CVE-2016-2978
published 2017-08-29CVE-2016-2978: IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache locally that could be available to a local user. IBM X-Force…
PriorityP49low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.32%
24.0th percentile
IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache locally that could be available to a local user. IBM X-Force ID: 113938.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
| ibm | sametime | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q6c4-9r7h-7482: IBM Sametime 8
ghsa_unreviewed·2022-05-17
CVE-2016-2978 [LOW] CWE-200 GHSA-q6c4-9r7h-7482: IBM Sametime 8
IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache locally that could be available to a local user. IBM X-Force ID: 113938.
OSV
linux-lts-wily vulnerabilities
osv·2016-05-16·CVSS 7.8
linux-lts-wily vulnerabilities
linux-lts-wily vulnerabilities
USN-2978-1 fixed vulnerabilities in the Linux kernel for Ubuntu 15.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 15.10 for Ubuntu 14.04 LTS.
David Matlack discovered that the Kernel-based Virtual Machine (KVM)
implementation in the Linux kernel did not properly restrict variable
Memory Type Range Registers (MTRR) in KVM guests. A privileged user in a
guest VM could use this to cause a denial of service (system crash) in the
host, expose sensitive information from the host, or possibly gain
administrative privileges in the host. (CVE-2016-3713)
Philip Pettersson discovered that the Linux kernel's ASN.1 DER decoder did
not properly process certificate files with tags of indefinite length. A
loca
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.ibm.com/support/docview.wss?uid=swg22006441http://www.securityfocus.com/bid/100572https://exchange.xforce.ibmcloud.com/vulnerabilities/113938http://www.ibm.com/support/docview.wss?uid=swg22006441http://www.securityfocus.com/bid/100572https://exchange.xforce.ibmcloud.com/vulnerabilities/113938
2017-08-29
Published