Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2016-01-10 CVE-2015-7465 Cross-Site Request Forgery (CSRF) vulnerability in IBM Jazz Reporting Service 6.0
Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
network
low complexity
ibm CWE-352
8.8
2016-01-10 CVE-2015-7397 Unspecified vulnerability in IBM Websphere Commerce 7.0
Multiple open redirect vulnerabilities in the Aurora starter store in IBM WebSphere Commerce 7.0 through Feature Pack 8 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referrer parameter.
network
low complexity
ibm
7.4
2016-01-08 CVE-2016-1499 Resource Management Errors vulnerability in Owncloud
ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information from a directory listing and possibly cause a denial of service (CPU consumption) via the force parameter to index.php/apps/files/ajax/scan.php.
network
low complexity
owncloud CWE-399
8.5
2016-01-08 CVE-2015-8765 Unspecified vulnerability in Mcafee Epolicy Orchestrator
Intel McAfee ePolicy Orchestrator (ePO) 4.6.9 and earlier, 5.0.x, 5.1.x before 5.1.3 Hotfix 1106041, and 5.3.x before 5.3.1 Hotfix 1106041 allow remote attackers to execute arbitrary code via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
network
low complexity
mcafee
8.3
2016-01-08 CVE-2015-4694 Path Traversal vulnerability in ZIP Attachments Project ZIP Attachments 1.5
Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote attackers to read arbitrary files via a ..
network
low complexity
zip-attachments-project CWE-22
8.6
2016-01-08 CVE-2014-8886 Cryptographic Issues vulnerability in AVM Fritz! OS 6.23
AVM FRITZ!OS before 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which allows remote attackers to create symlinks or overwrite critical files, and consequently execute arbitrary code, via a crafted firmware image.
network
high complexity
avm CWE-310
8.1
2016-01-08 CVE-2015-8754 Permissions, Privileges, and Access Controls vulnerability in Acquia Mollom
The Mollom module 6.x-2.7 before 6.x-2.15 for Drupal allows remote attackers to bypass intended access restrictions and modify the mollom blacklist via unspecified vectors.
network
low complexity
acquia CWE-264
7.5
2016-01-08 CVE-2015-8612 Permissions, Privileges, and Access Controls vulnerability in Blueman Project Blueman 1.99/2.0
The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users to gain privileges via the dhcp_handler argument.
local
low complexity
blueman-project CWE-264
8.4
2016-01-08 CVE-2015-8597 Unspecified vulnerability in Bluecoat Advanced Secure Gateway and Proxysg
Open redirect vulnerability in Blue Coat ProxySG 6.5 before 6.5.8.8 and 6.6 and Advanced Secure Gateway (ASG) 6.6 might allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a base64-encoded URL in conjunction with a "clear text" one in a coaching page, as demonstrated by "http://www.%humbug-URL%.local/bluecoat-splash-API?%BASE64-URL%."
network
low complexity
bluecoat
7.4
2016-01-08 CVE-2015-8547 Code vulnerability in multiple products
The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to cause a denial of service (application crash) via the "/op *" command in a query.
network
low complexity
quassel-irc opensuse CWE-17
7.5