Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-03-30 CVE-2017-6184 Command Injection vulnerability in Sophos web Appliance
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token parameter, aka NSWA-1303.
network
low complexity
sophos CWE-77
4.7
2017-03-30 CVE-2017-6183 Command Injection vulnerability in Sophos web Appliance
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers was vulnerable to remote command injection, aka NSWA-1314.
network
low complexity
sophos CWE-77
7.2
2017-03-30 CVE-2017-6182 OS Command Injection vulnerability in Sophos web Appliance
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304.
network
low complexity
sophos CWE-78
critical
9.8
2017-03-30 CVE-2017-5185 Improper Input Validation vulnerability in Microfocus Sentinel 8.0/8.0.0.1
A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow remote denial of service.
network
low complexity
microfocus CWE-20
7.5
2017-03-30 CVE-2017-5184 Information Exposure vulnerability in Microfocus Sentinel 8.0/8.0.0.1
A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow leakage of information (account enumeration).
network
low complexity
microfocus CWE-200
5.3
2017-03-30 CVE-2014-9826 7PK - Errors vulnerability in Imagemagick
ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files.
network
low complexity
imagemagick CWE-388
critical
9.8
2017-03-30 CVE-2014-9825 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Imagemagick
Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file, a different vulnerability than CVE-2014-9824.
local
low complexity
imagemagick CWE-119
7.8
2017-03-30 CVE-2014-9824 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Imagemagick
Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file, a different vulnerability than CVE-2014-9825.
local
low complexity
imagemagick CWE-119
7.8
2017-03-30 CVE-2014-9823 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Imagemagick
Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted palm file, a different vulnerability than CVE-2014-9819.
local
low complexity
imagemagick CWE-119
7.8
2017-03-30 CVE-2014-9822 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Imagemagick
Heap-based buffer overflow in ImageMagick allows remote attackers to have unspecified impact via a crafted quantum file.
local
low complexity
imagemagick CWE-119
7.8