Vulnerabilities > Microsoft > Windows

DATE CVE VULNERABILITY TITLE RISK
2017-02-15 CVE-2017-0309 Integer Overflow or Wraparound vulnerability in Nvidia GPU Driver
All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where multiple integer overflows may cause improper memory allocation leading to a denial of service or potential escalation of privileges.
local
low complexity
nvidia freebsd linux microsoft oracle CWE-190
7.2
2017-02-15 CVE-2017-0308 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Nvidia GPU Driver
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where untrusted input is used for buffer size calculation leading to denial of service or escalation of privileges.
local
low complexity
nvidia microsoft CWE-119
7.2
2017-02-08 CVE-2016-5918 Information Exposure vulnerability in IBM Tivoli Storage Manager FOR Space Management
IBM Tivoli Storage Manager HSM for Windows displays the encrypted Tivoli Storage Manager password in application trace output if the password access option is prompt and the password is changed.
1.9
2017-02-01 CVE-2016-8977 Information Exposure vulnerability in IBM Bigfix Inventory and License Metric Tool
IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests.
network
low complexity
ibm hp linux microsoft oracle CWE-200
5.0
2017-02-01 CVE-2016-8963 Information Exposure vulnerability in IBM Bigfix Inventory and License Metric Tool
IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.
local
low complexity
ibm hp linux microsoft oracle CWE-200
2.1
2017-02-01 CVE-2016-6110 Credentials Management vulnerability in IBM products
IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local user.
local
low complexity
ibm linux microsoft CWE-255
2.1
2017-02-01 CVE-2016-8967 Credentials Management vulnerability in IBM Bigfix Inventory and License Metric Tool
IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm hp linux microsoft oracle CWE-255
2.1
2017-02-01 CVE-2016-8981 Information Exposure vulnerability in IBM Bigfix Inventory and License Metric Tool
IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm hp linux microsoft oracle CWE-200
2.1
2017-02-01 CVE-2016-8980 XXE vulnerability in IBM Bigfix Inventory and License Metric Tool
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data.
network
low complexity
ibm hp linux microsoft oracle CWE-611
7.5
2017-02-01 CVE-2016-8966 Information Exposure vulnerability in IBM Bigfix Inventory and License Metric Tool
IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
4.3