Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-02-22 CVE-2016-9384 Information Exposure vulnerability in XEN 4.7.0/4.7.1
Xen 4.7 allows local guest OS users to obtain sensitive host information by loading a 32-bit ELF symbol table.
local
low complexity
xen CWE-200
6.5
2017-02-22 CVE-2016-9378 Improper Access Control vulnerability in XEN
Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging an incorrect choice for software interrupt delivery.
local
low complexity
xen CWE-284
5.5
2017-02-22 CVE-2016-9377 Incorrect Calculation vulnerability in XEN
Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation.
local
low complexity
xen CWE-682
5.5
2017-02-22 CVE-2016-8636 Integer Overflow or Wraparound vulnerability in Linux Kernel
Integer overflow in the mem_check_range function in drivers/infiniband/sw/rxe/rxe_mr.c in the Linux kernel before 4.9.10 allows local users to cause a denial of service (memory corruption), obtain sensitive information from kernel memory, or possibly have unspecified other impact via a write or read request involving the "RDMA protocol over infiniband" (aka Soft RoCE) technology.
local
low complexity
linux CWE-190
7.8
2017-02-22 CVE-2014-4677 Command Injection vulnerability in Gpgtools Libmacgpg 0.6
The installPackage function in the installerHelper subcomponent in Libmacgpg in GPG Suite before 2015.06 allows local users to execute arbitrary commands with root privileges via shell metacharacters in the xmlPath argument.
local
low complexity
gpgtools CWE-77
7.8
2017-02-22 CVE-2016-9684 Command Injection vulnerability in Dell Sonicwall Secure Remote Access Server 8.1.0.214Sv
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface.
network
low complexity
dell CWE-77
critical
9.8
2017-02-22 CVE-2016-9683 Command Injection vulnerability in Dell Sonicwall Secure Remote Access Server 8.1.0.214Sv
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface.
network
low complexity
dell CWE-77
critical
9.8
2017-02-22 CVE-2016-9682 Command Injection vulnerability in Dell Sonicwall Secure Remote Access Server 8.1.0.214Sv
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface.
network
low complexity
dell CWE-77
critical
9.8
2017-02-22 CVE-2017-3847 Cross-site Scripting vulnerability in Cisco Secure Firewall Management Center 6.2.1
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface.
network
low complexity
cisco CWE-79
5.4
2017-02-22 CVE-2017-3845 Cross-site Scripting vulnerability in Cisco Prime Collaboration Assurance 11.0.0/11.1.0/11.5.0
A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
network
low complexity
cisco CWE-79
6.1