Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2016-10-28 CVE-2016-4396 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HP System Management Homepage
HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" issue.
network
low complexity
hp CWE-119
7.5
2016-10-28 CVE-2016-4395 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HP System Management Homepage
HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" issue.
network
low complexity
hp CWE-119
7.5
2016-10-28 CVE-2016-8335 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Iceni Argus 6.6.04
An exploitable stack based buffer overflow vulnerability exists in the ipNameAdd functionality of Iceni Argus Version 6.6.04 (Sep 7 2012) NK - Linux x64 and Version 6.6.04 (Nov 14 2014) NK - Windows x64.
local
low complexity
iceni CWE-119
7.8
2016-10-28 CVE-2016-8333 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Iceni Argus 6.6.04
An exploitable stack-based buffer overflow vulnerability exists in the ipfSetColourStroke functionality of Iceni Argus version 6.6.04 A specially crafted pdf file can cause a buffer overflow resulting in arbitrary code execution.
local
low complexity
iceni CWE-119
7.8
2016-10-28 CVE-2016-8331 Unspecified vulnerability in Libtiff 4.0.6
An exploitable remote code execution vulnerability exists in the handling of TIFF images in LibTIFF version 4.0.6.
network
high complexity
libtiff
8.1
2016-10-28 CVE-2016-9028 7PK - Security Features vulnerability in Citrix Netscaler Application Delivery Controller Firmware
Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header.
network
low complexity
citrix CWE-254
8.8
2016-10-28 CVE-2016-9017 Out-of-bounds Read vulnerability in Artifex Mujs
Artifex Software, Inc.
network
low complexity
artifex CWE-125
7.5
2016-10-28 CVE-2016-8867 Permissions, Privileges, and Access Controls vulnerability in Docker 1.12.2
Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies.
network
low complexity
docker CWE-264
7.5
2016-10-28 CVE-2016-8600 7PK - Security Features vulnerability in Dotcms 3.2.1
In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.
network
low complexity
dotcms CWE-254
7.5
2016-10-28 CVE-2016-7919 SQL Injection vulnerability in Moodle 3.1.2
Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component.
network
low complexity
moodle CWE-89
7.5