Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-03-05 CVE-2017-6483 Cross-site Scripting vulnerability in Atutor
Multiple Cross-Site Scripting (XSS) issues were discovered in ATutor 2.2.2.
network
low complexity
atutor CWE-79
6.1
2017-03-05 CVE-2017-6481 Cross-site Scripting vulnerability in PHPipam
Multiple Cross-Site Scripting (XSS) issues were discovered in phpipam 1.2.
network
low complexity
phpipam CWE-79
6.1
2017-03-05 CVE-2017-6480 Cross-site Scripting vulnerability in Groovel Project Cmsgroovel 3.3.6
groovel/cmsgroovel before 3.3.7-beta is vulnerable to a reflected XSS in commons/browser.php (path parameter).
network
low complexity
groovel-project CWE-79
6.1
2017-03-05 CVE-2017-6479 Cross-site Scripting vulnerability in Fenix Hosting Fenix-Open-Source 20170221
FenixHosting/fenix-open-source before 2017-03-04 is vulnerable to a reflected XSS in forums/search.php (search-by-topic parameter).
network
low complexity
fenix-hosting CWE-79
6.1
2017-03-05 CVE-2017-6478 Cross-site Scripting vulnerability in Mangoswebv4 Project Mangoswebv4
paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).
network
low complexity
mangoswebv4-project CWE-79
6.1
2017-03-03 CVE-2016-10070 Out-of-bounds Read vulnerability in multiple products
Heap-based buffer overflow in the CalcMinMax function in coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted mat file.
local
low complexity
imagemagick opensuse CWE-125
5.5
2017-03-03 CVE-2016-10066 Classic Buffer Overflow vulnerability in Imagemagick
Buffer overflow in the ReadVIFFImage function in coders/viff.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a crafted file.
local
low complexity
imagemagick CWE-120
5.5
2017-03-03 CVE-2016-10061 Unchecked Return Value vulnerability in Imagemagick
The ReadGROUP4Image function in coders/tiff.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (crash) via a crafted image file.
network
low complexity
imagemagick CWE-252
6.5
2017-03-03 CVE-2016-7409 Information Exposure vulnerability in Dropbear SSH Project Dropbear SSH
The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument, related to a failed remote ident.
local
low complexity
dropbear-ssh-project CWE-200
5.5
2017-03-03 CVE-2016-6884 Out-of-bounds Read vulnerability in Matrixssl 3.8.2
TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bounds read) via a crafted message.
network
low complexity
matrixssl CWE-125
6.5