Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-02-27 CVE-2016-8387 Out-of-bounds Write vulnerability in Iceni Argus 6.6.04
An exploitable heap-based buffer overflow exists in Iceni Argus.
local
low complexity
iceni CWE-787
7.8
2017-02-27 CVE-2016-8386 Out-of-bounds Write vulnerability in Iceni Argus 6.6.04
An exploitable heap-based buffer overflow exists in Iceni Argus.
local
low complexity
iceni CWE-787
7.8
2017-02-27 CVE-2016-8385 Out-of-bounds Write vulnerability in Iceni Argus 6.6.04
An exploitable uninitialized variable vulnerability which leads to a stack-based buffer overflow exists in Iceni Argus.
local
low complexity
iceni CWE-787
7.8
2017-02-27 CVE-2016-8105 Unspecified vulnerability in Intel X710 Series Driver and Xl710 Series Driver
Drivers for the Intel Ethernet Controller X710 and Intel Ethernet Controller XL710 families before version 22.0 are vulnerable to a denial of service in certain layer 2 network configurations.
low complexity
intel
6.5
2017-02-27 CVE-2017-2683 Cross-site Scripting vulnerability in Siemens Ruggedcom Network Management Software 2.0.2
A non-privileged user of the Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could perform a persistent Cross-Site Scripting (XSS) attack, potentially resulting in obtaining administrative permissions.
network
low complexity
siemens CWE-79
8.2
2017-02-27 CVE-2017-2682 Cross-Site Request Forgery (CSRF) vulnerability in Siemens Ruggedcom Network Management Software 2.0.2
The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery (CSRF) attack, potentially allowing an attacker to execute administrative operations, provided the targeted user has an active session and is induced to trigger a malicious request.
network
low complexity
siemens CWE-352
8.8
2017-02-27 CVE-2017-6350 Integer Overflow or Wraparound vulnerability in VIM
An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
network
low complexity
vim CWE-190
critical
9.8
2017-02-27 CVE-2017-6349 Integer Overflow or Wraparound vulnerability in VIM
An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
network
low complexity
vim CWE-190
critical
9.8
2017-02-27 CVE-2017-6344 XXE vulnerability in Grails PDF Plugin 0.6
XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read arbitrary files via a crafted XML document.
local
low complexity
grails CWE-611
5.9
2017-02-27 CVE-2017-6343 Improper Authentication vulnerability in Dahuasecurity Camera Firmware, NVR Firmware and Smartpss Firmware
The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 allows remote attackers to obtain login access by leveraging knowledge of the MD5 Admin Hash without knowledge of the corresponding password, a different vulnerability than CVE-2013-6117.
network
high complexity
dahuasecurity CWE-287
8.1