Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-11-10 CVE-2017-11461 Improper Input Validation vulnerability in Netapp Oncommand Unified Manager 5.1
NetApp OnCommand Unified Manager for 7-mode (core package) versions prior to 5.2.1 are susceptible to a clickjacking or "UI redress attack" which could be used to cause a user to perform an unintended action in the user interface.
network
low complexity
netapp CWE-20
4.3
2017-11-09 CVE-2017-16759 Path Traversal vulnerability in Librenms
The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php.
network
high complexity
librenms CWE-22
5.9
2017-11-09 CVE-2017-16758 Cross-site Scripting vulnerability in Ultimate Instagram Feed Project Ultimate Instagram Feed
Cross-site scripting (XSS) vulnerability in admin/partials/uif-access-token-display.php in the Ultimate Instagram Feed plugin before 1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "access_token" parameter.
network
low complexity
ultimate-instagram-feed-project CWE-79
4.8
2017-11-09 CVE-2017-16711 NULL Pointer Dereference vulnerability in Swftools 0.9.2
The swf_DefineLosslessBitsTagToImage function in lib/modules/swfbits.c in SWFTools 0.9.2 mishandles an uncompress failure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) because of extractDefinitions in lib/readers/swf.c and fill_line_bitmap in lib/devices/render.c, as demonstrated by swfrender.
local
low complexity
swftools CWE-476
5.5
2017-11-09 CVE-2017-16673 Information Exposure vulnerability in Datto Backup Agent 1.0.6.0
Datto Backup Agent 1.0.6.0 and earlier does not authenticate incoming connections.
high complexity
datto CWE-200
5.3
2017-11-09 CVE-2017-16672 Missing Release of Resource after Effective Lifetime vulnerability in Digium Asterisk
An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7.
network
high complexity
digium CWE-772
5.9
2017-11-08 CVE-2017-15085 Unspecified vulnerability in Redhat Gluster Storage 3.3
It was discovered that the fix for CVE-2017-12150 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
network
high complexity
redhat
5.9
2017-11-08 CVE-2017-16665 Cross-site Scripting vulnerability in Remobjects Remoting SDK 9 1.0.0.0.
RemObjects Remoting SDK 9 1.0.0.0 for Delphi is vulnerable to a reflected Cross Site Scripting (XSS) attack via the service parameter to the /soap URI, triggering an invalid attempt to generate WSDL.
network
low complexity
remobjects CWE-79
6.1
2017-11-08 CVE-2017-16663 Integer Overflow or Wraparound vulnerability in Sam2P Project Sam2P 0.49.4
In sam2p 0.49.4, there are integer overflows (with resultant heap-based buffer overflows) in input-bmp.ci in the function ReadImage, because "width * height" multiplications occur unsafely.
local
low complexity
sam2p-project CWE-190
5.5
2017-11-08 CVE-2017-16661 Information Exposure vulnerability in Cacti 1.1.27
Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private directory, and then making a clog.php?filename= request, as demonstrated by filename=passwd (with a Log Path under /etc) to read /etc/passwd.
network
low complexity
cacti CWE-200
4.9