Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-12-29 CVE-2015-8745 Reachable Assertion vulnerability in multiple products
QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue.
local
low complexity
qemu debian CWE-617
5.5
2016-12-29 CVE-2015-8744 Improper Input Validation vulnerability in multiple products
QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue.
local
low complexity
qemu debian CWE-20
5.5
2016-12-29 CVE-2015-8701 Off-by-one Error vulnerability in Qemu
QEMU (aka Quick Emulator) built with the Rocker switch emulation support is vulnerable to an off-by-one error.
local
low complexity
qemu CWE-193
6.5
2016-12-29 CVE-2016-9891 Cross-site Scripting vulnerability in Dotclear
Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated users to inject arbitrary web script or HTML via the upfiletitle or media_title parameter (aka the media title).
network
low complexity
dotclear CWE-79
5.4
2016-12-29 CVE-2016-7463 Cross-site Scripting vulnerability in VMWare Esxi 5.5/6.0
Cross-site scripting (XSS) vulnerability in the Host Client in VMware vSphere Hypervisor (aka ESXi) 5.5 and 6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted VM.
network
low complexity
vmware CWE-79
5.4
2016-12-29 CVE-2016-7458 XXE vulnerability in VMWare Vsphere Client 5.5/6.0
VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
network
low complexity
vmware CWE-611
5.8
2016-12-29 CVE-2016-7087 Path Traversal vulnerability in VMWare Horizon View
Directory traversal vulnerability in the Connection Server in VMware Horizon View 5.x before 5.3.7, 6.x before 6.2.3, and 7.x before 7.0.1 allows remote attackers to obtain sensitive information via unspecified vectors.
network
low complexity
vmware CWE-22
5.3
2016-12-29 CVE-2016-5334 Exposure of Resource to Wrong Sphere vulnerability in VMWare Identity Manager and Vrealize Automation
VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.
network
low complexity
vmware CWE-668
5.3
2016-12-29 CVE-2016-5329 Information Exposure vulnerability in VMWare Fusion
VMware Fusion 8.x before 8.5 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecified vectors.
local
low complexity
vmware CWE-200
5.5
2016-12-29 CVE-2016-5328 7PK - Security Features vulnerability in VMWare Tools
VMware Tools 9.x and 10.x before 10.1.0 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecified vectors.
local
low complexity
vmware CWE-254
5.5