Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-01-23 CVE-2016-10101 Inadequate Encryption Strength vulnerability in Hiteksoftware Automize
Information Disclosure can occur in Hitek Software's Automize 10.x and 11.x passManager.jsd.
network
high complexity
hiteksoftware CWE-326
8.1
2017-01-20 CVE-2016-6253 Link Following vulnerability in Netbsd
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox.
local
low complexity
netbsd CWE-59
7.8
2017-01-20 CVE-2016-5323 Divide By Zero vulnerability in multiple products
The _TIFFFax3fillruns function in libtiff before 4.0.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted Tiff image.
network
low complexity
libtiff opensuse CWE-369
7.5
2017-01-20 CVE-2014-9755 Improper Input Validation vulnerability in Viprinet Multichannel VPN Router 300 Firmware 2013070830/2013080900
The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows remote attackers to perform a replay attack.
network
low complexity
viprinet CWE-20
7.5
2017-01-20 CVE-2016-7038 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Moodle
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
network
low complexity
moodle CWE-640
7.3
2017-01-20 CVE-2016-10143 Information Exposure vulnerability in Tiki Tikiwiki Cms/Groupware 15.2
A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on a targeted system via a crafted pathname in a banner URL field.
network
low complexity
tiki CWE-200
7.5
2017-01-19 CVE-2016-9016 Improper Access Control vulnerability in Firejail Project Firejail 0.9.38.4
Firejail 0.9.38.4 allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
local
low complexity
firejail-project CWE-284
8.8
2017-01-19 CVE-2016-7793 Improper Access Control vulnerability in Sociomantic Git-Hub
sociomantic-tsunami git-hub before 0.10.3 allows remote attackers to execute arbitrary code via a crafted repository URL.
network
low complexity
sociomantic CWE-284
8.8
2017-01-19 CVE-2016-7545 Improper Access Control vulnerability in multiple products
SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
8.8
2017-01-19 CVE-2016-7543 Improper Input Validation vulnerability in multiple products
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
local
low complexity
gnu fedoraproject CWE-20
8.4