Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-01-27 CVE-2016-3996 Information Exposure vulnerability in Samsung Knox 1.0/2.3.0
ClipboardDataMgr in Samsung KNOX 1.0.0 and 2.3.0 does not properly check the caller, which allows local users to read KNOX clipboard data via a crafted application.
local
low complexity
samsung CWE-200
5.5
2017-01-27 CVE-2016-1920 Improper Access Control vulnerability in Samsung Knox 1.0
Samsung KNOX 1.0.0 uses the shared certificate on Android, which allows local users to conduct man-in-the-middle attacks as demonstrated by installing a certificate and running a VPN service.
local
low complexity
samsung CWE-284
5.5
2017-01-27 CVE-2016-1919 Information Exposure vulnerability in Samsung Knox 1.0
Samsung KNOX 1.0 uses a weak eCryptFS Key generation algorithm, which makes it easier for local users to obtain sensitive information by leveraging knowledge of the TIMA key and a brute-force attack.
local
high complexity
samsung CWE-200
4.7
2017-01-27 CVE-2017-5599 Cross-site Scripting vulnerability in Eclinicalworks Patient Portal 7.0
An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13.
network
low complexity
eclinicalworks CWE-79
6.1
2017-01-26 CVE-2016-8226 Data Processing Errors vulnerability in Lenovo products
The BIOS in Lenovo System X M5, M6, and X6 systems allows administrators to cause a denial of service via updating a UEFI data structure.
network
low complexity
lenovo CWE-19
4.9
2017-01-26 CVE-2016-9317 Improper Input Validation vulnerability in Libgd
The gdImageCreate function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (system hang) via an oversized image.
local
low complexity
libgd CWE-20
5.5
2017-01-26 CVE-2016-6911 Out-of-bounds Read vulnerability in Libgd
The dynamicGetbuf function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TIFF image.
local
low complexity
libgd CWE-125
5.5
2017-01-26 CVE-2016-6908 Open Redirect vulnerability in Opera Browser 37.0.2192.105088
Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 37.0.2192.105088 for Android, due to mishandling of several unicode characters such as U+FE70, U+0622, U+0623 etc and how they are rendered combined with (first strong character) such as an IP address or alphabet could lead to a spoofed URL.
network
low complexity
opera CWE-601
6.1
2017-01-26 CVE-2016-10025 NULL Pointer Dereference vulnerability in multiple products
VMFUNC emulation in Xen 4.6.x through 4.8.x on x86 systems using AMD virtualization extensions (aka SVM) allows local HVM guest OS users to cause a denial of service (hypervisor crash) by leveraging a missing NULL pointer check.
local
low complexity
xen citrix CWE-476
5.5
2017-01-26 CVE-2016-10024 Improper Input Validation vulnerability in multiple products
Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction stream asynchronously while performing certain kernel operations.
local
low complexity
xen citrix CWE-20
6.0