Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-03-03 CVE-2017-5832 Cross-site Scripting vulnerability in Revive-Adserver Revive Adserver
Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user's email address.
network
low complexity
revive-adserver CWE-79
5.4
2017-03-03 CVE-2017-5831 Session Fixation vulnerability in Revive-Adserver Revive Adserver
Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.
network
high complexity
revive-adserver CWE-384
5.9
2017-03-03 CVE-2017-5616 Cross-site Scripting vulnerability in Cpanel Cgiecho and Cgiemail
Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter.
network
low complexity
cpanel CWE-79
6.1
2017-03-03 CVE-2017-5615 Open Redirect vulnerability in Cpanel Cgiecho and Cgiemail
cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.
network
low complexity
cpanel CWE-601
6.1
2017-03-03 CVE-2017-5614 Open Redirect vulnerability in Cpanel
Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the (1) success or (2) failure parameter.
network
low complexity
cpanel CWE-601
6.1
2017-03-03 CVE-2017-5571 Open Redirect vulnerability in Flexerasoftware Flexnet Publisher 11.10/11.13.1.0/11.14.1
Open redirect vulnerability in the lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) 11.14.1 and earlier, as used in Citrix License Server for Windows and the Citrix License Server VPX, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
low complexity
flexerasoftware CWE-601
6.1
2017-03-03 CVE-2016-10203 Cross-site Scripting vulnerability in Zoneminder
Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the name when creating a new monitor.
network
low complexity
zoneminder CWE-79
6.1
2017-03-03 CVE-2016-10202 Cross-site Scripting vulnerability in Zoneminder
Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the path info to index.php.
network
low complexity
zoneminder CWE-79
6.1
2017-03-03 CVE-2016-10201 Cross-site Scripting vulnerability in Zoneminder
Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the format parameter in a download log request to index.php.
network
low complexity
zoneminder CWE-79
6.1
2017-03-02 CVE-2016-9892 Improper Certificate Validation vulnerability in Eset Endpoint Antivirus and Endpoint Security
The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not properly verify X.509 certificates from the edf.eset.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide crafted responses to license activation requests via a self-signed certificate.
network
high complexity
eset CWE-295
5.9