Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-03-31 CVE-2016-8032 Improper Access Control vulnerability in Mcafee Anti-Malware Scan Engine
Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local attackers to bypass local security protection via a crafted input file.
local
low complexity
mcafee CWE-284
7.3
2017-03-31 CVE-2017-7374 Use After Free vulnerability in Linux Kernel
Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing cryptographic transform objects to be freed prematurely.
local
low complexity
linux CWE-416
7.8
2017-03-31 CVE-2016-6561 NULL Pointer Dereference vulnerability in Illumos
illumos smbsrv NULL pointer dereference allows system crash.
network
low complexity
illumos CWE-476
7.5
2017-03-31 CVE-2016-6560 Improper Input Validation vulnerability in Illumos
illumos osnet-incorporation bcopy() and bzero() implementations make signed instead of unsigned comparisons allowing a system crash.
network
low complexity
illumos CWE-20
8.6
2017-03-31 CVE-2017-2775 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in NI Labview 16.0.0.49152
An exploitable memory corruption vulnerability exists in the LvVariantUnflatten functionality in 64-bit versions of LabVIEW before 2015 SP1 f7 Patch and 2016 before f2 Patch.
local
low complexity
ni CWE-119
7.8
2017-03-31 CVE-2017-1171 Unspecified vulnerability in IBM Tririga Application Platform
The IBM TRIRIGA Application Platform 3.3, 3,4, and 3,5 contain a vulnerability that could allow an authenticated user to execute Application actions they do not have access to.
network
low complexity
ibm
4.3
2017-03-31 CVE-2017-1154 Information Exposure vulnerability in IBM Algo ONE 4.9.1/5.0.0/5.1.0
IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to files in the local environment which should not be viewed by application users.
network
low complexity
ibm CWE-200
6.5
2017-03-31 CVE-2016-9990 Cross-site Scripting vulnerability in IBM Inotes
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2017-03-31 CVE-2016-9707 XXE vulnerability in IBM products
IBM Jazz Foundation is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data.
network
low complexity
ibm CWE-611
8.1
2017-03-31 CVE-2016-8935 Cross-site Scripting vulnerability in IBM Kenexa LMS
IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4