Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-01-09 CVE-2015-7086 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Quicktime
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.
local
low complexity
apple CWE-119
6.6
2016-01-09 CVE-2015-7085 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Quicktime
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.
local
low complexity
apple CWE-119
6.6
2016-01-09 CVE-2015-6933 Improper Access Control vulnerability in VMWare products
The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x before 7.1.2, and VMware ESXi 5.0 through 6.0 allows Windows guest OS users to gain guest OS privileges or cause a denial of service (guest OS kernel memory corruption) via unspecified vectors.
network
low complexity
vmware CWE-284
6.3
2016-01-08 CVE-2016-1565 Cross-site Scripting vulnerability in Field Group Project Field Group
Cross-site scripting (XSS) vulnerability in the Field Group module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with permission to configure field display settings to inject arbitrary web script or HTML via an element attribute.
network
low complexity
field-group-project CWE-79
6.1
2016-01-08 CVE-2016-1501 Information Exposure vulnerability in Owncloud
ownCloud Server before 8.0.9 and 8.1.x before 8.1.4 allow remote authenticated users to obtain sensitive information via unspecified vectors, which reveals the installation path in the resulting exception messages.
network
low complexity
owncloud CWE-200
4.3
2016-01-08 CVE-2016-1498 Cross-site Scripting vulnerability in Owncloud
Cross-site scripting (XSS) vulnerability in the OCS discovery provider component in ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a URL.
network
low complexity
owncloud CWE-79
6.1
2016-01-08 CVE-2015-8766 Cross-site Scripting vulnerability in Getsymphony Symphony
Multiple cross-site scripting (XSS) vulnerabilities in content/content.systempreferences.php in Symphony CMS before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via the (1) email_sendmail[from_name], (2) email_sendmail[from_address], (3) email_smtp[from_name], (4) email_smtp[from_address], (5) email_smtp[host], (6) email_smtp[port], (7) jit_image_manipulation[trusted_external_sites], or (8) maintenance_mode[ip_whitelist] parameters to system/preferences.
network
low complexity
getsymphony CWE-79
6.1
2016-01-08 CVE-2015-8376 Cross-site Scripting vulnerability in Getsymphony Symphony 2.6.3
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.6.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Navigation Group, or (3) Label parameter to blueprints/sections/edit/1.
network
low complexity
getsymphony CWE-79
6.1
2016-01-08 CVE-2014-7151 Cross-site Scripting vulnerability in Nex-Forms Lite Project Nex-Forms Lite 2.1.0
Multiple cross-site scripting (XSS) vulnerabilities in the NEX-Forms Lite plugin 2.1.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the form_fields parameter in a (1) do_edit or (2) do_insert action to wp-admin/admin-ajax.php.
network
low complexity
nex-forms-lite-project CWE-79
6.1
2016-01-08 CVE-2014-6444 Cross-site Scripting vulnerability in Titan Framework Project Titan Framework 1.5
Multiple cross-site scripting (XSS) vulnerabilities in the Titan Framework plugin before 1.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) t parameter to iframe-googlefont-preview.php or the (2) text parameter to iframe-font-preview.php.
network
low complexity
titan-framework-project CWE-79
6.1