Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-11-01 CVE-2017-16353 Out-of-bounds Read vulnerability in multiple products
GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file, because of a heap-based buffer over-read.
network
low complexity
graphicsmagick debian CWE-125
6.5
2017-11-01 CVE-2017-12625 Information Exposure vulnerability in Apache Hive
Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views, e.g., using Apache Ranger.
network
low complexity
apache CWE-200
4.3
2017-11-01 CVE-2017-1000243 Missing Authorization vulnerability in Jenkins Favorite Plugin
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
network
low complexity
jenkins CWE-862
4.3
2017-10-31 CVE-2017-1000383 Information Exposure vulnerability in GNU Emacs
GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary.
local
low complexity
gnu CWE-200
5.5
2017-10-31 CVE-2017-1000382 Information Exposure vulnerability in VIM
VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the vi binary.
local
low complexity
vim CWE-200
5.5
2017-10-31 CVE-2017-10944 Information Exposure vulnerability in Foxitsoftware Foxit Reader 8.3.0.14878
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878.
network
low complexity
foxitsoftware CWE-200
6.5
2017-10-31 CVE-2017-10943 Information Exposure vulnerability in Foxitsoftware Foxit Reader 8.3.0.14878
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878.
network
low complexity
foxitsoftware CWE-200
6.5
2017-10-31 CVE-2017-10942 Information Exposure vulnerability in Foxitsoftware Foxit Reader 8.3.0.14878
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878.
network
low complexity
foxitsoftware CWE-200
6.5
2017-10-31 CVE-2017-15273 Cross-site Scripting vulnerability in Mahara
Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as titles in internal artefacts.
network
low complexity
mahara CWE-79
5.4
2017-10-31 CVE-2017-14752 Cross-site Scripting vulnerability in Mahara
Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as their first name, last name, or display name in the profile fields that can cause issues such as escalation of privileges or unknown execution of malicious code when replying to messages in Mahara.
network
low complexity
mahara CWE-79
5.4