Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2016-01-16 CVE-2016-1133 Unspecified vulnerability in Dena H2O
CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URI.
network
high complexity
dena
3.7
2016-01-12 CVE-2015-7759 Improper Input Validation vulnerability in F5 products
BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 12.0.0 before HF1, when the TCP profile for a virtual server is configured with Congestion Metrics Cache enabled, allow remote attackers to cause a denial of service (Traffic Management Microkernel (TMM) restart) via crafted ICMP packets, related to Path MTU (PMTU) discovery.
network
high complexity
f5 CWE-20
3.7
2016-01-12 CVE-2015-7548 Information Exposure vulnerability in Openstack Nova
OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot.
network
high complexity
openstack CWE-200
3.5
2016-01-10 CVE-2015-7466 Injection vulnerability in IBM Jazz Reporting Service 6.0
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended query restrictions or modify the LDAP directory, via unspecified vectors.
network
high complexity
ibm CWE-74
3.1
2016-01-08 CVE-2016-1500 Information Exposure vulnerability in Owncloud
ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the files with names starting with ".v" and belonging to a sharing user by leveraging an incoming share.
network
high complexity
owncloud CWE-200
3.1
2016-01-08 CVE-2015-8481 Information Exposure vulnerability in Atlassian Jira Core, Jira Server and Jira Service Desk
Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Desk 3.0.3 installer attaches the wrong image to e-mail notifications when a user views an issue with inline wiki markup referencing an image attachment, which might allow remote attackers to obtain sensitive information by updating a different issue that includes wiki markup for an external image reference.
network
high complexity
atlassian CWE-200
3.1
2016-01-08 CVE-2015-7758 Link Following vulnerability in multiple products
Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the name of an existing file and a (1) .aux, (2) .log, (3) .out, (4) .pdf, or (5) .toc extension for the file name, as demonstrated by .thesis.tex.aux.
local
low complexity
opensuse gummi-project CWE-59
3.3
2016-01-08 CVE-2015-7519 Improper Input Validation vulnerability in Phusionpassenger Phusion Passenger
agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.
network
high complexity
phusionpassenger CWE-20
3.7
2016-01-06 CVE-2015-6644 Information Exposure vulnerability in Google Android
Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.
local
low complexity
google CWE-200
3.3
2016-01-06 CVE-2015-6641 Information Exposure vulnerability in Google Android 6.0
Bluetooth in Android 6.0 before 2016-01-01 allows remote attackers to obtain sensitive Contacts information by leveraging pairing, aka internal bug 23607427.
high complexity
google CWE-200
3.1