CVE-2016-10825

CVSS v3 Score
8.1
High
CVSS v2 Score
5.5
Medium

Vulnerability Description

cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).

CVSS:8.1(High)

Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an au...

CVSS:8.1(High)

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to execute arbitrary code with kernel privileges.

CVSS:7.8(High)

The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RPM warning and allow i...

CVSS:7.8(High)

An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework component.

CVSS:7.5(High)

IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information due to security misconfigurations.

CVSS:7.5(High)

A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and in...