Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-10-24 CVE-2017-15867 Cross-site Scripting vulnerability in User-Login-History Project User-Login-History
Multiple cross-site scripting (XSS) vulnerabilities in the user-login-history plugin through 1.5.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) date_from, (2) date_to, (3) user_id, (4) username, (5) country_name, (6) browser, (7) operating_system, or (8) ip_address parameter to admin/partials/listing/listing.php.
network
low complexity
user-login-history-project CWE-79
6.1
2017-10-24 CVE-2017-15863 Cross-site Scripting vulnerability in WP NO External Links Project WP NO External Links
Cross Site Scripting (XSS) exists in the wp-noexternallinks plugin before 3.5.19 for WordPress via the date1 or date2 parameter to wp-admin/options-general.php.
network
low complexity
wp-no-external-links-project CWE-79
6.1
2017-10-24 CVE-2017-15223 Infinite Loop vulnerability in Argosoft Mini Mail Server 1.0.0.2
Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) via unspecified vectors, possibly triggering an infinite loop.
network
low complexity
argosoft CWE-835
5.3
2017-10-24 CVE-2017-15186 Double Free vulnerability in Ffmpeg
Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.
network
low complexity
ffmpeg CWE-415
6.5
2017-10-24 CVE-2013-3734 Credentials Management vulnerability in Redhat Jboss Application Server 1.2
The Embedded Jopr component in JBoss Application Server includes the cleartext datasource password in unspecified HTML responses, which might allow (1) man-in-the-middle attackers to obtain sensitive information by leveraging failure to use SSL or (2) attackers to obtain sensitive information by reading the HTML source code.
network
high complexity
redhat CWE-255
6.6
2017-10-24 CVE-2017-12618 Out-of-bounds Read vulnerability in Apache Portable Runtime Utility
Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access.
local
high complexity
apache CWE-125
4.7
2017-10-23 CVE-2017-13683 Missing Release of Resource after Effective Lifetime vulnerability in Symantec Endpoint Encryption
In Symantec Endpoint Encryption before SEE 11.1.3HF3, a kernel memory leak is a type of resource leak that can occur when a computer program incorrectly manages memory allocations in such a way that memory which is no longer needed is not released.
low complexity
symantec CWE-772
5.7
2017-10-23 CVE-2017-13682 Missing Release of Resource after Effective Lifetime vulnerability in Symantec Encryption Desktop
In Symantec Encryption Desktop before SED 10.4.1 MP2HF1, a kernel memory leak is a type of resource leak that can occur when a computer program incorrectly manages memory allocations in such a way that memory which is no longer needed is not released.
low complexity
symantec CWE-772
5.7
2017-10-23 CVE-2015-6839 Improper Input Validation vulnerability in Grupo MSA Vot.Ar 3.1
The parse function in MSA vot.Ar 3.1 does not check whether a candidate receives more than one vote, which allows physically proximate attackers to cast multiple votes for a candidate via a crafted RFID ballot tag.
low complexity
grupo-msa CWE-20
4.6
2017-10-23 CVE-2015-5532 Cross-site Scripting vulnerability in Strangerstudios Paid Memberships PRO
Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to membershiplevels.php, (2) memberslist.php, or (3) orders.php in adminpages/ or the (4) edit parameter to adminpages/membershiplevels.php.
network
low complexity
strangerstudios CWE-79
6.1