Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2017-12-11 CVE-2017-15897 Improper Initialization vulnerability in Nodejs Node.Js
Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified.
network
high complexity
nodejs CWE-665
3.1
2017-12-07 CVE-2017-1497 Information Exposure vulnerability in IBM Sterling File Gateway 2.2
IBM Sterling File Gateway 2.2 could allow an unauthorized user to view files they should not have access to providing they know the directory location of the file.
network
high complexity
ibm CWE-200
3.7
2017-12-07 CVE-2017-1355 Information Exposure vulnerability in IBM Atlas Ediscovery Process Management
IBM Atlas eDiscovery Process Management 6.0.3 stores sensitive information in URL parameters.
network
high complexity
ibm CWE-200
3.7
2017-12-07 CVE-2017-1353 Information Exposure vulnerability in IBM Atlas Ediscovery Process Management
IBM Atlas eDiscovery Process Management 6.0.3 could allow an authenticated attacker to obtain sensitive information when an unsuspecting user clicks on unsafe third-party links.
network
low complexity
ibm CWE-200
3.5
2017-12-07 CVE-2017-1341 Unspecified vulnerability in IBM Websphere MQ
IBM WebSphere MQ 8.0 and 9.0 could allow, under special circumstances, an unauthorized user to access an object which they should have been denied access.
network
high complexity
ibm
3.7
2017-12-06 CVE-2017-17433 Missing Authorization vulnerability in multiple products
The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allows remote attackers to bypass intended access restrictions.
network
high complexity
debian samba CWE-862
3.7
2017-12-03 CVE-2017-8822 Channel and Path Errors vulnerability in multiple products
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.
network
high complexity
tor-project debian CWE-417
3.7
2017-11-22 CVE-2017-8118 Information Exposure vulnerability in Huawei UMA V200R001/V300R001
The UMA product with software V200R001 and V300R001 has an information leak vulnerability.
local
low complexity
huawei CWE-200
2.3
2017-11-22 CVE-2017-2739 Download of Code Without Integrity Check vulnerability in Huawei Vmall 1.5.2.0
The upgrade package of Huawei Vmall APP Earlier than HwVmall 1.5.3.0 versions is transferred through HTTP.
high complexity
huawei CWE-494
3.1
2017-11-22 CVE-2017-2730 Information Exposure vulnerability in Huawei Hilink and Tech Support
HUAWEI HiLink APP (for IOS) versions earlier before 5.0.25.306 and HUAWEI Tech Support APP (for IOS) versions earlier before 5.0.0 have an information leak vulnerability.
low complexity
huawei CWE-200
3.5