Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2016-10-28 CVE-2016-4395 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HP System Management Homepage
HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" issue.
network
low complexity
hp CWE-119
7.5
2016-10-28 CVE-2016-4394 7PK - Security Features vulnerability in HP System Management Homepage
HPE System Management Homepage before v7.6 allows remote attackers to obtain sensitive information via unspecified vectors, related to an "HSTS" issue.
network
low complexity
hp CWE-254
6.5
2016-10-28 CVE-2016-4393 Cross-site Scripting vulnerability in HP System Management Homepage
HPE System Management Homepage before v7.6 allows "remote authenticated" attackers to obtain sensitive information via unspecified vectors, related to an "XSS" issue.
network
low complexity
hp CWE-79
5.4
2016-10-28 CVE-2016-8335 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Iceni Argus 6.6.04
An exploitable stack based buffer overflow vulnerability exists in the ipNameAdd functionality of Iceni Argus Version 6.6.04 (Sep 7 2012) NK - Linux x64 and Version 6.6.04 (Nov 14 2014) NK - Windows x64.
local
low complexity
iceni CWE-119
7.8
2016-10-28 CVE-2016-8333 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Iceni Argus 6.6.04
An exploitable stack-based buffer overflow vulnerability exists in the ipfSetColourStroke functionality of Iceni Argus version 6.6.04 A specially crafted pdf file can cause a buffer overflow resulting in arbitrary code execution.
local
low complexity
iceni CWE-119
7.8
2016-10-28 CVE-2016-8331 Unspecified vulnerability in Libtiff 4.0.6
An exploitable remote code execution vulnerability exists in the handling of TIFF images in LibTIFF version 4.0.6.
network
high complexity
libtiff
8.1
2016-10-28 CVE-2016-9028 7PK - Security Features vulnerability in Citrix Netscaler Application Delivery Controller Firmware
Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header.
network
low complexity
citrix CWE-254
8.8
2016-10-28 CVE-2016-9018 NULL Pointer Dereference vulnerability in Realnetworks Realplayer 18.1.5.705
Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlayer 18.1.5.705 through a crafted .QCP media file.
local
low complexity
realnetworks CWE-476
5.5
2016-10-28 CVE-2016-9017 Out-of-bounds Read vulnerability in Artifex Mujs
Artifex Software, Inc.
network
low complexity
artifex CWE-125
7.5
2016-10-28 CVE-2016-8889 Information Exposure vulnerability in Bitcoin Knots Project Bitcoin Knots
In Bitcoin Knots v0.11.0.ljr20150711 through v0.13.0.knots20160814 (fixed in v0.13.1.knots20161027), the debug console stores sensitive information including private keys and the wallet passphrase in its persistent command history.
local
low complexity
bitcoin-knots-project CWE-200
6.2