Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-02-28 CVE-2017-5581 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Tigervnc
Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE message with subrectangle outside framebuffer boundaries.
network
low complexity
tigervnc CWE-119
critical
9.8
2017-02-28 CVE-2016-9558 Integer Overflow or Wraparound vulnerability in Libdwarf Project Libdwarf
(1) libdwarf/dwarf_leb.c and (2) dwarfdump/print_frames.c in libdwarf before 20161124 allow remote attackers to have unspecified impact via a crafted bit pattern in a signed leb number, aka a "negation overflow."
network
low complexity
libdwarf-project CWE-190
critical
9.8
2017-02-28 CVE-2016-9261 Cross-site Scripting vulnerability in Tenable LOG Correlation Engine 4.8.0
Cross-site scripting (XSS) vulnerability in Tenable Log Correlation Engine (aka LCE) before 4.8.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
tenable CWE-79
5.4
2017-02-28 CVE-2016-9259 Cross-site Scripting vulnerability in Tenable Nessus
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
tenable CWE-79
5.4
2017-02-28 CVE-2016-10207 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.
network
low complexity
opensuse tigervnc CWE-119
7.5
2017-02-28 CVE-2016-8715 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Iceni Argus 6.6.05
An exploitable heap corruption vulnerability exists in the loadTrailer functionality of Iceni Argus version 6.6.05.
local
low complexity
iceni CWE-119
7.8
2017-02-28 CVE-2016-8389 Integer Overflow or Wraparound vulnerability in Iceni Argus 6.6.04
An exploitable integer-overflow vulnerability exists within Iceni Argus.
local
low complexity
iceni CWE-190
7.8
2017-02-28 CVE-2016-8388 Out-of-bounds Read vulnerability in Iceni Argus 6.6.04
An exploitable arbitrary heap-overwrite vulnerability exists within Iceni Argus.
local
low complexity
iceni CWE-125
7.8
2017-02-27 CVE-2016-9818 Improper Access Control vulnerability in XEN 4.7.0/4.7.1
Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at HYP.
local
low complexity
xen CWE-284
6.5
2017-02-27 CVE-2016-9817 Improper Access Control vulnerability in XEN 4.7.0/4.7.1
Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving a (1) data or (2) prefetch abort with the ESR_EL2.EA bit set.
local
low complexity
xen CWE-284
6.5