Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-01-05 CVE-2016-6890 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Matrixssl
Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Subject Alt Name in an X.509 certificate.
network
low complexity
matrixssl CWE-119
critical
9.8
2017-01-05 CVE-2015-3441 Command Injection vulnerability in Genexia Drgos 1.14
The Parental Control panel in Genexis devices with DRGOS before 1.14.1 allows remote authenticated users to execute arbitrary CLI commands via the (1) start_hour, (2) start_minute, (3) end_hour, (4) end_minute, or (5) hostname parameter.
network
low complexity
genexia CWE-77
8.8
2017-01-05 CVE-2016-9754 Integer Overflow or Wraparound vulnerability in Linux Kernel
The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.1 mishandles certain integer calculations, which allows local users to gain privileges by writing to the /sys/kernel/debug/tracing/buffer_size_kb file.
local
low complexity
linux CWE-190
7.8
2017-01-05 CVE-2016-10030 Improper Access Control vulnerability in Schedmd Slurm
The _prolog_error function in slurmd/req.c in Slurm before 15.08.13, 16.x before 16.05.7, and 17.x before 17.02.0-pre4 has a vulnerability in how the slurmd daemon informs users of a Prolog failure on a compute node.
network
high complexity
schedmd CWE-284
8.1
2017-01-05 CVE-2016-7169 Path Traversal vulnerability in Wordpress
Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade package uploader in WordPress before 4.6.1 allows remote authenticated users to access arbitrary files via a crafted urlholder parameter.
network
low complexity
wordpress CWE-22
6.3
2017-01-05 CVE-2016-7168 Cross-site Scripting vulnerability in Wordpress
Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted filename.
network
low complexity
wordpress CWE-79
4.8
2017-01-05 CVE-2016-10012 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Openbsd Openssh
The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bounds check is enforced by all compilers, which might allows local users to gain privileges by leveraging access to a sandboxed privilege-separation process, related to the m_zback and m_zlib data structures.
local
low complexity
openbsd CWE-119
7.8
2017-01-05 CVE-2016-10011 Key Management Errors vulnerability in Openbsd Openssh
authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging access to a privilege-separated child process.
local
low complexity
openbsd CWE-320
5.5
2017-01-05 CVE-2016-10010 Permissions, Privileges, and Access Controls vulnerability in Openbsd Openssh
sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to serverloop.c.
local
high complexity
openbsd CWE-264
7.0
2017-01-05 CVE-2016-10009 Untrusted Search Path vulnerability in Openbsd Openssh
Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket.
network
low complexity
openbsd CWE-426
7.3