Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-10-03 CVE-2017-14755 Cross-site Scripting vulnerability in Opentext Document Sciences Xpression 4.5
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Cross-Site Scripting: /xAdmin/html/XPressoDoc, parameter: categoryId.
network
low complexity
opentext CWE-79
6.1
2017-10-03 CVE-2017-14754 Path Traversal vulnerability in Opentext Document Sciences Xpression 4.5
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Arbitrary File Read: /xAdmin/html/cm_datasource_group_xsd.jsp, parameter: xsd_datasource_schema_file filename.
network
low complexity
opentext CWE-22
6.5
2017-10-03 CVE-2017-14494 Information Exposure vulnerability in multiple products
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.
network
high complexity
redhat debian novell canonical thekelleys CWE-200
5.9
2017-10-03 CVE-2017-1429 Cross-site Scripting vulnerability in IBM Rational Engineering Lifecycle Manager
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-10-03 CVE-2017-1369 Cross-site Scripting vulnerability in IBM Rational Engineering Lifecycle Manager
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-10-03 CVE-2017-1364 Cross-site Scripting vulnerability in IBM Rational Engineering Lifecycle Manager
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-10-03 CVE-2017-1359 Cross-site Scripting vulnerability in IBM Rational Engineering Lifecycle Manager
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-10-03 CVE-2017-1345 Cross-site Scripting vulnerability in IBM Insights Foundation for Energy 2.0
IBM Insights Foundation for Energy 2.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-10-03 CVE-2017-1335 Cross-site Scripting vulnerability in IBM Rational Engineering Lifecycle Manager
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-10-03 CVE-2017-1334 Cross-site Scripting vulnerability in IBM Rational Engineering Lifecycle Manager
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4