Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-03-21 CVE-2017-7207 NULL Pointer Dereference vulnerability in Artifex Ghostscript 9.20
The mem_get_bits_rectangle function in Artifex Software, Inc.
local
low complexity
artifex CWE-476
5.5
2017-03-21 CVE-2017-7205 Cross-site Scripting vulnerability in Gamepanelx Gamepanelx-V3 3.0.12
A Cross-Site Scripting (XSS) was discovered in GamePanelX-V3 3.0.12.
network
low complexity
gamepanelx CWE-79
6.1
2017-03-21 CVE-2017-7204 Cross-site Scripting vulnerability in Imdbphp Project Imdbphp 5.1.1
A Cross-Site Scripting (XSS) was discovered in imdbphp 5.1.1.
network
low complexity
imdbphp-project CWE-79
6.1
2017-03-21 CVE-2017-7203 Cross-site Scripting vulnerability in Zoneminder 1.30.2
A Cross-Site Scripting (XSS) was discovered in ZoneMinder before 1.30.2.
network
low complexity
zoneminder CWE-79
6.1
2017-03-21 CVE-2017-7202 Cross-site Scripting vulnerability in Slims Slims7 Cendana 62B8Ee8B51Be89Fc65E0D59B01C3724737F9Da20
Multiple Cross-Site Scripting (XSS) were discovered in SLiMS 7 Cendana before 2017-03-16.
network
low complexity
slims CWE-79
6.1
2017-03-21 CVE-2017-7200 Server-Side Request Forgery (SSRF) vulnerability in Openstack Glance
An SSRF issue was discovered in OpenStack Glance before Newton.
network
low complexity
openstack CWE-918
5.8
2017-03-20 CVE-2016-4931 XXE vulnerability in Juniper Junos Space
XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service.
network
low complexity
juniper CWE-611
6.5
2017-03-20 CVE-2016-4930 Cross-site Scripting vulnerability in Juniper Junos Space
Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2 allows remote attackers to steal sensitive information or perform certain administrative actions.
network
low complexity
juniper CWE-79
6.1
2017-03-20 CVE-2017-6839 Integer Overflow or Wraparound vulnerability in Audiofile 0.3.6
Integer overflow in modules/MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.
local
low complexity
audiofile CWE-190
5.5
2017-03-20 CVE-2017-6838 Integer Overflow or Wraparound vulnerability in Audiofile 0.3.6
Integer overflow in sfcommands/sfconvert.c in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.
local
low complexity
audiofile CWE-190
5.5