Vulnerabilities > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-01-18 | CVE-2016-10086 | Permissions, Privileges, and Access Controls vulnerability in CA Service Desk Management and Service Desk Manager RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticated users to read or modify task information by leveraging incorrect permissions applied to a RESTful request. | 8.1 |
2017-01-18 | CVE-2016-6896 | Path Traversal vulnerability in Wordpress 4.5.3 Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a .. | 7.1 |
2017-01-18 | CVE-2016-9297 | Out-of-bounds Read vulnerability in Libtiff 4.0.6 The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII tag values. | 7.5 |
2017-01-18 | CVE-2016-9279 | Use After Free vulnerability in Samsung Exynos Fimg2D Driver Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sensitive information via unspecified vectors. | 7.5 |
2017-01-18 | CVE-2016-9109 | Out-of-bounds Read vulnerability in Artifex Mujs Artifex Software MuJS allows attackers to cause a denial of service (crash) via vectors related to incomplete escape sequences. | 7.5 |
2017-01-18 | CVE-2016-7999 | Server-Side Request Forgery (SSRF) vulnerability in Spip ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to conduct server side request forgery (SSRF) attacks via a URL in the var_url parameter in a valider_xml action. | 7.4 |
2017-01-18 | CVE-2016-7998 | Improper Input Validation vulnerability in Spip The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML file with a crafted (1) INCLUDE or (2) INCLURE tag and then accessing it with a valider_xml action. | 8.8 |
2017-01-18 | CVE-2016-7997 | NULL Pointer Dereference vulnerability in Graphicsmagick The WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (assertion failure and crash) via vectors related to a ReferenceBlob and a NULL pointer. | 7.5 |
2017-01-18 | CVE-2016-7982 | Path Traversal vulnerability in Spip Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in a valider_xml action. | 7.5 |
2017-01-18 | CVE-2016-7980 | Cross-Site Request Forgery (CSRF) vulnerability in Spip Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execute the XML validator on a local file via a crafted valider_xml request. | 8.8 |