Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2016-12-27 CVE-2016-10031 Permissions, Privileges, and Access Controls vulnerability in Wampserver 3.0.6
WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges.
local
high complexity
wampserver CWE-264
7.5
2016-12-26 CVE-2016-9217 Improper Authorization vulnerability in Cisco Intercloud Fabric 2.2.1Base/2.3.1Base/3.1.1Base
A vulnerability in Cisco Intercloud Fabric for Business and Cisco Intercloud Fabric for Providers could allow an unauthenticated, remote attacker to connect to the database used by these products.
network
low complexity
cisco CWE-285
8.8
2016-12-25 CVE-2016-10041 Permissions, Privileges, and Access Controls vulnerability in Sprecher-Automation Sprecon-E Service Program 3.42
An issue was discovered in Sprecher Automation SPRECON-E Service Program before 3.43 SP0.
network
high complexity
sprecher-automation CWE-264
7.5
2016-12-24 CVE-2016-10039 Path Traversal vulnerability in Modx Revolution
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/getfiles.
network
low complexity
modx CWE-22
7.3
2016-12-24 CVE-2016-10038 Path Traversal vulnerability in Modx Revolution
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove.
network
low complexity
modx CWE-22
7.3
2016-12-24 CVE-2016-10037 Path Traversal vulnerability in Modx Revolution
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted id (aka dir) parameter, related to browser/directory/getlist.
network
low complexity
modx CWE-22
7.3
2016-12-23 CVE-2016-9037 Out-of-bounds Read vulnerability in Tarantool 1.7.2
An exploitable out-of-bounds array access vulnerability exists in the xrow_header_decode function of Tarantool 1.7.2.0-g8e92715.
network
low complexity
tarantool CWE-125
7.5
2016-12-23 CVE-2016-9036 Out-of-bounds Read vulnerability in Tarantool Msgpuck 1.0.3
An exploitable incorrect return value vulnerability exists in the mp_check function of Tarantool's Msgpuck library 1.0.3.
network
low complexity
tarantool CWE-125
7.5
2016-12-23 CVE-2016-8707 Out-of-bounds Write vulnerability in multiple products
An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility.
local
low complexity
imagemagick debian CWE-787
7.8
2016-12-23 CVE-2016-7967 Improper Access Control vulnerability in KDE Kmail
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled.
network
low complexity
kde CWE-284
8.1