Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-02-17 CVE-2016-9827 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libming
The _iprintf function in outputtxt.c in the listswf tool in libming 0.4.7 allows remote attackers to cause a denial of service (buffer over-read) via a crafted SWF file.
local
low complexity
libming CWE-119
5.5
2017-02-17 CVE-2016-9773 Out-of-bounds Read vulnerability in Imagemagick 7.0.38
Heap-based buffer overflow in the IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.
local
low complexity
imagemagick CWE-125
5.5
2017-02-17 CVE-2016-9139 Cross-site Scripting vulnerability in Otrs
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.3.x before 3.3.16, 4.0.x before 4.0.19, and 5.0.x before 5.0.14 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment.
network
low complexity
otrs CWE-79
6.1
2017-02-17 CVE-2016-8652 Improper Input Validation vulnerability in Dovecot
The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setting a username.
network
high complexity
dovecot CWE-20
5.9
2017-02-17 CVE-2016-4327 Cross-site Scripting vulnerability in Wso2 Enablement Server for Java 6.6200908271616
Cross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server for Java/6.6 build SSJ-6.6-20090827-1616 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
network
low complexity
wso2 CWE-79
6.1
2017-02-17 CVE-2016-4316 Cross-site Scripting vulnerability in Wso2 Carbon 4.4.5
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) setName parameter to identity-mgt/challenges-mgt.jsp; the (2) webappType or (3) httpPort parameter to webapp-list/webapp_info.jsp; the (4) dsName or (5) description parameter to ndatasource/newdatasource.jsp; the (6) phase parameter to viewflows/handlers.jsp; or the (7) url parameter to ndatasource/validateconnection-ajaxprocessor.jsp.
network
low complexity
wso2 CWE-79
6.1
2017-02-17 CVE-2016-4315 Cross-Site Request Forgery (CSRF) vulnerability in Wso2 Carbon 4.4.5
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.
network
low complexity
wso2 CWE-352
5.7
2017-02-17 CVE-2016-4314 Path Traversal vulnerability in Wso2 Carbon 4.4.5
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a ..
network
low complexity
wso2 CWE-22
4.9
2017-02-17 CVE-2016-1249 Out-of-bounds Read vulnerability in Dbd-Mysql Project Dbd-Mysql
The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression.
network
high complexity
dbd-mysql-project CWE-125
5.9
2017-02-16 CVE-2016-6062 Cross-site Scripting vulnerability in IBM Resilient 26.0/26.1/26.2
IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1