Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-02-24 CVE-2017-6099 Cross-site Scripting vulnerability in Paypal Merchant-Sdk-PHP 3.9.1
Cross-site scripting (XSS) vulnerability in GetAuthDetails.html.php in PayPal PHP Merchant SDK (aka merchant-sdk-php) 3.9.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter.
network
low complexity
paypal CWE-79
6.1
2017-02-24 CVE-2017-6076 Information Exposure vulnerability in Wolfssl
In versions of wolfSSL before 3.10.2 the function fp_mul_comba makes it easier to extract RSA key information for a malicious user who has access to view cache on a machine.
local
low complexity
wolfssl CWE-200
5.5
2017-02-24 CVE-2014-9916 Cross-site Scripting vulnerability in Bilboplanet 2.0
Multiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) tribe_name or (2) tags parameter in a tribes page request to user/ or the (3) user_id or (4) fullname parameter to signup.php.
network
low complexity
bilboplanet CWE-79
6.1
2017-02-23 CVE-2016-6055 Cross-site Scripting vulnerability in IBM products
IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-02-23 CVE-2016-5883 Cross-site Scripting vulnerability in IBM Inotes
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2017-02-22 CVE-2017-6188 Improper Input Validation vulnerability in multiple products
Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled.
local
low complexity
munin-monitoring debian CWE-20
5.5
2017-02-22 CVE-2016-8986 Improper Access Control vulnerability in IBM Websphere MQ
IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using specially crafted HTTP requests.
network
low complexity
ibm CWE-284
6.5
2017-02-22 CVE-2016-8915 Improper Access Control vulnerability in IBM Websphere MQ
IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to other channels running under the same process.
network
low complexity
ibm CWE-284
6.5
2017-02-22 CVE-2016-3052 Information Exposure vulnerability in IBM Websphere MQ
Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network.
network
high complexity
ibm CWE-200
5.9
2017-02-22 CVE-2016-3013 Data Processing Errors vulnerability in IBM Websphere MQ
IBM WebSphere MQ 8.0 could allow an authenticated user to crash the MQ channel due to improper data conversion handling.
network
low complexity
ibm CWE-19
6.5