Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-09-21 CVE-2017-11001 Information Exposure vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, the length of the MAC address is not checked which may cause out of bounds read.
local
low complexity
google CWE-200
5.5
2017-09-21 CVE-2017-10996 Information Exposure vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, out of bounds access is possible in c_show(), due to compat_hwcap_str[] not being NULL-terminated.
local
low complexity
google CWE-200
5.5
2017-09-21 CVE-2015-4706 Cross-site Scripting vulnerability in Ipython 3.0.0/3.1.0
Cross-site scripting (XSS) vulnerability in IPython 3.x before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/contents path.
network
low complexity
ipython CWE-79
6.1
2017-09-21 CVE-2015-3296 Cross-site Scripting vulnerability in Nodebb
Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript: or (2) data: URLs.
network
low complexity
nodebb CWE-79
6.1
2017-09-21 CVE-2017-14634 Divide By Zero vulnerability in multiple products
In libsndfile 1.0.28, a divide-by-zero error exists in the function double64_init() in double64.c, which may lead to DoS when playing a crafted audio file.
network
low complexity
libsndfile-project debian CWE-369
6.5
2017-09-21 CVE-2017-14633 Out-of-bounds Read vulnerability in multiple products
In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().
network
low complexity
xiph-org debian canonical CWE-125
6.5
2017-09-21 CVE-2017-6720 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
A vulnerability in the Secure Shell (SSH) subsystem of Cisco Small Business Managed Switches software could allow an authenticated, remote attacker to cause a reload of the affected switch, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-119
6.5
2017-09-21 CVE-2017-12255 Improper Input Validation vulnerability in Cisco Unified Computing System 1.5(1C)
A vulnerability in the CLI of Cisco UCS Central Software could allow an authenticated, local attacker to gain shell access.
local
low complexity
cisco CWE-20
6.7
2017-09-21 CVE-2017-12254 Cross-site Scripting vulnerability in Cisco Unified Intelligence Center 11.5(1)
A vulnerability in the web interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to perform a Document Object Model (DOM)-based cross-site scripting attack.
network
low complexity
cisco CWE-79
6.1
2017-09-21 CVE-2017-12250 Improper Input Validation vulnerability in Cisco Wide Area Application Services 6.2(3A)
A vulnerability in the HTTP web interface for Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an HTTP Application Optimization (AO) related process to restart, causing a partial denial of service (DoS) condition.
network
low complexity
cisco CWE-20
5.3