Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2016-04-26 CVE-2016-1601 Credentials Management vulnerability in Suse Yast2
yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty password fields in /etc/shadow during an AutoYaST installation when the profile does not contain inst-sys users, which might allow attackers to have unspecified impact via unknown vectors.
network
low complexity
suse CWE-255
critical
9.8
2016-04-25 CVE-2016-2346 Insufficient Verification of Data Authenticity vulnerability in Allroundautomations Pl/Sql Developer
Allround Automations PL/SQL Developer 11 before 11.0.6 relies on unverified HTTP data for updates, which allows man-in-the-middle attackers to execute arbitrary code by modifying fields in the client-server data stream.
network
high complexity
allroundautomations CWE-345
8.1
2016-04-25 CVE-2016-2333 Cryptographic Issues vulnerability in Systech Syslink Sl-1000 Modular Gateway Firmware
SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 use the same hardcoded encryption key across different customers' installations, which allows attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
network
low complexity
systech CWE-310
7.5
2016-04-25 CVE-2016-2332 Command Injection vulnerability in Systech Syslink Sl-1000 Modular Gateway Firmware
flu.cgi in the web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 allows remote authenticated users to execute arbitrary commands via the 5066 (aka dnsmasq) parameter.
network
low complexity
systech CWE-77
8.8
2016-04-25 CVE-2016-2331 Credentials Management vulnerability in Systech Syslink Sl-1000 Modular Gateway Firmware
The web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 has a default password, which makes it easier for remote attackers to obtain access via unspecified vectors.
network
low complexity
systech CWE-255
critical
9.8
2016-04-25 CVE-2016-1202 Unspecified vulnerability in Atom Electron 0.33.4
Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan horse Node.js module in a parent directory of a directory named on a require line.
local
low complexity
atom
7.8
2016-04-25 CVE-2016-1185 Information Exposure vulnerability in Cybozu Kintone
The Cybozu kintone mobile application 1.x before 1.0.6 for Android allows attackers to discover an authentication token via a crafted application.
local
high complexity
cybozu CWE-200
2.5
2016-04-25 CVE-2016-4054 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.
network
high complexity
canonical squid-cache oracle CWE-119
8.1
2016-04-25 CVE-2016-4053 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization.
network
high complexity
squid-cache oracle canonical CWE-119
3.7
2016-04-25 CVE-2016-4052 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses.
network
high complexity
canonical squid-cache CWE-119
8.1