Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-06-07 CVE-2017-9500 Reachable Assertion vulnerability in Imagemagick 7.0.58
In ImageMagick 7.0.5-8 Q16, an assertion failure was found in the function ResetImageProfileIterator, which allows attackers to cause a denial of service via a crafted file.
network
low complexity
imagemagick CWE-617
6.5
2017-06-07 CVE-2017-9499 Reachable Assertion vulnerability in Imagemagick 7.0.57
In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function SetPixelChannelAttributes, which allows attackers to cause a denial of service via a crafted file.
network
low complexity
imagemagick CWE-617
6.5
2017-06-07 CVE-2015-8326 Link Following vulnerability in Iptables-Parse Project Iptables-Parse Module
The IPTables-Parse module before 1.6 for Perl allows local users to write to arbitrary files owned by the current user.
local
low complexity
iptables-parse-project CWE-59
5.5
2017-06-07 CVE-2015-7514 Information Exposure vulnerability in Openstack Ironic 4.2.0/4.2.1
OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.
network
low complexity
openstack CWE-200
6.5
2017-06-07 CVE-2016-9834 Cross-site Scripting vulnerability in Sophos Cyberoam Firmware 10.6.4
An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices with firmware through 10.6.4.
network
low complexity
sophos CWE-79
6.1
2017-06-07 CVE-2017-9474 Out-of-bounds Read vulnerability in Ytnef Project Ytnef 1.9.2
In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
local
low complexity
ytnef-project CWE-125
5.5
2017-06-07 CVE-2017-9473 In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
local
low complexity
ytnef-project canonical
5.5
2017-06-07 CVE-2017-9472 Out-of-bounds Read vulnerability in Ytnef Project Ytnef 1.9.2
In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
local
low complexity
ytnef-project CWE-125
5.5
2017-06-07 CVE-2017-9471 Out-of-bounds Read vulnerability in multiple products
In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
local
low complexity
ytnef-project canonical CWE-125
5.5
2017-06-07 CVE-2017-9470 NULL Pointer Dereference vulnerability in Ytnef Project Ytnef 1.9.2
In ytnef 1.9.2, the MAPIPrint function in lib/ytnef.c allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
local
low complexity
ytnef-project CWE-476
5.5