Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2016-01-31 CVE-2016-1945 The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive.
network
low complexity
mozilla opensuse
8.8
2016-01-31 CVE-2016-1942 Improper Input Validation vulnerability in multiple products
Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a (1) wyciwyg: URI or (2) resource: URI.
network
low complexity
opensuse mozilla CWE-20
7.4
2016-01-31 CVE-2016-1935 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbitrary code via crafted WebGL content.
network
low complexity
opensuse oracle mozilla CWE-119
8.8
2016-01-30 CVE-2016-1145 Path Traversal vulnerability in NEC Expresscluster X 3.3
Directory traversal vulnerability in WebManager in NEC EXPRESSCLUSTER X through 3.3 11.31 on Windows and through 3.3 3.3.1-1 on Linux and Solaris allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
nec CWE-22
7.5
2016-01-30 CVE-2016-1139 Cross-Site Request Forgery (CSRF) vulnerability in Kddi Home Spot Cube Firmware 2.0
Cross-site request forgery (CSRF) vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
network
high complexity
kddi CWE-352
7.5
2016-01-30 CVE-2016-1137 Unspecified vulnerability in Kddi Home Spot Cube Firmware 2.0
Open redirect vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
low complexity
kddi
7.4
2016-01-30 CVE-2016-0867 Information Exposure vulnerability in Carel Plantvisor Enhanced
CAREL PlantVisorEnhanced allows remote attackers to bypass intended access restrictions via a direct file request.
network
low complexity
carel CWE-200
7.5
2016-01-30 CVE-2016-1303 Improper Input Validation vulnerability in Cisco 500 Series Switch Firmware 1.2.0.92
The web GUI on Cisco Small Business 500 devices 1.2.0.92 allows remote attackers to cause a denial of service via a crafted HTTP request, aka Bug ID CSCul65330.
network
low complexity
cisco CWE-20
7.5
2016-01-29 CVE-2016-1493 Insufficient Verification of Data Authenticity vulnerability in Intel Driver Update Utility
Intel Driver Update Utility before 2.4 retrieves driver updates in cleartext, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted file.
network
high complexity
intel CWE-345
7.5
2016-01-29 CVE-2016-0755 Improper Authentication vulnerability in multiple products
The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.
network
low complexity
haxx canonical debian CWE-287
7.3