker to inject arbitrary code via secondary Gem source
Bundler allows attacker to inject arbitrary code via secondary Gem source
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.
OSV
linux-lts-vivid vulnerabilities
osv·2016-03-14·CVSS 6.2
CVE-2016-3134 linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
Ben Hawkes discovered that the Linux netfilter implementation did not
correctly perform validation when handling IPT_SO_SET_REPLACE events. A
local unprivileged attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code with administrative
privileges. (CVE-2016-3134)
It was discovered that the Linux kernel did not properly enforce rlimits
for file descriptors sent over UNIX domain sockets. A local attacker could
use this to cause a denial of service. (CVE-2013-4312)
Ralf Spenneberg discovered that the USB driver for Clie devices in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7566)
Ralf
OSV
perl vulnerabilities
osv·2016-03-02·CVSS 7.5
CVE-2013-7422 perl vulnerabilities
perl vulnerabilities
It was discovered that Perl incorrectly handled certain regular expressions
with an invalid backreference. An attacker could use this issue to cause
Perl to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2013-7422)
Markus Vervier discovered that Perl incorrectly handled nesting in the
Data::Dumper module. An attacker could use this issue to cause Perl to
consume memory and crash, resulting in a denial of service. (CVE-2014-4330)
Stephane Chazelas discovered that Perl incorrectly handled duplicate
environment variables. An attacker could possibly use this issue to bypass
the taint protection mechanism. (CVE-2016-2381)
Microsoft
Microsoft Exchange Server Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 9.1
CVE-2021-26855 [CRITICAL] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
FAQ: Is this vulnerability being used in an active attack?
Yes. The vulnerability described in this CVE is one of four vulnerabilities that are being exploited in an active attack. The security updates address this attack. More information can be found here: https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server.
What is the target for this attack?
The initial attack in this attack chain targets an Exchange On-prem server that is able to receive untrusted connections from an external source. In addition, the Exchange server would need to be running Microsoft Exchange Server 2013, 2016, or 2019.
Where can I get more information about how to protect myself from the vulnerabilities?
Pleas
Jenkins
Jenkins Security Advisory 2016-06-20
vendor_jenkins·2016-06-20·CVSS 4.3
CVE-2013-7397 [MEDIUM] Jenkins Security Advisory 2016-06-20
Title: Jenkins Security Advisory 2016-06-20
Jenkins Security Advisory 2016-06-20
This advisory announces vulnerabilities in these Jenkins plugins:
Async Http Client Plugin
Build Failure Analyzer
Image Gallery Plugin
TAP Plugin
Description
Path traversal vulnerability in TAP Plugin
SECURITY-85 / CVE-2016-4986
The plugin did not correctly filter a parameter and allowed reading arbitrary files on the file system.
Path traversal vulnerability in Image Gallery Plugin
SECURITY-278 / CVE-2016-4987
The plugin did not correctly validate form fields and allowed listing arbitrary directories and reading arbitrary files on the file system.
Cross-site scripting vulnerability in Build Failure Analyzer Plugin
SECURITY-290 / CVE-2016-49
Red Hat
JDK: insecure deserialization in CORBA, incorrect CVE-2013-5456 fix
vendor_redhat·2016-04-14·CVSS 9.3
CVE-2016-0376 [CRITICAL] JDK: insecure deserialization in CORBA, incorrect CVE-2013-5456 fix
JDK: insecure deserialization in CORBA, incorrect CVE-2013-5456 fix
The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code as demonstrated by the readValue method of the com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which implements the javax.rmi.CORBA.ValueHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-5456.
No detection rules found.
Exploit-DB
Microsoft Word 2013/2016 - sprmSdyaTop Denial of Service (MS16-099)
exploitdb·2016-08-16·CVSS 7.8
CVE-2016-3316 [HIGH] Microsoft Word 2013/2016 - sprmSdyaTop Denial of Service (MS16-099)
Microsoft Word 2013/2016 - sprmSdyaTop Denial of Service (MS16-099)
---
#####################################################################################
# Application: Microsoft Office Word
# Platforms: Windows, OSX
# Versions: Microsoft Office Word 2013,2016
# Author: Francis Provencher of COSIG
# Website: https://cosig.gouv.qc.ca/en/advisory/
# Twitter: @COSIG_
# Date: August 09, 2016
# CVE: CVE-2016-3316
# COSIG-2016-32
#####################################################################################
1) Introduction
2) Report Timeline
3) Technical details
4) POC
#######################################################################################
1) Introduction
Microsoft Word is a word processor developed by Microsoft. It was first released on October 25, 1983[3]
und
Metasploit
Microsoft Exchange ProxyLogon Collector
metasploit·CVSS 9.8
CVE-2021-26855 [CRITICAL] Microsoft Exchange ProxyLogon Collector
Microsoft Exchange ProxyLogon Collector
This module exploit a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin (CVE-2021-26855). By taking advantage of this vulnerability, it is possible to dump all mailboxes (emails, attachments, contacts, ...). This vulnerability affects (Exchange 2013 Versions < 15.00.1497.012, Exchange 2016 CU18 < 15.01.2106.013, Exchange 2016 CU19 < 15.01.2176.009, Exchange 2019 CU7 < 15.02.0721.013, Exchange 2019 CU8 < 15.02.0792.010). All components are vulnerable by default.
Bugzilla
CVE-2013-5653 ghostscript: getenv and filenameforall ignore -dSAFER
bugzilla·2016-09-29·CVSS 5.5
CVE-2013-5653 [MEDIUM] CVE-2013-5653 ghostscript: getenv and filenameforall ignore -dSAFER
CVE-2013-5653 ghostscript: getenv and filenameforall ignore -dSAFER
It was found that getenv and filenameforall ignore -dSAFER possibly allowing filesystem enumeration.
Upstream bug:
http://bugs.ghostscript.com/show_bug.cgi?id=694724
Upstream patch:
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=ab109aaeb3ddba59518b036fb288402a65cf7ce8
Reference:
http://seclists.org/oss-sec/2016/q3/651
Reproducer:
%!PS
(HOME) getenv { print (\n) print } { (variable not found\n) print } ifelse
Discussion:
Created ghostscript tracking bugs for this issue:
Affects: fedora-all [bug 1390486]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2017:0014 https://rhn.redhat.com/errata/RHSA-2017-0014.html
---
This issue has been addressed in the
Bugzilla
CVE-2013-7458 redis: world-readable ~/.rediscli_history
bugzilla·2016-08-03·CVSS 3.3
CVE-2013-7458 [LOW] CVE-2013-7458 redis: world-readable ~/.rediscli_history
CVE-2013-7458 redis: world-readable ~/.rediscli_history
redis-cli stores its history in ~/.rediscli_history, this file is created with permissions 0644, which could lead to exposure of sensitive data if for users with world readable home directories.
CVE request:
http://seclists.org/oss-sec/2016/q3/180
Upstream issue:
https://github.com/antirez/redis/issues/3284
Discussion:
Created redis tracking bugs for this issue:
Affects: fedora-all [bug 1363671]
Affects: epel-all [bug 1363672]
---
Fixed upstream in Redis 3.2.3 Released Tue Aug 02 10:55:24 CEST 2016
http://download.redis.io/redis-stable/00-RELEASENOTES
Redis-cli created the history file with insecure permissions, allowing reading from the file. This was actually a bug in linenoise which is now fixed. The applied fix is from
Bugzilla
CVE-2016-6213 kernel: Overflowing kernel mount table using shared bind mount
bugzilla·2016-07-14·CVSS 4.7
CVE-2016-6213 [MEDIUM] CVE-2016-6213 kernel: Overflowing kernel mount table using shared bind mount
CVE-2016-6213 kernel: Overflowing kernel mount table using shared bind mount
It was found that in Linux kernel the mount table expands by a power-of-two with each bind mount command. If a system is configured to allow non-privileged user to do bind mounts, or allows to do so in a container or unprivileged mount namespace, then non-privileged user is able to cause a local DoS by overflowing the mount table, which causes a deadlock for the whole system.
CVE request:
http://seclists.org/oss-sec/2016/q3/56
Proofs:
http://seclists.org/oss-sec/2016/q3/65
http://seclists.org/oss-sec/2016/q3/75
Discussions:
https://lkml.org/lkml/2013/6/17/143
Discussion:
Acknowledgments:
Name: Qian Cai (Red Hat)
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1356472]
---
Bugzilla
CVE-2016-3706 glibc: stack (frame) overflow in getaddrinfo() when called with AF_INET, AF_INET6 (incomplete fix for CVE-2013-4458)
bugzilla·2016-04-27·CVSS 5.0
CVE-2016-3706 [MEDIUM] CVE-2016-3706 glibc: stack (frame) overflow in getaddrinfo() when called with AF_INET, AF_INET6 (incomplete fix for CVE-2013-4458)
CVE-2016-3706 glibc: stack (frame) overflow in getaddrinfo() when called with AF_INET, AF_INET6 (incomplete fix for CVE-2013-4458)
It was found that the fix for CVE-2013-4458 is incomplete.
A stack (frame) overflow flaw, which could led to a denial of service (application crash), was found in the way glibc's getaddrinfo() function processed certain requests when called with AF_INET or AF_INET6.
This is less substantial than the CVE-2013-4458 issue because there is an other, unfixed bug in nss_files which causes it to use gigabytes of stack space with "multi on" (our default) in /etc/host.conf. Only about 4096 addresses fit into a DNS reply, so this is not really exploitable via nss_dns (only in fringe cases with extremely small stacks, as sometimes seen with Java VMs).
Discussion:
Ack
Bugzilla
CVE-2016-0636 OpenJDK: missing type safety checks for MethodHandle calls across class loaders, incorrect CVE-2013-5838 fix (Hotspot, 8151666)
bugzilla·2016-03-23·CVSS 9.3
CVE-2016-0636 [CRITICAL] CVE-2016-0636 OpenJDK: missing type safety checks for MethodHandle calls across class loaders, incorrect CVE-2013-5838 fix (Hotspot, 8151666)
CVE-2016-0636 OpenJDK: missing type safety checks for MethodHandle calls across class loaders, incorrect CVE-2013-5838 fix (Hotspot, 8151666)
It was discovered that the security fix for CVE-2013-5838 was incomplete
and still allowed remote attackers to escape the Java security sandbox
mechanism.
The root problem is that the Reflection API does not properly guarantee
type safety when Method Handle objects were invoked across two different
Class Loader namespaces.
A part of the original patch was to use the "loadersAreRelated()" method
to ensure that the two Class Loaders are related, which is a condition
for correct type safety.
However, this condition could be easily fulfilled by abusing certain
behaviours in the class loading process, which could allow an attacker
to bypass the type s
Bugzilla
CVE-2013-4312 kernel: File descriptors passed over unix sockets are not properly accounted
bugzilla·2016-01-12·CVSS 6.2
CVE-2013-4312 [MEDIUM] CVE-2013-4312 kernel: File descriptors passed over unix sockets are not properly accounted
CVE-2013-4312 kernel: File descriptors passed over unix sockets are not properly accounted
It was found that process could allocate and accumulate far more FDs than the process' limit by sending them over a unix socket then closing them to keep the process' fd count low, which could result into a local DoS against kernel by depleting all available memory.
Upstream patch:
https://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=712f4aad406b
Discussion:
https://lkml.org/lkml/2015/12/28/155
Discussion:
This issue went public via debian security advisory:
https://www.debian.org/security/2016/dsa-3448
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1300216]
---
Statement:
This issue affects the Linux kernel packages as shipped with Red Hat En
2016-05-07
Published