Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-01-12 CVE-2016-5737 Cross-site Scripting vulnerability in Openstack Puppet-Gerrit
The Gerrit configuration in the Openstack Puppet module for Gerrit (aka puppet-gerrit) improperly marks text/html as a safe mimetype, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via a crafted review.
network
low complexity
openstack CWE-79
6.1
2017-01-12 CVE-2016-5715 Open Redirect vulnerability in Puppet Enterprise
Open redirect vulnerability in the Console in Puppet Enterprise 2015.x and 2016.x before 2016.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the redirect parameter.
network
low complexity
puppet CWE-601
6.1
2017-01-12 CVE-2016-3150 Cross-site Scripting vulnerability in Barco products
Cross-site scripting (XSS) vulnerability in wallpaper.php in the Base Unit in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with firmware before 01.03.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
barco CWE-79
6.1
2017-01-12 CVE-2016-10027 Race Condition vulnerability in multiple products
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.
network
high complexity
igniterealtime fedoraproject CWE-362
5.9
2017-01-12 CVE-2015-6501 Open Redirect vulnerability in Puppet Enterprise
Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the string parameter.
network
low complexity
puppet CWE-601
6.1
2017-01-12 CVE-2016-8605 Permission Issues vulnerability in multiple products
The mkdir procedure of GNU Guile temporarily changed the process' umask to zero.
network
low complexity
fedoraproject gnu CWE-275
5.3
2017-01-12 CVE-2017-0402 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2017-01-12 CVE-2017-0401 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2017-01-12 CVE-2017-0400 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5
2017-01-12 CVE-2017-0399 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a local malicious application to access data outside of its permission levels.
local
low complexity
google CWE-200
5.5