Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2016-12-23 CVE-2016-7966 Code Injection vulnerability in multiple products
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer.
network
low complexity
kde debian fedoraproject suse CWE-94
7.3
2016-12-23 CVE-2016-9154 Insufficient Entropy in PRNG vulnerability in Siemens products
Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D (All firmware versions < V6.00.046) and Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 for Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U (All firmware versions < V6.00.046) use a pseudo random number generator with insufficient entropy to generate certificates for HTTPS, potentially allowing remote attackers to reconstruct the corresponding private key.
network
low complexity
siemens CWE-332
7.5
2016-12-23 CVE-2016-7502 Out-of-bounds Read vulnerability in Ffmpeg
The cavs_idct8_add_c function in libavcodec/cavsdsp.c in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when decoding with cavs_decode.
local
low complexity
ffmpeg CWE-125
7.8
2016-12-23 CVE-2016-7450 Out-of-bounds Read vulnerability in Ffmpeg
The ff_log2_16bit_c function in libavutil/intmath.h in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when it decodes a malformed AIFF file.
local
low complexity
ffmpeg CWE-125
7.8
2016-12-23 CVE-2016-6671 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ffmpeg
The raw_decode function in libavcodec/rawdec.c in FFmpeg before 3.1.2 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted SWF file.
local
low complexity
ffmpeg CWE-119
7.8
2016-12-23 CVE-2016-6659 Improper Authentication vulnerability in multiple products
Cloud Foundry before 248; UAA 2.x before 2.7.4.12, 3.x before 3.6.5, and 3.7.x through 3.9.x before 3.9.3; and UAA bosh release (aka uaa-release) before 13.9 for UAA 3.6.5 and before 24 for UAA 3.9.3 allow attackers to gain privileges by accessing UAA logs and subsequently running a specially crafted application that interacts with a configured SAML provider.
network
high complexity
pivotal-software cloudfoundry CWE-287
8.1
2016-12-22 CVE-2016-9675 Out-of-bounds Write vulnerability in multiple products
openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045.
local
low complexity
uclouvain redhat CWE-787
7.8
2016-12-22 CVE-2016-9181 XXE vulnerability in Image-Info Project Image-Info for Perl 1.16/1.30
perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled.
local
low complexity
image-info-project CWE-611
7.1
2016-12-22 CVE-2016-9179 Improper Input Validation vulnerability in Lynx
lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host.
network
low complexity
lynx CWE-20
7.5
2016-12-21 CVE-2016-7172 Information Exposure vulnerability in Netapp Snap Creator Framework
NetApp Snap Creator Framework before 4.3.1 discloses sensitive information which could be viewed by an unauthorized user.
network
low complexity
netapp CWE-200
7.5