Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-12-07 CVE-2017-1481 Information Exposure vulnerability in IBM Sterling B2B Integrator 5.2
IBM Sterling B2B Integrator Standard Edition 5.2 allows a user to view sensitive information that belongs to another user.
network
low complexity
ibm CWE-200
4.3
2017-12-07 CVE-2017-1465 Cross-site Scripting vulnerability in IBM Tririga Application Platform
IBM TRIRIGA 3.2, 3.3, 3.4, and 3.5 could allow a remote attacker to hijack the clicking action of the victim.
network
low complexity
ibm CWE-79
5.4
2017-12-07 CVE-2017-1433 Unspecified vulnerability in IBM Websphere MQ
IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow an authenticated user to insert messages with a corrupt RFH header into the channel which would cause it to restart.
network
low complexity
ibm
6.5
2017-12-07 CVE-2017-1354 Cross-site Scripting vulnerability in IBM Atlas Ediscovery Process Management
IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-12-07 CVE-2017-1342 Information Exposure vulnerability in IBM Insights Foundation for Energy 2.0
IBM Insights Foundation for Energy 2.0 could reveal sensitive information in error messages to authenticated users that could e used to conduct further attacks.
network
low complexity
ibm CWE-200
4.3
2017-12-07 CVE-2017-1336 Code Injection vulnerability in IBM Infosphere Biginsights 4.2.0
IBM Infosphere BigInsights 4.2.0 could allow an attacker to inject code that could allow access to restricted data and files.
network
high complexity
ibm CWE-94
4.4
2017-12-07 CVE-2017-17381 Divide By Zero vulnerability in multiple products
The Virtio Vring implementation in QEMU allows local OS guest users to cause a denial of service (divide-by-zero error and QEMU process crash) by unsetting vring alignment while updating Virtio rings.
local
low complexity
qemu debian CWE-369
6.5
2017-12-07 CVE-2017-16884 Cross-site Scripting vulnerability in Mistserver
Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web script or HTML via vectors related to failed authentication requests alerts.
network
low complexity
mistserver CWE-79
6.1
2017-12-07 CVE-2017-15121 Unspecified vulnerability in Redhat products
A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary.
local
low complexity
redhat
5.5
2017-12-07 CVE-2017-17451 Cross-site Scripting vulnerability in Wpmailster WP Mailster
The WP Mailster plugin before 1.5.5 for WordPress has XSS in the unsubscribe handler via the mes parameter to view/subscription/unsubscribe2.php.
network
low complexity
wpmailster CWE-79
6.1