Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2014-02-14 CVE-2013-6743 Cross-Site Scripting vulnerability in IBM Sametime
Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving an IMG element.
network
ibm CWE-79
3.5
2014-02-04 CVE-2014-1458 Cross-Site Scripting vulnerability in Fortinet Fortiweb
Cross-site scripting (XSS) vulnerability in the web administration interface in FortiGuard FortiWeb 5.0.3 and earlier allows remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors.
network
fortinet CWE-79
3.5
2014-02-04 CVE-2014-0019 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server name in the PROXY-CONNECT address in the command line.
1.9
2014-02-04 CVE-2013-6033 Cross-Site Scripting vulnerability in Lexmark products
Multiple cross-site scripting (XSS) vulnerabilities on Lexmark W840 through LS.HA.P252, T64x before LS.ST.P344, C935dn through LC.JO.P091, C920 through LS.TA.P152, C53x through LS.SW.P069, C52x through LS.FA.P150, E450 through LM.SZ.P124, E350 through LE.PH.P129, and E250 through LE.PM.P126 printers allow remote authenticated users to inject arbitrary web script or HTML by using (1) SNMP or (2) the Embedded Web Server (EWS) to set the (a) Contact or (b) Location field.
network
lexmark CWE-79
3.5
2014-02-03 CVE-2011-4327 Information Exposure vulnerability in Openbsd Openssh
ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.
local
low complexity
openbsd CWE-200
2.1
2014-02-02 CVE-2012-3427 Permissions, Privileges, and Access Controls vulnerability in Redhat Jboss Enterprise Application Platform 5.1.2
EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading files in the directory.
local
low complexity
redhat CWE-264
2.1
2014-02-02 CVE-2013-4331 Permissions, Privileges, and Access Controls vulnerability in Robert Ancell Lightdm
Light Display Manager (aka LightDM) 1.4.x before 1.4.3, 1.6.x before 1.6.2, and 1.7.x before 1.7.14 uses 0664 permissions for the temporary .Xauthority file, which allows local users to obtain sensitive information by reading the file.
local
low complexity
robert-ancell CWE-264
2.1
2014-02-01 CVE-2014-0832 Cross-Site Scripting vulnerability in IBM Financial Transaction Manager 2.0.0.0/2.0.0.1/2.0.0.2
Multiple cross-site scripting (XSS) vulnerabilities in configuration-details screens in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted text value.
network
ibm CWE-79
3.5
2014-01-31 CVE-2013-4383 Cross-Site Scripting vulnerability in Dennis Bruecke Jquery Countdown 7.X1.0
Cross-site scripting (XSS) vulnerability in the jQuery Countdown module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via unspecified vectors.
network
high complexity
dennis-bruecke drupal CWE-79
2.1
2014-01-30 CVE-2013-0177 Cross-Site Scripting vulnerability in Apache Ofbiz
Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly 09.04.x allow remote authenticated users to inject arbitrary web script or HTML via the (1) Screenlet.title or (2) Image.alt Widget attribute, as demonstrated by the parentPortalPageId parameter to exampleext/control/ManagePortalPages.
network
apache CWE-79
3.5