Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-10-13 CVE-2017-11784 Information Exposure vulnerability in Microsoft products
The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability".
local
low complexity
microsoft CWE-200
5.5
2017-10-13 CVE-2017-11777 Cross-site Scripting vulnerability in Microsoft Sharepoint Enterprise Server 2013/2016
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cross-site scripting (XSS) vulnerability by sending a specially crafted request to an affected SharePoint server, due to how SharePoint Server sanitizes web requests, aka "Microsoft Office SharePoint XSS Vulnerability".
network
low complexity
microsoft CWE-79
5.4
2017-10-13 CVE-2017-11775 Cross-site Scripting vulnerability in Microsoft Sharepoint Enterprise Server 2013/2016
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cross-site scripting (XSS) vulnerability by sending a specially crafted request to an affected SharePoint server, due to how SharePoint Server sanitizes web requests, aka "Microsoft Office SharePoint XSS Vulnerability".
network
low complexity
microsoft CWE-79
5.4
2017-10-13 CVE-2017-11765 Information Exposure vulnerability in Microsoft products
The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability".
local
low complexity
microsoft CWE-200
5.5
2017-10-12 CVE-2016-9263 Improper Input Validation vulnerability in Wordpress
WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.
network
high complexity
wordpress CWE-20
4.7
2017-10-12 CVE-2017-15287 Cross-site Scripting vulnerability in Bouqueteditor Project Bouqueteditor 2.0.0
There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouquets" field, or the file parameter to the /file URI.
network
low complexity
bouqueteditor-project CWE-79
6.1
2017-10-12 CVE-2017-12849 Information Exposure vulnerability in Silverstripe
Response discrepancy in the login and password reset forms in SilverStripe CMS before 3.5.5 and 3.6.x before 3.6.1 allows remote attackers to enumerate users via timing attacks.
network
low complexity
silverstripe CWE-200
5.3
2017-10-12 CVE-2015-6358 Improper Certificate Validation vulnerability in Cisco products
Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installation, aka Bug IDs CSCuw46610, CSCuw46620, CSCuw46637, CSCuw46654, CSCuw46665, CSCuw46672, CSCuw46677, CSCuw46682, CSCuw46705, CSCuw46716, CSCuw46979, CSCuw47005, CSCuw47028, CSCuw47040, CSCuw47048, CSCuw47061, CSCuw90860, CSCuw90869, CSCuw90875, CSCuw90881, CSCuw90899, and CSCuw90913.
network
high complexity
cisco CWE-295
5.9
2017-10-12 CVE-2017-10862 Insufficient Verification of Data Authenticity vulnerability in Really Jwt-Scala 1.2.2
jwt-scala 1.2.2 and earlier fails to verify token signatures correctly which may lead to an attacker being able to pass specially crafted JWT data as a correctly signed token.
network
low complexity
really CWE-345
5.3
2017-10-12 CVE-2017-10857 Improper Privilege Management vulnerability in Cybozu Office
Cybozu Office 10.0.0 to 10.6.1 allows authenticated attackers to bypass access restriction to perform arbitrary actions via "Cabinet" function.
network
low complexity
cybozu CWE-269
4.3