Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-02-17 CVE-2016-9773 Out-of-bounds Read vulnerability in Imagemagick 7.0.38
Heap-based buffer overflow in the IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.
local
low complexity
imagemagick CWE-125
5.5
2017-02-17 CVE-2016-9637 Permissions, Privileges, and Access Controls vulnerability in Citrix Xenserver
The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access.
local
high complexity
citrix CWE-264
7.5
2017-02-17 CVE-2016-9139 Cross-site Scripting vulnerability in Otrs
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.3.x before 3.3.16, 4.0.x before 4.0.19, and 5.0.x before 5.0.14 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment.
network
low complexity
otrs CWE-79
6.1
2017-02-17 CVE-2016-8652 Improper Input Validation vulnerability in Dovecot
The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setting a username.
network
high complexity
dovecot CWE-20
5.9
2017-02-17 CVE-2016-6233 SQL Injection vulnerability in multiple products
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pattern [\w]* in a regular expression.
network
low complexity
fedoraproject zend CWE-89
critical
9.8
2017-02-17 CVE-2016-5417 Resource Management Errors vulnerability in GNU Glibc
Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows remote attackers to cause a denial of service (memory consumption) by leveraging partial initialization of internal resolver data structures.
network
low complexity
gnu CWE-399
7.5
2017-02-17 CVE-2016-4861 SQL Injection vulnerability in multiple products
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.
network
low complexity
fedoraproject zend CWE-89
critical
9.8
2017-02-17 CVE-2016-4327 Cross-site Scripting vulnerability in Wso2 Enablement Server for Java 6.6200908271616
Cross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server for Java/6.6 build SSJ-6.6-20090827-1616 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
network
low complexity
wso2 CWE-79
6.1
2017-02-17 CVE-2016-4316 Cross-site Scripting vulnerability in Wso2 Carbon 4.4.5
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) setName parameter to identity-mgt/challenges-mgt.jsp; the (2) webappType or (3) httpPort parameter to webapp-list/webapp_info.jsp; the (4) dsName or (5) description parameter to ndatasource/newdatasource.jsp; the (6) phase parameter to viewflows/handlers.jsp; or the (7) url parameter to ndatasource/validateconnection-ajaxprocessor.jsp.
network
low complexity
wso2 CWE-79
6.1
2017-02-17 CVE-2016-4315 Cross-Site Request Forgery (CSRF) vulnerability in Wso2 Carbon 4.4.5
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.
network
low complexity
wso2 CWE-352
5.7