Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-04-13 CVE-2016-10117 Permissions, Privileges, and Access Controls vulnerability in Firejail Project Firejail
Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc.
local
low complexity
firejail-project CWE-264
7.8
2017-04-13 CVE-2015-8864 Cross-site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.
network
low complexity
opensuse roundcube CWE-79
6.1
2017-04-13 CVE-2015-8284 Improper Access Control vulnerability in Seawell Networks Spectrum SDC 02.05.00
SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.
network
low complexity
seawell-networks CWE-284
8.8
2017-04-13 CVE-2015-8283 Path Traversal vulnerability in Seawell Networks Spectrum SDC 02.05.00
Directory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00.
network
low complexity
seawell-networks CWE-22
6.5
2017-04-13 CVE-2015-8282 Credentials Management vulnerability in Seawell Networks Spectrum SDC 02.05.00
SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account.
network
low complexity
seawell-networks CWE-255
critical
9.8
2017-04-13 CVE-2015-8272 NULL Pointer Dereference vulnerability in Rtmpdump Project Rtmpdump 2.4
RTMPDump 2.4 allows remote attackers to trigger a denial of service (NULL pointer dereference and process crash).
network
low complexity
rtmpdump-project CWE-476
6.5
2017-04-13 CVE-2015-8271 Write-what-where Condition vulnerability in Rtmpdump Project Rtmpdump 2.4
The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code.
network
low complexity
rtmpdump-project CWE-123
critical
9.8
2017-04-13 CVE-2015-8270 NULL Pointer Dereference vulnerability in Rtmpdump Project Rtmpdump 2.4
The AMF3ReadString function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to cause a denial of service (invalid pointer dereference and process crash).
network
low complexity
rtmpdump-project CWE-476
7.5
2017-04-13 CVE-2015-8223 Permission Issues vulnerability in Huawei P7 Firmware and P8 Ale-Ul00 Firmware
Huawei P7 before P7-L00C17B851, P7-L05C00B851, and P7-L09C92B85, and P8 ALE-UL00 before ALE-UL00B211 allows local users to cause a denial of service (OS crash) by leveraging camera permissions and via crafted input to the camera driver.
local
low complexity
huawei CWE-275
5.5
2017-04-13 CVE-2015-8107 Use of Externally-Controlled Format String vulnerability in GNU A2Ps 4.14
Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code.
local
low complexity
gnu CWE-134
7.8