Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-12-17 CVE-2016-9951 Improper Access Control vulnerability in Apport Project Apport
An issue was discovered in Apport before 2.20.4.
network
low complexity
apport-project CWE-284
6.5
2016-12-17 CVE-2016-9159 Information Exposure vulnerability in Siemens products
A vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl.
network
high complexity
siemens CWE-200
5.9
2016-12-16 CVE-2016-8827 Path Traversal vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience 3.x before GFE 3.1.0.52 contains a vulnerability in NVIDIA Web Helper.exe where a local web API endpoint, /VisualOPS/v.1.0./, lacks proper access control and parameter validation, allowing for information disclosure via a directory traversal attack.
network
low complexity
nvidia CWE-22
6.5
2016-12-16 CVE-2016-8826 Resource Management Errors vulnerability in Nvidia GPU Driver
All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys for Windows or nvidia.ko for Linux) where a user can cause a GPU interrupt storm, leading to a denial of service.
local
low complexity
nvidia CWE-399
5.5
2016-12-16 CVE-2016-8820 Improper Input Validation vulnerability in Nvidia GPU Driver
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a check on a function return value is missing, potentially allowing an uninitialized value to be used as the source of a strcpy() call, leading to denial of service or information disclosure.
local
low complexity
nvidia CWE-20
6.1
2016-12-16 CVE-2016-9964 CRLF Injection vulnerability in multiple products
redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233\r\nSet-Cookie: name=salt") call.
network
low complexity
bottlepy debian CWE-93
6.5
2016-12-16 CVE-2016-3129 Unspecified vulnerability in Blackberry Good Enterprise Mobility Server 2.2.22.25
A remote shell execution vulnerability in the BlackBerry Good Enterprise Mobility Server (GEMS) implementation of the Apache Karaf command shell in GEMS versions 2.1.5.3 to 2.2.22.25 allows remote attackers to obtain local administrator rights on the GEMS server via commands executed on the Karaf command shell.
network
high complexity
blackberry
6.6
2016-12-15 CVE-2015-3271 Information Exposure vulnerability in Apache Tika 1.9
Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.
network
low complexity
apache CWE-200
5.3
2016-12-15 CVE-2016-7891 Cross-site Scripting vulnerability in Adobe Robohelp
Adobe RoboHelp version 2015.0.3 and earlier, RoboHelp 11 and earlier have an input validation issue that could be used in cross-site scripting attacks.
network
low complexity
adobe CWE-79
6.1
2016-12-15 CVE-2016-7888 Information Exposure vulnerability in Adobe Digital Editions
Adobe Digital Editions versions 4.5.2 and earlier has an important vulnerability that could lead to memory address leak.
network
low complexity
adobe CWE-200
5.3