Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-03-06 CVE-2017-5197 Cross-site Scripting vulnerability in Silverstripe
There is XSS in SilverStripe CMS before 3.4.4 and 3.5.x before 3.5.2.
network
low complexity
silverstripe CWE-79
6.1
2017-03-06 CVE-2016-10244 Out-of-bounds Read vulnerability in multiple products
The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.
local
low complexity
freetype debian CWE-125
7.8
2017-03-06 CVE-2017-6504 Improper Input Validation vulnerability in Qbittorrent
WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking.
network
low complexity
qbittorrent CWE-20
6.1
2017-03-06 CVE-2017-6503 Cross-site Scripting vulnerability in Qbittorrent
WebUI in qBittorrent before 3.3.11 did not escape many values, which could potentially lead to XSS.
network
low complexity
qbittorrent CWE-79
6.1
2017-03-06 CVE-2017-6502 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Imagemagick 6.9.7
An issue was discovered in ImageMagick 6.9.7.
local
low complexity
imagemagick CWE-119
5.5
2017-03-06 CVE-2017-6501 NULL Pointer Dereference vulnerability in Imagemagick 6.9.7
An issue was discovered in ImageMagick 6.9.7.
local
low complexity
imagemagick CWE-476
5.5
2017-03-06 CVE-2017-6500 Out-of-bounds Read vulnerability in multiple products
An issue was discovered in ImageMagick 6.9.7.
local
low complexity
imagemagick debian CWE-125
5.5
2017-03-06 CVE-2017-6499 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
An issue was discovered in Magick++ in ImageMagick 6.9.7.
local
low complexity
imagemagick debian CWE-772
5.5
2017-03-06 CVE-2017-6498 Improper Input Validation vulnerability in multiple products
An issue was discovered in ImageMagick 6.9.7.
local
low complexity
imagemagick debian CWE-20
5.5
2017-03-06 CVE-2017-6497 NULL Pointer Dereference vulnerability in Imagemagick 6.9.7
An issue was discovered in ImageMagick 6.9.7.
network
low complexity
imagemagick CWE-476
7.5