Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-03-17 CVE-2017-3866 Cross-site Scripting vulnerability in Cisco Prime Service Catalog 11.1.2/11.1Base
A vulnerability in the web framework code of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system.
network
low complexity
cisco CWE-79
6.1
2017-03-17 CVE-2017-3815 Cleartext Transmission of Sensitive Information vulnerability in Cisco Telepresence Server Software 4.2(4.17)/4.2(4.18)/4.2(4.19)
An API Privilege vulnerability in Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to emulate Cisco TelePresence Server endpoints.
network
low complexity
cisco CWE-319
5.3
2017-03-17 CVE-2017-3811 XXE vulnerability in Cisco Webex Meetings Server 2.6
An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the information stored in the affected system.
network
low complexity
cisco CWE-611
6.5
2017-03-17 CVE-2017-6370 Cleartext Transmission of Sensitive Information vulnerability in Typo3 7.6.15
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.
network
low complexity
typo3 CWE-319
5.3
2017-03-17 CVE-2015-7313 Resource Management Errors vulnerability in Libtiff
LibTIFF allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted tiff file.
local
low complexity
libtiff CWE-399
5.5
2017-03-17 CVE-2015-4645 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input, which triggers a stack-based buffer overflow.
local
low complexity
squashfs-project fedoraproject CWE-190
5.5
2017-03-17 CVE-2015-3883 Cross-site Scripting vulnerability in Qdpm 8.3
Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) search[keywords] parameter to index.php/users page; the (2) "Name of application" on index.php/configuration; (3) a new project name on index.php/projects; (4) the task name on index.php/tasks; (5) ticket name on index.php/tickets; (6) discussion name on index.php/discussions; (7) report name on index.php/projectReports; or (8) event name on index.php/scheduler/personal.
network
low complexity
qdpm CWE-79
6.1
2017-03-17 CVE-2015-3882 Information Exposure vulnerability in Qdpm 8.3
qdPM 8.3 allows remote attackers to obtain sensitive information via invalid ID value to index.php/users/info/id/[ID], which reveals the installation path in an error message.
network
low complexity
qdpm CWE-200
5.3
2017-03-17 CVE-2014-9853 Resource Management Errors vulnerability in multiple products
Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.
5.5
2017-03-17 CVE-2014-8723 Information Exposure vulnerability in Get-Simple Getsimple CMS 3.3.4
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plugins/InnovationPlugin.php, which reveals the installation path in an error message.
network
low complexity
get-simple CWE-200
5.3