Vulnerabilities > Microsoft > Windows > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-02-01 CVE-2016-8977 Information Exposure vulnerability in IBM Bigfix Inventory and License Metric Tool
IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests.
network
low complexity
ibm hp linux microsoft oracle CWE-200
5.0
2017-02-01 CVE-2016-8966 Information Exposure vulnerability in IBM Bigfix Inventory and License Metric Tool
IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security.
4.3
2017-02-01 CVE-2016-8961 Open Redirect vulnerability in IBM Bigfix Inventory and License Metric Tool
IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
5.8
2017-02-01 CVE-2016-6034 Information Exposure vulnerability in IBM Tivoli Storage Manager FOR Virtual Environments Data Protection FOR VMWare
IBM Tivoli Storage Manager for Virtual Environments (VMware) could disclose the Windows domain credentials to a user with a high level of privileges.
network
low complexity
ibm microsoft CWE-200
4.0
2017-01-31 CVE-2016-9418 Information Exposure vulnerability in Mybb Merge System and Mybb
MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows might allow remote attackers to obtain sensitive information from ACP backups via vectors involving a short name.
network
low complexity
mybb microsoft CWE-200
5.0
2017-01-31 CVE-2016-9415 Improper Access Control vulnerability in Mybb Merge System and Mybb
MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows allow remote attackers to overwrite arbitrary CSS files via vectors related to "style import."
network
low complexity
mybb microsoft CWE-284
5.0
2017-01-30 CVE-2016-7544 Resource Management Errors vulnerability in Cryptopp Crypto++ 5.6.4
Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions.
network
low complexity
cryptopp microsoft CWE-399
5.0
2017-01-24 CVE-2017-2929 Cross-site Scripting vulnerability in Adobe Acrobat 15.1.0.3
Adobe Acrobat Chrome extension version 15.1.0.3 and earlier have a DOM-based cross-site scripting vulnerability.
4.3
2017-01-23 CVE-2017-5556 Out-of-bounds Read vulnerability in Foxitsoftware Foxit Reader and Phantompdf
The ConvertToPDF plugin in Foxit Reader before 8.2 and PhantomPDF before 8.2 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image.
5.8
2017-01-18 CVE-2016-10086 Permissions, Privileges, and Access Controls vulnerability in CA Service Desk Management and Service Desk Manager
RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticated users to read or modify task information by leveraging incorrect permissions applied to a RESTful request.
network
low complexity
ca ibm linux microsoft oracle CWE-264
5.5