Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-01-18 CVE-2018-5773 Cross-site Scripting vulnerability in Python-Markdown2 Project Python-Markdown2
An issue was discovered in markdown2 (aka python-markdown2) through 2.3.5.
network
low complexity
python-markdown2-project CWE-79
6.1
2018-01-18 CVE-2017-12197 Improper Input Validation vulnerability in multiple products
It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating.
network
low complexity
libpam4j-project redhat debian CWE-20
6.5
2018-01-18 CVE-2017-16863 Cross-site Scripting vulnerability in Atlassian Jira
The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a project or filter.
network
low complexity
atlassian CWE-79
6.1
2018-01-18 CVE-2017-18033 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira
The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external system import via various Cross-site request forgery (CSRF) vulnerabilities.
network
low complexity
atlassian CWE-352
6.5
2018-01-18 CVE-2017-15869 Cross-site Scripting vulnerability in Livezilla
Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inject arbitrary web script or HTML via the search-for parameter.
network
low complexity
livezilla CWE-79
6.1
2018-01-18 CVE-2014-2017 CRLF Injection vulnerability in Oxidforge Eshop
CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x before 5.1.4, and Community Edition before 4.7.11 and 4.8.x before 4.8.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
network
low complexity
oxidforge CWE-93
6.1
2018-01-18 CVE-2018-5772 Uncontrolled Recursion vulnerability in Exiv2 0.26
In Exiv2 0.26, there is a segmentation fault caused by uncontrolled recursion in the Exiv2::Image::printIFDStructure function in the image.cpp file.
local
low complexity
exiv2 CWE-674
5.5
2018-01-18 CVE-2018-0115 OS Command Injection vulnerability in Cisco Staros
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series routers could allow an authenticated, local attacker to execute arbitrary commands with root privileges on an affected host operating system.
local
low complexity
cisco CWE-78
6.7
2018-01-18 CVE-2018-0111 Information Exposure vulnerability in Cisco Webex Meetings Server
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data about the application.
network
low complexity
cisco CWE-200
5.3
2018-01-18 CVE-2018-0108 XXE vulnerability in Cisco Webex Meetings Server
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to collect customer files via an out-of-band XML External Entity (XXE) injection.
network
low complexity
cisco CWE-611
5.3