Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-02-07 CVE-2016-7400 SQL Injection vulnerability in Exponentcms Exponent CMS
Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an activate_address address controller action, (2) title parameter in a show blog controller action, or (3) content_id parameter in a showComments expComment controller action.
network
low complexity
exponentcms CWE-89
critical
9.8
2017-02-07 CVE-2016-7164 Improper Input Validation vulnerability in Libtorrent 1.1
The construct function in puff.cpp in Libtorrent 1.1.0 allows remote torrent trackers to cause a denial of service (segmentation fault and crash) via a crafted GZIP response.
network
low complexity
libtorrent CWE-20
7.5
2017-02-07 CVE-2016-6199 Deserialization of Untrusted Data vulnerability in Gradle 2.12
ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.
network
low complexity
gradle CWE-502
critical
9.8
2017-02-07 CVE-2016-6175 Code Injection vulnerability in PHP-Gettext Project PHP-Gettext
Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header.
network
low complexity
php-gettext-project CWE-94
critical
9.8
2017-02-07 CVE-2016-6131 Improper Input Validation vulnerability in GNU Libiberty
The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.
network
low complexity
gnu CWE-20
7.5
2017-02-07 CVE-2016-2781 Improper Input Validation vulnerability in GNU Coreutils
chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
local
low complexity
gnu CWE-20
6.5
2017-02-07 CVE-2016-2779 Permissions, Privileges, and Access Controls vulnerability in Kernel Util-Linux 2.24.21
runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
local
low complexity
kernel CWE-264
7.8
2017-02-07 CVE-2016-2539 Cross-Site Request Forgery (CSRF) vulnerability in Atutor
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of users for requests that upload arbitrary files and execute arbitrary PHP code via vectors involving a crafted zip file.
network
low complexity
atutor CWE-352
8.8
2017-02-07 CVE-2016-1504 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dhcpcd Project Dhcpcd
dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to the option length.
network
low complexity
dhcpcd-project CWE-119
7.5
2017-02-07 CVE-2015-8608 Out-of-bounds Read vulnerability in Perl 5.22
The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly execute arbitrary code via a crafted (1) drive letter or (2) pInName argument.
network
low complexity
perl CWE-125
critical
9.8