Vulnerabilities > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-02-17 | CVE-2016-9827 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libming The _iprintf function in outputtxt.c in the listswf tool in libming 0.4.7 allows remote attackers to cause a denial of service (buffer over-read) via a crafted SWF file. | 5.5 |
2017-02-17 | CVE-2016-9773 | Out-of-bounds Read vulnerability in Imagemagick 7.0.38 Heap-based buffer overflow in the IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file. | 5.5 |
2017-02-17 | CVE-2016-9139 | Cross-site Scripting vulnerability in Otrs Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.3.x before 3.3.16, 4.0.x before 4.0.19, and 5.0.x before 5.0.14 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment. | 6.1 |
2017-02-17 | CVE-2016-8652 | Improper Input Validation vulnerability in Dovecot The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setting a username. | 5.9 |
2017-02-17 | CVE-2016-4327 | Cross-site Scripting vulnerability in Wso2 Enablement Server for Java 6.6200908271616 Cross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server for Java/6.6 build SSJ-6.6-20090827-1616 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | 6.1 |
2017-02-17 | CVE-2016-4316 | Cross-site Scripting vulnerability in Wso2 Carbon 4.4.5 Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) setName parameter to identity-mgt/challenges-mgt.jsp; the (2) webappType or (3) httpPort parameter to webapp-list/webapp_info.jsp; the (4) dsName or (5) description parameter to ndatasource/newdatasource.jsp; the (6) phase parameter to viewflows/handlers.jsp; or the (7) url parameter to ndatasource/validateconnection-ajaxprocessor.jsp. | 6.1 |
2017-02-17 | CVE-2016-4315 | Cross-Site Request Forgery (CSRF) vulnerability in Wso2 Carbon 4.4.5 Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp. | 5.7 |
2017-02-17 | CVE-2016-4314 | Path Traversal vulnerability in Wso2 Carbon 4.4.5 Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. | 4.9 |
2017-02-17 | CVE-2016-1249 | Out-of-bounds Read vulnerability in Dbd-Mysql Project Dbd-Mysql The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression. | 5.9 |
2017-02-16 | CVE-2016-6062 | Cross-site Scripting vulnerability in IBM Resilient 26.0/26.1/26.2 IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting. | 6.1 |