Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-03-09 CVE-2017-6552 Resource Exhaustion vulnerability in Sagemcom Livebox Firmware 5.15.8.1
Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing table size: it can be filled within minutes.
network
low complexity
sagemcom CWE-400
7.5
2017-03-09 CVE-2017-6549 Improper Authentication vulnerability in Asus Rt-Ac53 Firmware 3.0.0.4.380.6038
Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750 routers with firmware before 3.0.0.4.380.7378; RT-AC68W routers with firmware before 3.0.0.4.380.7266; and RT-N600, RT-N12+ B1, RT-N11P B1, RT-N12VP B1, RT-N12E C1, RT-N300 B1, and RT-N12+ Pro routers with firmware before 3.0.0.4.380.9488; and Asuswrt-Merlin firmware before 380.65_2 allows remote attackers to steal any active admin session by sending cgi_logout and asusrouter-Windows-IFTTT-1.0 in certain HTTP headers.
network
low complexity
asus CWE-287
8.8
2017-03-09 CVE-2017-6548 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Asus Rt-Ac53 Firmware 3.0.0.4.380.6038
Buffer overflows in networkmap on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750 routers with firmware before 3.0.0.4.380.7378; RT-AC68W routers with firmware before 3.0.0.4.380.7266; and RT-N600, RT-N12+ B1, RT-N11P B1, RT-N12VP B1, RT-N12E C1, RT-N300 B1, and RT-N12+ Pro routers with firmware before 3.0.0.4.380.9488; and Asuswrt-Merlin firmware before 380.65_2 allow remote attackers to execute arbitrary code on the router via a long host or port in crafted multicast messages.
network
low complexity
asus CWE-119
critical
9.8
2017-03-09 CVE-2017-6547 Cross-site Scripting vulnerability in Asus Rt-Ac53 Firmware 3.0.0.4.380.6038
Cross-site scripting (XSS) vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750 routers with firmware before 3.0.0.4.380.7378; RT-AC68W routers with firmware before 3.0.0.4.380.7266; and RT-N600, RT-N12+ B1, RT-N11P B1, RT-N12VP B1, RT-N12E C1, RT-N300 B1, and RT-N12+ Pro routers with firmware before 3.0.0.4.380.9488 allows remote attackers to inject arbitrary JavaScript by requesting filenames longer than 50 characters.
network
low complexity
asus CWE-79
6.1
2017-03-08 CVE-2017-6544 Cross-site Scripting vulnerability in Wuhu Project Wuhu 20170308
Gargaj/wuhu through 2017-03-08 is vulnerable to a reflected XSS in wuhu-master/www_admin/users.php (id parameter).
network
low complexity
wuhu-project CWE-79
6.1
2017-03-08 CVE-2017-6543 Unspecified vulnerability in Tenable Nessus
Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system.
local
low complexity
tenable
7.3
2017-03-08 CVE-2017-1150 Improper Privilege Management vulnerability in IBM DB2 10.1/10.5/11.1
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view.
network
high complexity
ibm CWE-269
3.1
2017-03-08 CVE-2016-9985 Information Exposure Through Log Files vulnerability in IBM Cognos Business Intelligence 10.1.1/10.2
IBM Cognos Server 10.1.1 and 10.2 stores highly sensitive information in log files that could be read by a local user.
local
low complexity
ibm CWE-532
5.5
2017-03-08 CVE-2016-9006 Cross-site Scripting vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-03-08 CVE-2016-5933 7PK - Security Features vulnerability in IBM Tivoli Monitoring
IBM Tivoli Monitoring 6.2 and 6.3 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass.
network
low complexity
ibm CWE-254
4.6