Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-06-25 CVE-2017-9865 Out-of-bounds Read vulnerability in multiple products
The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in ImageOutputDev.cc.
local
low complexity
freedesktop debian CWE-125
5.5
2017-06-24 CVE-2017-9847 Out-of-bounds Read vulnerability in Libtorrent 1.1.3
The bdecode function in bdecode.cpp in libtorrent 1.1.3 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
local
low complexity
libtorrent CWE-125
5.5
2017-06-24 CVE-2017-9836 Cross-site Scripting vulnerability in Piwigo 2.9.1
Cross-site scripting (XSS) vulnerability in Piwigo 2.9.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the virtual_name parameter to /admin.php (i.e., creating a virtual album).
network
low complexity
piwigo CWE-79
4.8
2017-06-24 CVE-2017-9832 Integer Overflow or Wraparound vulnerability in Libmtp Project Libmtp
An integer overflow vulnerability in ptp-pack.c (ptp_unpack_OPL function) of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable.
low complexity
libmtp-project CWE-190
6.8
2017-06-24 CVE-2017-9831 Integer Overflow or Wraparound vulnerability in Libmtp Project Libmtp 1.1.12
An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a personal computer through a USB cable.
low complexity
libmtp-project CWE-190
6.8
2017-06-23 CVE-2017-1349 Information Exposure vulnerability in IBM Sterling B2B Integrator 5.2
IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could be read by a local user.
local
low complexity
ibm CWE-200
5.5
2017-06-23 CVE-2017-1348 Cross-site Scripting vulnerability in IBM Sterling B2B Integrator 5.2
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-06-23 CVE-2017-1302 Information Exposure vulnerability in IBM Sterling B2B Integrator 5.2
IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information due to improper access controls.
local
low complexity
ibm CWE-200
5.5
2017-06-23 CVE-2017-1193 Information Exposure vulnerability in IBM Sterling B2B Integrator 5.2
IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET request.
network
low complexity
ibm CWE-200
6.5
2017-06-23 CVE-2017-1132 Cross-site Scripting vulnerability in IBM Sterling B2B Integrator 5.2
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4