Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-03-30 CVE-2016-10305 Use of Hard-coded Credentials vulnerability in Gotrango products
Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default password that was once stored in cleartext within a software update package on a Trango FTP server.
network
low complexity
gotrango CWE-798
critical
9.8
2017-03-29 CVE-2017-7310 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Flexense Diskboss, Disksorter and Syncbreeze
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout before 10.6, and VX Search before 10.6 allows attackers to execute arbitrary code via a crafted XML file containing a long name attribute of a classify element.
local
low complexity
flexense CWE-119
7.8
2017-03-29 CVE-2017-4980 Path Traversal vulnerability in EMC Isilon Onefs
EMC Isilon OneFS is affected by a path traversal vulnerability that may potentially be exploited by attackers to compromise the affected system.
network
low complexity
emc CWE-22
7.5
2017-03-29 CVE-2017-4977 Information Exposure vulnerability in EMC RSA Archer Security Operations Management 1.3.1.51
EMC RSA Archer Security Operations Management with RSA Unified Collector Framework versions prior to 1.3.1.52 contain a sensitive information disclosure vulnerability that could potentially be exploited by malicious users to compromise an affected system.
local
high complexity
emc CWE-200
7.0
2017-03-29 CVE-2017-7308 Incorrect Conversion between Numeric Types vulnerability in Linux Kernel
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain privileges (if the CAP_NET_RAW capability is held), via crafted system calls.
local
low complexity
linux CWE-681
7.8
2017-03-29 CVE-2017-7258 Path Traversal vulnerability in Auromeera Emli 1.0
HTTP Exploit in eMLi Portal in AuroMeera Technometrix Pvt.
network
low complexity
auromeera CWE-22
7.5
2017-03-29 CVE-2017-5226 Improper Input Validation vulnerability in Projectatomic Bubblewrap
When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox.
network
low complexity
projectatomic CWE-20
critical
10.0
2017-03-29 CVE-2016-6349 Information Exposure vulnerability in Projectatomic Oci-Register-Machine
The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by running that command.
local
low complexity
projectatomic CWE-200
3.3
2017-03-29 CVE-2016-4976 Information Exposure vulnerability in Apache Ambari
Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive information via a process listing.
local
low complexity
apache CWE-200
5.5
2017-03-29 CVE-2016-2379 Inadequate Encryption Strength vulnerability in Pidgin Mxit
The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by leveraging knowledge of client registration codes or (2) gain login access by eavesdropping on login messages and re-using the hashed passwords.
low complexity
pidgin CWE-326
8.8