Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-03-29 CVE-2017-6864 Cross-site Scripting vulnerability in Siemens Ruggedcom ROX I 2.9.0
The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow an authenticated user to perform stored Cross-Site Scripting attacks.
network
low complexity
siemens CWE-79
5.4
2017-03-29 CVE-2017-2687 Cross-site Scripting vulnerability in Siemens Ruggedcom ROX I 2.9.0
Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability in the integrated web server at port 10000/TCP which is prone to reflected Cross-Site Scripting attacks if an unsuspecting user is induced to click on a malicious link.
network
low complexity
siemens CWE-79
6.1
2017-03-29 CVE-2017-2686 Information Exposure vulnerability in Siemens Ruggedcom ROX I 2.9.0
Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary files through the web interface at port 10000/TCP and access sensitive information.
network
low complexity
siemens CWE-200
6.5
2017-03-28 CVE-2016-8884 NULL Pointer Dereference vulnerability in multiple products
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image.
local
low complexity
jasper-project fedoraproject CWE-476
5.5
2017-03-28 CVE-2017-0882 Information Exposure vulnerability in Gitlab
Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request.
network
low complexity
gitlab CWE-200
6.3
2017-03-28 CVE-2017-0881 Incorrect Authorization vulnerability in Zulip Server
An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an invitation from an existing member to join.
network
low complexity
zulip CWE-863
4.3
2017-03-28 CVE-2016-9473 Cross-site Scripting vulnerability in Brave Browser 1.2.16/1.9.56
Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trick a victim by displaying a malicious page for legitimate domain names.
network
low complexity
brave CWE-79
4.7
2017-03-28 CVE-2016-9472 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-28 CVE-2016-9468 Improper Access Control vulnerability in multiple products
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app.
network
low complexity
owncloud nextcloud CWE-284
5.3
2017-03-28 CVE-2016-9467 Improper Access Control vulnerability in multiple products
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app.
network
low complexity
owncloud nextcloud CWE-284
5.3