Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-03-17 CVE-2017-6965 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Binutils 2.28
readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-difference relocations, leading to a heap-based buffer overflow.
local
low complexity
gnu CWE-119
5.5
2017-03-17 CVE-2017-6962 Integer Overflow or Wraparound vulnerability in Apng2Gif Project Apng2Gif 1.7
An issue was discovered in apng2gif 1.7.
network
low complexity
apng2gif-project CWE-190
7.5
2017-03-17 CVE-2017-6961 Improper Input Validation vulnerability in Apng2Gif Project Apng2Gif 1.7
An issue was discovered in apng2gif 1.7.
local
low complexity
apng2gif-project CWE-20
5.5
2017-03-17 CVE-2017-6960 Integer Overflow or Wraparound vulnerability in multiple products
An issue was discovered in apng2gif 1.7.
network
low complexity
apng2gif-project debian canonical CWE-190
7.5
2017-03-17 CVE-2017-6958 Cross-site Scripting vulnerability in Mantisbt Source Integration
An XSS vulnerability in the MantisBT Source Integration Plugin (before 2.0.2) search result page allows an attacker to inject arbitrary HTML or JavaScript (if MantisBT's CSP settings permit it) by crafting any valid parameter.
network
low complexity
mantisbt CWE-79
6.1
2017-03-17 CVE-2017-6955 Improper Input Validation vulnerability in Teleogistic Invite Anyone
An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress.
network
low complexity
teleogistic CWE-20
5.3
2017-03-17 CVE-2017-6954 Improper Privilege Management vulnerability in Buddypress
An issue was discovered in includes/component.php in the BuddyPress Docs plugin before 1.9.3 for WordPress.
network
low complexity
buddypress CWE-269
4.3
2017-03-17 CVE-2017-0154 Injection vulnerability in Microsoft Internet Explorer 11
Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application, aka, "Internet Explorer Elevation of Privilege Vulnerability."
local
low complexity
microsoft CWE-74
4.4
2017-03-17 CVE-2017-0151 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Edge
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers.
network
high complexity
microsoft CWE-119
7.5
2017-03-17 CVE-2017-0150 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft Edge
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers.
network
high complexity
microsoft CWE-119
7.5