Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-12-12 CVE-2017-16681 Cross-site Scripting vulnerability in SAP Business Intelligence Promotion Management Application 4.10/4.20/4.30
Cross-Site Scripting (XSS) vulnerability in SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, 4.30, as user controlled inputs are not sufficiently encoded.
network
low complexity
sap CWE-79
6.1
2017-12-12 CVE-2017-16679 Open Redirect vulnerability in SAP Kernel
URL redirection vulnerability in SAP's Startup Service, SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.22, 7.45, 7.49 and 7.52, that allows an attacker to redirect users to a malicious site.
network
low complexity
sap CWE-601
6.1
2017-12-12 CVE-2017-16678 Server-Side Request Forgery (SSRF) vulnerability in SAP products
Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50, that allows an attacker to manipulate the vulnerable application to send crafted requests on behalf of the application.
network
low complexity
sap CWE-918
4.7
2017-12-12 CVE-2017-17555 NULL Pointer Dereference vulnerability in multiple products
The swri_audio_convert function in audioconvert.c in FFmpeg libswresample through 3.0.101, as used in FFmpeg 3.4.1, aubio 0.4.6, and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted audio file.
network
low complexity
aubio ffmpeg CWE-476
6.5
2017-12-12 CVE-2017-17554 NULL Pointer Dereference vulnerability in Aubio 0.4.6
A NULL pointer dereference (DoS) Vulnerability was found in the function aubio_source_avcodec_readframe in io/source_avcodec.c of aubio 0.4.6, which may lead to DoS when playing a crafted audio file.
local
low complexity
aubio CWE-476
5.5
2017-12-12 CVE-2017-17553 Unspecified vulnerability in Changyou Dolphin 12.0.2
The Dolphin Browser for Android 12.0.2 suffers from an insecure parsing implementation of the Intent URI scheme.
network
low complexity
changyou
5.3
2017-12-11 CVE-2017-8867 Unspecified vulnerability in Cognitoys Stemosaur Firmware 0.0.794
Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 use AES-128 with ECB mode to encrypt voice traffic between the device and remote server, allowing a malicious user to map encrypted traffic to a particular AES key index and gaining further access to eavesdrop on privacy-sensitive voice communication of a child and their Dino device.
network
high complexity
cognitoys
5.9
2017-12-11 CVE-2017-8866 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Cognitoys Stemosaur Firmware 0.0.794
Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 share a fixed small pool of hardcoded keys, allowing a remote attacker to use a different Dino device to decrypt VoIP traffic between a child's Dino and remote server.
network
high complexity
cognitoys CWE-327
5.9
2017-12-11 CVE-2017-8865 Information Exposure vulnerability in Cognitoys Stemosaur Firmware 0.0.794
Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 do not provide sufficient protections against capture-replay attacks, allowing an attacker on the network to replay VoIP traffic between a Dino device and remote server to any other Dino device.
network
high complexity
cognitoys CWE-200
5.9
2017-12-11 CVE-2017-1683 Cross-site Scripting vulnerability in IBM Connections Engagement Center 6.0
IBM Connections Engagement Center 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4