Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-01-11 CVE-2016-9015 Improper Certificate Validation vulnerability in Python Urllib3 1.17/1.18
Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates.
network
high complexity
python CWE-295
3.7
2017-01-11 CVE-2016-6820 Information Exposure vulnerability in Netapp Metrocluster Tiebreaker 1.1
MetroCluster Tiebreaker for clustered Data ONTAP in versions before 1.2 discloses sensitive information in cleartext which may be viewed by an unauthenticated user.
network
low complexity
netapp CWE-200
7.5
2017-01-11 CVE-2016-4808 Cross-Site Request Forgery (CSRF) vulnerability in Web2Py
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged in user to perform some unwanted actions i.e An attacker can trick an victim to disable the installed application just by sending a URL to victim.
network
low complexity
web2py CWE-352
8.8
2017-01-11 CVE-2016-4807 Cross-site Scripting vulnerability in Web2Py
Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (admin).
network
low complexity
web2py CWE-79
4.8
2017-01-11 CVE-2016-4806 Information Exposure vulnerability in Web2Py
Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server sensitive files.
network
low complexity
web2py CWE-200
7.5
2017-01-11 CVE-2015-8020 Information Exposure vulnerability in Netapp Clustered Data Ontap 8.0/8.3.1/8.3.2
Clustered Data ONTAP versions 8.0, 8.3.1, and 8.3.2 contain a default privileged account which under certain conditions can be used for unauthorized information disclosure.
network
high complexity
netapp CWE-200
3.7
2017-01-11 CVE-2016-7480 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data.
network
low complexity
php netapp CWE-119
critical
9.8
2017-01-11 CVE-2017-5340 Integer Overflow or Wraparound vulnerability in multiple products
Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory access, and use of arbitrary destructor function pointers) via crafted serialized data.
network
low complexity
php netapp CWE-190
critical
9.8
2017-01-11 CVE-2016-7478 Unspecified vulnerability in PHP
Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (infinite loop) via a crafted Exception object in serialized data, a related issue to CVE-2015-8876.
network
low complexity
php
7.5
2017-01-11 CVE-2017-2967 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe products
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the XFA engine related to a form's structure and organization.
local
low complexity
adobe CWE-119
7.8