Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2016-06-09 CVE-2016-2150 Improper Access Control vulnerability in multiple products
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
local
low complexity
redhat opensuse debian spice-project CWE-284
7.1
2016-06-09 CVE-2016-4523 Out-of-bounds Read vulnerability in Trihedral Vtscada
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via unspecified vectors.
network
low complexity
trihedral CWE-125
7.5
2016-06-09 CVE-2016-4370 Unspecified vulnerability in HPE Project and Portfolio Management Center
HPE Project and Portfolio Management Center (PPM) 9.2x and 9.3x before 9.32.0002 allows remote authenticated users to execute arbitrary commands or obtain sensitive information via unspecified vectors.
network
low complexity
hpe
8.8
2016-06-08 CVE-2016-3738 Permissions, Privileges, and Access Controls vulnerability in Redhat Openshift 3.2
Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket and gain privileges via vectors related to build-pod.
network
low complexity
redhat CWE-264
8.8
2016-06-08 CVE-2016-3708 Improper Access Control vulnerability in Redhat Openshift 3.2
Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in other namespaces, allows remote authenticated users to access network resources on restricted pods via an s2i build with a builder image that (1) contains ONBUILD commands or (2) does not contain a tar binary.
network
low complexity
redhat CWE-284
7.1
2016-06-08 CVE-2016-2160 Permissions, Privileges, and Access Controls vulnerability in Redhat Openshift and Openshift Origin
Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root privileges by changing the root password in an sti builder image.
network
low complexity
redhat CWE-264
8.8
2016-06-08 CVE-2016-4369 Improper Access Control vulnerability in HP Discovery and Dependency Mapping Inventory 9.30/9.31/9.32
HPE Discovery and Dependency Mapping Inventory (DDMi) 9.30, 9.31, 9.32, 9.32 update 1, 9.32 update 2, and 9.32 update 3 allows remote authenticated users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
network
low complexity
hp CWE-284
8.8
2016-06-08 CVE-2016-4367 Information Exposure vulnerability in HP Universal Cmbd Foundation
The Universal Discovery component in HPE Universal CMDB 10.0, 10.01, 10.10, 10.11, 10.20, and 10.21 allows remote attackers to obtain sensitive information via unspecified vectors.
network
low complexity
hp CWE-200
7.5
2016-06-08 CVE-2016-4365 Unspecified vulnerability in HP Insight Control Server Deployment
HPE Insight Control server deployment allows remote attackers to obtain sensitive information via unspecified vectors.
network
low complexity
hp
7.5
2016-06-08 CVE-2016-4364 Unspecified vulnerability in HP Insight Control Server Deployment
HPE Insight Control server deployment allows local users to gain privileges via unspecified vectors.
local
low complexity
hp
8.4