Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-12-03 CVE-2016-9803 Out-of-bounds Read vulnerability in Bluez 5.42
In BlueZ 5.42, an out-of-bounds read was observed in "le_meta_ev_dump" function in "tools/parser/hci.c" source file.
network
low complexity
bluez CWE-125
5.3
2016-12-03 CVE-2016-9802 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Bluez 5.42
In BlueZ 5.42, a buffer over-read was identified in "l2cap_packet" function in "monitor/packet.c" source file.
network
low complexity
bluez CWE-119
5.3
2016-12-03 CVE-2016-9801 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Bluez 5.42
In BlueZ 5.42, a buffer overflow was observed in "set_ext_ctrl" function in "tools/parser/l2cap.c" source file when processing corrupted dump file.
network
low complexity
bluez CWE-119
5.3
2016-12-03 CVE-2016-9800 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Bluez 5.42
In BlueZ 5.42, a buffer overflow was observed in "pin_code_reply_dump" function in "tools/parser/hci.c" source file.
network
low complexity
bluez CWE-119
5.3
2016-12-03 CVE-2016-9799 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Bluez 5.42
In BlueZ 5.42, a buffer overflow was observed in "pklg_read_hci" function in "btsnoop.c" source file.
network
low complexity
bluez CWE-119
5.3
2016-12-03 CVE-2016-9798 Use After Free vulnerability in Bluez 5.42
In BlueZ 5.42, a use-after-free was identified in "conf_opt" function in "tools/parser/l2cap.c" source file.
network
low complexity
bluez CWE-416
5.3
2016-12-03 CVE-2016-9797 Out-of-bounds Read vulnerability in Bluez 5.42
In BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" function in "tools/parser/l2cap.c" source file.
network
low complexity
bluez CWE-125
5.3
2016-12-01 CVE-2016-9751 Cross-site Scripting vulnerability in Piwigo 2.8.3
Cross-site scripting (XSS) vulnerability in the search results front end in Piwigo 2.8.3 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
network
low complexity
piwigo CWE-79
6.1
2016-12-01 CVE-2016-3047 Open Redirect vulnerability in IBM Filenet Workplace 4.0.2
Open redirect vulnerability in IBM FileNet Workplace 4.0.2 through 4.0.2.14 IF001 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
low complexity
ibm CWE-601
6.8
2016-12-01 CVE-2016-3044 Improper Access Control vulnerability in IBM Powerkvm
The Linux kernel component in IBM PowerKVM 2.1 before 2.1.1.3-65.10 and 3.1 before 3.1.0.2 allows guest OS users to cause a denial of service (host OS infinite loop and hang) via unspecified vectors.
local
low complexity
ibm CWE-284
6.5