Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-04-21 CVE-2016-0640 Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect integrity and availability via vectors related to DML.
local
low complexity
oracle opensuse mariadb debian redhat ibm
6.1
2016-04-21 CVE-2016-0623 Unspecified vulnerability in Oracle Solaris 11.3
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows remote attackers to affect integrity via vectors related to the Automated Installer sub-component.
network
low complexity
oracle
4.7
2016-04-21 CVE-2016-0479 Unspecified vulnerability in Oracle Business Intelligence 11.1.1.7.0/11.1.1.9.0/12.2.1.0.0
Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality and integrity via vectors related to Analytics Scorecard.
network
low complexity
oracle
6.1
2016-04-21 CVE-2016-0469 Unspecified vulnerability in Oracle Micros C2 9.89.0.0
Unspecified vulnerability in the Oracle Retail MICROS C2 component in Oracle Retail Applications 9.89.0.0 allows local users to affect confidentiality via vectors related to POS.
local
low complexity
oracle
5.5
2016-04-21 CVE-2016-0468 Unspecified vulnerability in Oracle Business Intelligence 11.1.1.7.0/11.1.1.9.0/12.2.1.0.0
Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to Analytics Web General.
network
low complexity
oracle
5.4
2016-04-21 CVE-2016-0408 Unspecified vulnerability in Oracle Peoplesoft Enterprise Peopletools 8.53/8.54/8.55
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 through 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to the Activity Guide sub-component.
network
low complexity
oracle
5.4
2016-04-21 CVE-2016-0407 Unspecified vulnerability in Oracle Peoplesoft Enterprise Human Capital Management Human Resources 9.1/9.2
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via vectors related to Fusion HR Talent Integration.
network
low complexity
oracle
6.5
2016-04-21 CVE-2015-6479 Unspecified vulnerability in Sierrawireless Aleos
ACEmanager in Sierra Wireless ALEOS 4.4.2 and earlier on ES440, ES450, GX400, GX440, GX450, and LS300 devices allows remote attackers to read the filteredlogs.txt file, and consequently discover potentially sensitive boot-sequence information, via unspecified vectors.
network
low complexity
sierrawireless
4.3
2016-04-20 CVE-2016-2202 Permissions, Privileges, and Access Controls vulnerability in Symantec Altiris IT Management Suite 7.6
The Inventory Solution component in the Management Agent in the client in Symantec Altiris IT Management Suite (ITMS) through 7.6 HF7 allows local users to bypass intended application-blacklist restrictions via unspecified vectors.
local
low complexity
symantec CWE-264
5.5
2016-04-20 CVE-2015-7802 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitialized memory read) via a crafted GIF file.
local
low complexity
optipng-project canonical CWE-119
5.5