Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-02-13 CVE-2016-5803 Path Traversal vulnerability in CA Technologies Unified Infrastructure Management
An issue was discovered in CA Unified Infrastructure Management Version 8.47 and earlier.
network
low complexity
ca-technologies CWE-22
8.6
2017-02-13 CVE-2016-5802 Out-of-bounds Write vulnerability in Delta Electronics Ispsoft, Pmsoft and Wplsoft
An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, and PMSoft, Versions prior to 2.10.10.
local
low complexity
delta-electronics CWE-787
7.8
2017-02-13 CVE-2016-5801 Improper Access Control vulnerability in Omnimetrix Omniview 1.2
An issue was discovered in OmniMetrix OmniView, Version 1.2.
network
low complexity
omnimetrix CWE-284
7.5
2017-02-13 CVE-2016-5798 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Fatek Automation FV Designer and Automation PM Designer
An issue was discovered in Fatek Automation PM Designer V3 Version 2.1.2.2, and Automation FV Designer Version 1.2.8.0.
network
low complexity
fatek CWE-119
7.5
2017-02-13 CVE-2016-5796 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Fatek Automation FV Designer and Automation PM Designer
An issue was discovered in Fatek Automation PM Designer V3 Version 2.1.2.2, and Automation FV Designer Version 1.2.8.0.
network
low complexity
fatek CWE-119
8.8
2017-02-13 CVE-2016-5786 Information Exposure vulnerability in Omnimetrix Omniview 1.2
An issue was discovered in OmniMetrix OmniView, Version 1.2.
network
low complexity
omnimetrix CWE-200
7.5
2017-02-13 CVE-2016-5782 Improper Input Validation vulnerability in Locusenergy Lgate Firmware
An issue was discovered in Locus Energy LGate prior to 1.05H, LGate 50, LGate 100, LGate 101, LGate 120, and LGate 320.
network
low complexity
locusenergy CWE-20
8.6
2017-02-13 CVE-2016-10224 7PK - Security Features vulnerability in Sauter-Controls Novaweb web HMI
An issue was discovered in Sauter NovaWeb web HMI.
network
low complexity
sauter-controls CWE-254
7.2
2017-02-13 CVE-2016-8659 Permissions, Privileges, and Access Controls vulnerability in Bubblewrap Project Bubblewrap
Bubblewrap before 0.1.3 sets the PR_SET_DUMPABLE flag, which might allow local users to gain privileges by attaching to the process, as demonstrated by sending commands to a PrivSep socket.
local
high complexity
bubblewrap-project CWE-264
7.0
2017-02-13 CVE-2016-6129 Improper Input Validation vulnerability in multiple products
The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message length is equal to the ASN.1 encoded data length, which makes it easier for remote attackers to forge RSA signatures or public certificates by leveraging a Bleichenbacher signature forgery attack.
network
low complexity
op-tee libtom CWE-20
7.5