Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-02-09 CVE-2016-6173 Resource Management Errors vulnerability in Nlnetlabs NSD
NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.
network
low complexity
nlnetlabs CWE-399
7.5
2017-02-09 CVE-2016-6171 Resource Exhaustion vulnerability in Knot-Dns Knot DNS 2.1.1/2.2.0/2.2.1
Knot DNS before 2.3.0 allows remote DNS servers to cause a denial of service (memory exhaustion and slave server crash) via a large zone transfer for (1) DDNS, (2) AXFR, or (3) IXFR.
network
low complexity
knot-dns CWE-400
8.6
2017-02-09 CVE-2016-5727 Code Injection vulnerability in Simplemachines Simple Machines Forum 2.1
LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via vectors related to variables derived from user input in a foreach loop.
network
low complexity
simplemachines CWE-94
8.8
2017-02-09 CVE-2016-5726 Code Injection vulnerability in Simplemachines Simple Machines Forum 2.1
Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter.
network
low complexity
simplemachines CWE-94
critical
9.8
2017-02-09 CVE-2016-4988 Cross-site Scripting vulnerability in Jenkins Build Failure Analyzer
Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
network
low complexity
jenkins CWE-79
6.1
2017-02-09 CVE-2016-4987 Path Traversal vulnerability in Jenkins Image Gallery
Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbitrary directories and read arbitrary files via unspecified form fields.
network
low complexity
jenkins CWE-22
6.5
2017-02-09 CVE-2016-4986 Path Traversal vulnerability in Jenkins TAP
Directory traversal vulnerability in the TAP plugin before 1.25 in Jenkins allows remote attackers to read arbitrary files via an unspecified parameter.
network
low complexity
jenkins CWE-22
7.5
2017-02-09 CVE-2016-3102 7PK - Security Features vulnerability in Jenkins Script Security
The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection mechanism via a plugin that performs (1) direct field access or (2) get/set array operations.
network
low complexity
jenkins CWE-254
7.3
2017-02-09 CVE-2016-3101 Cross-site Scripting vulnerability in Jenkins Extra Columns
Cross-site scripting (XSS) vulnerability in the Extra Columns plugin before 1.17 in Jenkins allows remote attackers to inject arbitrary web script or HTML by leveraging failure to filter tool tips through the configured markup formatter.
network
low complexity
jenkins CWE-79
5.4
2017-02-09 CVE-2016-2148 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
network
low complexity
busybox debian canonical CWE-119
critical
9.8