Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-04-12 CVE-2016-5313 OS Command Injection vulnerability in Symantec web Gateway
Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.
network
low complexity
symantec CWE-78
8.8
2017-04-12 CVE-2016-4895 Code Injection vulnerability in Setucocms Project Setucocms
SetsucoCMS all versions allows remote authenticated attackers to conduct code injection attacks via unspecified vectors.
network
low complexity
setucocms-project CWE-94
8.8
2017-04-12 CVE-2016-4893 SQL Injection vulnerability in Setucocms Project Setucocms
SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
setucocms-project CWE-89
8.8
2017-04-12 CVE-2016-4891 Cross-Site Request Forgery (CSRF) vulnerability in Setucocms Project Setucocms
Cross-site request forgery (CSRF) vulnerability in SetsucoCMS all versions allows remote attackers to hijack the authentication of an administrator to change settings via unspecified vectors.
network
low complexity
setucocms-project CWE-352
8.8
2017-04-12 CVE-2015-7563 Cross-Site Request Forgery (CSRF) vulnerability in Teampass
Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticated user.
network
low complexity
teampass CWE-352
8.8
2017-04-12 CVE-2017-6059 Improper Input Validation vulnerability in Openidc MOD Auth Openidc
Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a malicious URL provided to the user, which triggers an invalid request.
network
low complexity
openidc CWE-20
7.5
2017-04-12 CVE-2016-9959 Out-of-bounds Write vulnerability in multiple products
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
7.8
2017-04-12 CVE-2016-9958 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
7.8
2017-04-12 CVE-2016-9957 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Stack-based buffer overflow in game-music-emu before 0.6.1.
7.8
2017-04-12 CVE-2016-4459 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Redhat Enterprise Linux and MOD Cluster
Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.
network
low complexity
redhat CWE-119
7.5