Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2016-12-29 CVE-2016-10081 Data Processing Errors vulnerability in Shutter-Project Shutter 0.93/0.93.1
/usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Run a plugin" action.
local
low complexity
shutter-project CWE-19
7.8
2016-12-29 CVE-2015-0854 Data Processing Errors vulnerability in Shutter-Project Shutter 0.93/0.93.1
App/HelperFunctions.pm in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Show in Folder" action.
local
low complexity
shutter-project CWE-19
7.8
2016-12-29 CVE-2016-9878 Path Traversal vulnerability in multiple products
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5.
network
low complexity
pivotal-software vmware CWE-22
7.5
2016-12-29 CVE-2016-7462 Exposed Dangerous Method or Function vulnerability in VMWare Vrealize Operations
The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload that is mishandled during deserialization.
network
low complexity
vmware CWE-749
8.5
2016-12-29 CVE-2016-7461 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in VMWare products
The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion and Fusion Pro 8.x before 8.5.2 allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (out-of-bounds memory access on the host OS) via unspecified vectors.
local
low complexity
vmware CWE-119
8.8
2016-12-29 CVE-2016-7459 XXE vulnerability in VMWare Vcenter Server 5.0/5.5/6.0
VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
network
low complexity
vmware CWE-611
7.7
2016-12-29 CVE-2016-7086 Permissions, Privileges, and Access Controls vulnerability in VMWare Workstation Player and Workstation PRO
The installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain privileges via a Trojan horse setup64.exe file in the installation directory.
local
low complexity
vmware CWE-264
7.8
2016-12-29 CVE-2016-7085 Untrusted Search Path vulnerability in VMWare Workstation Player and Workstation PRO
Untrusted search path vulnerability in the installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
vmware CWE-426
7.8
2016-12-29 CVE-2016-7084 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in VMWare Workstation Player and Workstation PRO
tpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (host OS memory corruption) via a JPEG 2000 image.
local
high complexity
vmware CWE-119
7.8
2016-12-29 CVE-2016-7083 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in VMWare Workstation Player and Workstation PRO
VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allow guest OS users to execute arbitrary code on the host OS or cause a denial of service (host OS memory corruption) via TrueType fonts embedded in EMFSPOOL.
local
high complexity
vmware CWE-119
7.8