Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2016-02-13 CVE-2016-1526 Information Exposure vulnerability in multiple products
The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.
network
low complexity
debian mozilla sil fedoraproject CWE-200
8.1
2016-02-13 CVE-2016-1525 Path Traversal vulnerability in Netgear Prosafe Network Management Software 300 1.5.0.11
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allows remote authenticated users to read arbitrary files via a ..
network
low complexity
netgear CWE-22
8.6
2016-02-13 CVE-2016-1524 Unspecified vulnerability in Netgear Prosafe Network Management Software 300 1.5.0.11
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUpload.do or (2) lib-1.0/external/flash/fileUpload.do to upload a JSP file, and then accessing it via a direct request for a /null URI.
low complexity
netgear
critical
9.6
2016-02-13 CVE-2016-1523 The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.
network
low complexity
fedoraproject mozilla sil debian
6.5
2016-02-13 CVE-2016-1522 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via a crafted Graphite smart font.
network
low complexity
fedoraproject mozilla debian sil CWE-119
8.8
2016-02-13 CVE-2016-1521 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.
network
low complexity
debian sil mozilla fedoraproject CWE-119
8.8
2016-02-13 CVE-2016-0866 Cross-site Scripting vulnerability in Tollgrade Smartgrid Lighthouse Sensor Management System 4.1.0/5.0
Cross-site scripting (XSS) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
tollgrade CWE-79
6.1
2016-02-13 CVE-2016-0865 Credentials Management vulnerability in Tollgrade Smartgrid Lighthouse Sensor Management System 4.1.0/5.0
Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote authenticated users to change arbitrary passwords via unspecified vectors.
network
low complexity
tollgrade CWE-255
8.8
2016-02-13 CVE-2016-0864 Information Exposure vulnerability in Tollgrade Smartgrid Lighthouse Sensor Management System 4.1.0/5.0
Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to obtain sensitive report and username information via unspecified vectors.
network
low complexity
tollgrade CWE-200
5.3
2016-02-13 CVE-2016-0863 Cross-Site Request Forgery (CSRF) vulnerability in Tollgrade Smartgrid Lighthouse Sensor Management System 4.1.0/5.0
Cross-site request forgery (CSRF) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to hijack the authentication of arbitrary users.
network
low complexity
tollgrade CWE-352
8.8