Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-09-11 CVE-2015-7879 Cross-site Scripting vulnerability in Stickynote Project Stickynote
Cross-site scripting (XSS) vulnerability in the Stickynote module 7.x before 7.x-1.3 for Drupal allows remote authenticated users with permission to create or edit a stickynote to inject arbitrary web script or HTML via note text on the admin listing page.
network
low complexity
stickynote-project CWE-79
5.4
2017-09-11 CVE-2017-7650 Improper Authentication vulnerability in multiple products
In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'.
network
low complexity
eclipse debian CWE-287
6.5
2017-09-11 CVE-2017-14268 Cross-site Scripting vulnerability in EE 4Gee Wifi MBB Firmware Ee600005.0025
EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices have XSS in the sms_content parameter in a getSMSlist request.
network
low complexity
ee CWE-79
6.1
2017-09-11 CVE-2017-14249 Divide By Zero vulnerability in Imagemagick 7.0.68
ImageMagick 7.0.6-8 Q16 mishandles EOF checks in ReadMPCImage in coders/mpc.c, leading to division by zero in GetPixelCacheTileSize in MagickCore/cache.c, allowing remote attackers to cause a denial of service via a crafted file.
network
low complexity
imagemagick CWE-369
6.5
2017-09-11 CVE-2017-14248 Out-of-bounds Read vulnerability in Imagemagick 7.0.68
A heap-based buffer over-read in SampleImage() in MagickCore/resize.c in ImageMagick 7.0.6-8 Q16 allows remote attackers to cause a denial of service via a crafted file.
network
low complexity
imagemagick CWE-125
6.5
2017-09-11 CVE-2017-14241 Cross-site Scripting vulnerability in Dolibarr 6.0.0
Cross-site scripting (XSS) vulnerability in Dolibarr ERP/CRM 6.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the Title parameter to htdocs/admin/menus/edit.php.
network
low complexity
dolibarr CWE-79
5.4
2017-09-11 CVE-2017-14239 Cross-site Scripting vulnerability in Dolibarr 6.0.0
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 6.0.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) CompanyName, (2) CompanyAddress, (3) CompanyZip, (4) CompanyTown, (5) Fax, (6) EMail, (7) Web, (8) ManagingDirectors, (9) Note, (10) Capital, (11) ProfId1, (12) ProfId2, (13) ProfId3, (14) ProfId4, (15) ProfId5, or (16) ProfId6 parameter to htdocs/admin/company.php.
network
low complexity
dolibarr CWE-79
5.4
2017-09-10 CVE-2017-14231 Improper Input Validation vulnerability in Genixcms
GeniXCMS before 1.1.0 allows remote attackers to cause a denial of service (account blockage) by leveraging the mishandling of certain username substring relationships, such as the admin<script> username versus the admin username, related to register.php, User.class.php, and Type.class.php.
network
low complexity
genixcms CWE-20
5.3
2017-09-09 CVE-2017-14228 NULL Pointer Dereference vulnerability in multiple products
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function paste_tokens() in preproc.c, aka a NULL pointer dereference.
local
low complexity
nasm canonical CWE-476
5.5
2017-09-09 CVE-2017-8041 Cross-site Scripting vulnerability in VMWare Single Sign-On for Pivotal Cloud Foundry
In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, a user can execute a XSS attack on certain Single Sign-On service UI pages by inputting code in the text field for an organization name.
network
low complexity
vmware CWE-79
6.1