Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-03-07 CVE-2017-6509 Cross-site Scripting vulnerability in Burgundy-Cms Project Burgundy-Cms 20170220
Smith0r/burgundy-cms before 2017-03-06 is vulnerable to a reflected XSS in admin/components/menu/views/menuitems.php (id parameter).
network
low complexity
burgundy-cms-project CWE-79
6.1
2017-03-07 CVE-2016-7140 Cross-site Scripting vulnerability in Plone
Multiple cross-site scripting (XSS) vulnerabilities in the ZMI page in Zope2 in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
plone CWE-79
6.1
2017-03-07 CVE-2016-7139 Cross-site Scripting vulnerability in Plone
Cross-site scripting (XSS) vulnerability in an unspecified page template in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
low complexity
plone CWE-79
6.1
2017-03-07 CVE-2016-7138 Cross-site Scripting vulnerability in Plone
Cross-site scripting (XSS) vulnerability in the URL checking infrastructure in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
network
low complexity
plone CWE-79
6.1
2017-03-07 CVE-2016-7137 Open Redirect vulnerability in Plone
Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter to (1) %2b%2bgroupdashboard%2b%2bplone.dashboard1%2bgroup/%2b/portlets.Actions or (2) folder/%2b%2bcontextportlets%2b%2bplone.footerportlets/%2b /portlets.Actions or the (3) came_from parameter to /login_form.
network
low complexity
plone CWE-601
6.1
2017-03-07 CVE-2016-7136 Cross-site Scripting vulnerability in Plone
z3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.11 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted GET request.
network
low complexity
plone CWE-79
6.1
2017-03-07 CVE-2016-7135 Path Traversal vulnerability in Plone
Directory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x through 4.3.11 allows remote administrators to read arbitrary files via a ..
network
low complexity
plone CWE-22
4.9
2017-03-07 CVE-2016-6522 Integer Overflow or Wraparound vulnerability in Openbsd 5.9
Integer overflow in the uvm_map_isavail function in uvm/uvm_map.c in OpenBSD 5.9 allows local users to cause a denial of service (kernel panic) via a crafted mmap call, which triggers the new mapping to overlap with an existing mapping.
local
low complexity
openbsd CWE-190
5.5
2017-03-07 CVE-2016-6350 NULL Pointer Dereference vulnerability in Openbsd 5.8/5.9
OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (NULL pointer dereference and panic) via a sysctl call with a path starting with 10,9.
local
low complexity
openbsd CWE-476
5.5
2017-03-07 CVE-2016-6247 Improper Input Validation vulnerability in Openbsd 5.8/5.9
OpenBSD 5.8 and 5.9 allows certain local users to cause a denial of service (kernel panic) by unmounting a filesystem with an open vnode on the mnt_vnodelist.
local
low complexity
openbsd CWE-20
5.5