Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2016-01-22 CVE-2016-1984 Credentials Management vulnerability in Harman AMX Firmware 1.2.322/1.3.100
The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the 1MB@tMaN account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2015-8362.
network
low complexity
harman CWE-255
critical
9.8
2016-01-22 CVE-2015-8362 Credentials Management vulnerability in Harman AMX Firmware 1.2.322/1.3.100
The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2015-10-12 has a hardcoded password for the BlackWidow account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2016-1984.
network
low complexity
harman CWE-255
critical
9.8
2016-01-22 CVE-2015-6435 OS Command Injection vulnerability in Cisco products
An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 before 3.0(2e) allows remote attackers to execute arbitrary shell commands via a crafted HTTP request, aka Bug ID CSCur90888.
network
low complexity
cisco CWE-78
critical
9.8
2016-01-22 CVE-2015-6412 Credentials Management vulnerability in Cisco Modular Encoding Platform D9036 Software
Cisco Modular Encoding Platform D9036 Software before 02.04.70 has hardcoded (1) root and (2) guest passwords, which makes it easier for remote attackers to obtain access via an SSH session, aka Bug ID CSCut88070.
network
low complexity
cisco CWE-255
critical
9.8
2016-01-20 CVE-2016-1929 Improper Input Validation vulnerability in SAP Hana
The XS engine in SAP HANA allows remote attackers to spoof log entries in trace files and consequently cause a denial of service (disk consumption and process crash) via a crafted HTTP request, related to an unspecified debug function, aka SAP Security Note 2241978.
network
low complexity
sap CWE-20
critical
9.3
2016-01-20 CVE-2016-1928 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in SAP Hana
Buffer overflow in the XS engine (hdbxsengine) in SAP HANA allows remote attackers to cause a denial of service or execute arbitrary code via a crafted HTTP request, related to JSON, aka SAP Security Note 2241978.
network
low complexity
sap CWE-119
critical
9.8
2016-01-20 CVE-2016-1901 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Content-Length HTTP header, which triggers a buffer overflow.
network
low complexity
fedoraproject cgit-project CWE-119
critical
9.8
2016-01-19 CVE-2016-1903 Information Exposure vulnerability in PHP
The gdImageRotateInterpolated function in ext/gd/libgd/gd_interpolation.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a large bgd_color argument to the imagerotate function.
network
low complexity
php CWE-200
critical
9.1
2016-01-19 CVE-2015-8617 Use of Externally-Controlled Format String vulnerability in PHP 7.0.1
Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute arbitrary code via format string specifiers in a string that is misused as a class name, leading to incorrect error handling.
network
low complexity
php CWE-134
critical
9.8
2016-01-16 CVE-2016-1142 OS Command Injection vulnerability in Seeds Acmailer
Seeds acmailer before 3.8.21 and 3.9.x before 3.9.15 Beta allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.
network
low complexity
seeds CWE-78
critical
9.1