Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-08-07 CVE-2015-7855 Improper Input Validation vulnerability in multiple products
The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value.
network
low complexity
ntp debian netapp siemens CWE-20
6.5
2017-08-07 CVE-2015-7852 Improper Input Validation vulnerability in multiple products
ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted mode 6 response packets.
network
high complexity
ntp debian netapp oracle redhat CWE-20
5.9
2017-08-07 CVE-2015-7850 Infinite Loop vulnerability in multiple products
ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (infinite loop or crash) by pointing the key file at the log file.
network
low complexity
ntp debian netapp CWE-835
6.5
2017-08-07 CVE-2015-7702 Improper Input Validation vulnerability in multiple products
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash).
network
low complexity
ntp oracle debian netapp redhat CWE-20
6.5
2017-08-07 CVE-2017-12654 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.63
The ReadPICTImage function in coders/pict.c in ImageMagick 7.0.6-3 allows attackers to cause a denial of service (memory leak) via a crafted file.
network
low complexity
imagemagick CWE-772
6.5
2017-08-07 CVE-2015-8621 Permissions, Privileges, and Access Controls vulnerability in Tcoffee T-Coffee 11.00.8Cbe4861
t-coffee before 11.00.8cbe486-2 allows local users to write to ~/.t_coffee globally.
local
low complexity
tcoffee CWE-264
5.5
2017-08-07 CVE-2015-3839 NULL Pointer Dereference vulnerability in Google Android
The updateMessageStatus function in Android 5.1.1 and earlier allows local users to cause a denial of service (NULL pointer exception and process crash).
local
low complexity
google CWE-476
5.5
2017-08-07 CVE-2009-5145 Cross-site Scripting vulnerability in Zope
Cross-site scripting (XSS) vulnerability in ZMI pages that use the manage_tabs_message in Zope 2.11.4, 2.11.2, 2.10.9, 2.10.7, 2.10.6, 2.10.5, 2.10.4, 2.10.2, 2.10.1, 2.12.
network
low complexity
zope CWE-79
6.1
2017-08-07 CVE-2017-12649 Cross-site Scripting vulnerability in Liferay Portal 6.1.2/6.2.2/7.0
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted title or summary that is mishandled in the Web Content Display.
network
low complexity
liferay CWE-79
6.1
2017-08-07 CVE-2017-12648 Cross-site Scripting vulnerability in Liferay Portal 6.1.2/6.2.2/7.0
XSS exists in Liferay Portal before 7.0 CE GA4 via a bookmark URL.
network
low complexity
liferay CWE-79
6.1