Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-10-05 CVE-2016-5901 Cross-site Scripting vulnerability in IBM Business Process Manager
Cross-site scripting (XSS) vulnerability in a test page in IBM Business Process Manager Advanced 8.5.6.0 through 8.5.7.0 before cumulative fix 2016.09 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
ibm CWE-79
5.4
2016-10-05 CVE-2016-5892 Cross-site Scripting vulnerability in IBM products
Cross-site scripting (XSS) vulnerability in IBM 10x, as used in Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications before 1.0.0.5_2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
ibm CWE-79
5.4
2016-10-05 CVE-2016-6550 Cryptographic Issues vulnerability in Bb&T the U 1.5.4
The U by BB&T app 1.5.4 and earlier for iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
low complexity
bb-t CWE-310
5.4
2016-10-03 CVE-2016-8280 Path Traversal vulnerability in Huawei Esight V300R002C00/V300R003C10/V300R003C20
Directory traversal vulnerability in Huawei eSight before V300R003C20SPC005 allows remote authenticated users to read arbitrary files via unspecified vectors.
network
low complexity
huawei CWE-22
6.5
2016-10-03 CVE-2016-8277 Improper Input Validation vulnerability in Huawei Usg9520, Usg9560 and Usg9580
Huawei USG9520, USG9560, and USG9580 unified security gateways with software before V300R001C01SPCa00 allow remote authenticated users to cause a denial of service (device restart) via an unspecified command parameter.
network
low complexity
huawei CWE-20
6.5
2016-10-03 CVE-2016-7046 Resource Management Errors vulnerability in Redhat Jboss Enterprise Application Platform 7.0
Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via a long URL.
network
high complexity
redhat CWE-399
5.9
2016-10-03 CVE-2016-6905 Out-of-bounds Read vulnerability in multiple products
The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA image.
network
low complexity
libgd opensuse CWE-125
6.5
2016-10-03 CVE-2015-8086 Inadequate Encryption Strength vulnerability in Huawei products
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 makes it easier for remote authenticated administrators to obtain encryption keys and ciphertext passwords via vectors related to key storage.
network
low complexity
huawei CWE-326
4.9
2016-10-03 CVE-2015-8085 Inadequate Encryption Strength vulnerability in Huawei products
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 make it easier for remote authenticated administrators to obtain and decrypt passwords by leveraging selection of a reversible encryption algorithm.
network
low complexity
huawei CWE-326
4.9
2016-10-03 CVE-2016-7572 Permissions, Privileges, and Access Controls vulnerability in Drupal
The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.
network
low complexity
drupal CWE-264
4.3