Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2017-01-06 CVE-2016-4323 Path Traversal vulnerability in multiple products
A directory traversal exists in the handling of the MXIT protocol in Pidgin.
network
high complexity
pidgin canonical debian CWE-22
3.7
2017-01-06 CVE-2016-2380 Out-of-bounds Read vulnerability in multiple products
An information leak exists in the handling of the MXIT protocol in Pidgin.
network
high complexity
pidgin canonical debian CWE-125
3.1
2017-01-04 CVE-2016-7903 Permissions, Privileges, and Access Controls vulnerability in Dotclear
Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header.
network
high complexity
dotclear CWE-264
3.7
2016-12-23 CVE-2016-9908 Information Exposure vulnerability in Qemu
Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue.
local
low complexity
qemu CWE-200
3.3
2016-12-15 CVE-2016-4027 Information Exposure vulnerability in Open-Xchange Appsuite 7.8.1
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev10.
network
low complexity
open-xchange CWE-200
3.5
2016-11-30 CVE-2016-2877 Permission Issues vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses weak permissions for unspecified directories under the web root, which allows local users to modify data by writing to a file.
local
low complexity
ibm CWE-275
3.3
2016-11-30 CVE-2016-2874 Improper Access Control vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 mishandles authorization, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
network
high complexity
ibm CWE-284
3.1
2016-11-30 CVE-2016-3009 Cross-Site Request Forgery (CSRF) vulnerability in IBM Connections 4.0.0.0/4.5.0.0/5.0.0.0
Cross-site request forgery (CSRF) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that modify the Connections generic page.
network
low complexity
ibm CWE-352
3.5
2016-11-30 CVE-2016-3002 Information Exposure vulnerability in IBM Connections 4.0.0.0/4.5.0.0/5.0.0.0
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sensitive information by reading cached data on a client device.
low complexity
ibm CWE-200
2.1
2016-11-30 CVE-2016-2953 Cryptographic Issues vulnerability in IBM Connections 4.0.0.0/4.5.0.0/5.0.0.0
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.
network
high complexity
ibm CWE-310
3.7