CVE-2016-8947
published 2017-07-12CVE-2016-8947: IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to…
PriorityP423medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
0.99%
58.6th percentile
IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 118834
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| harfbuzz_project | harfbuzz | >= 0 < 0.9.27-1ubuntu1.1 | 0.9.27-1ubuntu1.1 |
| harfbuzz_project | harfbuzz | >= 0 < 1.0.1-1ubuntu0.1 | 1.0.1-1ubuntu0.1 |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
| ibm | emptoris_sourcing | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv7.6HIGH
vendor_redhat7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jg7j-vxg4-4j74: IBM Emptoris Sourcing 9
ghsa_unreviewed·2022-05-17
CVE-2016-8947 [MEDIUM] CWE-601 GHSA-jg7j-vxg4-4j74: IBM Emptoris Sourcing 9
IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 118834
OSV
harfbuzz vulnerabilities
osv·2016-08-24·CVSS 7.6
CVE-2015-8947 harfbuzz vulnerabilities
harfbuzz vulnerabilities
Kostya Serebryany discovered that HarfBuzz incorrectly handled memory. A
remote attacker could use this issue to cause HarfBuzz to crash, resulting
in a denial of service, or possibly execute arbitrary code. (CVE-2015-8947)
It was discovered that HarfBuzz incorrectly handled certain length checks.
A remote attacker could use this issue to cause HarfBuzz to crash,
resulting in a denial of service, or possibly execute arbitrary code.
This issue only applied to Ubuntu 16.04 LTS. (CVE-2016-2052)
Red Hat
chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
vendor_redhat·2016-01-24·CVSS 7.6
CVE-2016-2052 [HIGH] chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.
Package: harfbuzz (Red Hat Enterprise Linux 7) - Will not fix
Red Hat
chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
vendor_redhat·2016-01-24·CVSS 7.6
CVE-2015-8947 [HIGH] chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
chromium-browser: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6
hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data, a different vulnerability than CVE-2016-2052.
Package: harfbuzz (Red Hat Enterprise Linux 7) - Will not fix
No detection rules found.
No public exploits indexed.
http://www.ibm.com/support/docview.wss?uid=swg22005549http://www.securityfocus.com/bid/99545https://exchange.xforce.ibmcloud.com/vulnerabilities/118834http://www.ibm.com/support/docview.wss?uid=swg22005549http://www.securityfocus.com/bid/99545https://exchange.xforce.ibmcloud.com/vulnerabilities/118834
2017-07-12
Published