Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-04-07 CVE-2016-1563 Improper Input Validation vulnerability in Netapp Clustered Data Ontap 8.3.1
NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
network
high complexity
netapp CWE-20
6.8
2016-04-06 CVE-2016-2292 Out-of-bounds Write vulnerability in Schneider-Electric products
Stack-based buffer overflow in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
schneider-electric CWE-787
6.5
2016-04-06 CVE-2016-2291 Out-of-bounds Read vulnerability in Schneider-Electric products
Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allow remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
network
low complexity
schneider-electric CWE-125
6.5
2016-04-06 CVE-2016-2277 Improper Access Control vulnerability in Rockwellautomation Integrated Architecture Builder 9.6.0.7/9.7.0.0/9.7.0.1
IAB.exe in Rockwell Automation Integrated Architecture Builder (IAB) before 9.6.0.8 and 9.7.x before 9.7.0.2 allows remote attackers to execute arbitrary code via a crafted project file.
local
high complexity
rockwellautomation CWE-284
6.3
2016-04-06 CVE-2016-1346 Resource Management Errors vulnerability in multiple products
The kernel in Cisco TelePresence Server 3.0 through 4.2(4.18) on Mobility Services Engine (MSE) 8710 devices allows remote attackers to cause a denial of service (panic and reboot) via a crafted sequence of IPv6 packets, aka Bug ID CSCuu46673.
network
high complexity
dell netgear samsung zyxel zzinc CWE-399
5.9
2016-04-06 CVE-2016-1173 Cross-site Scripting vulnerability in Hiniarata Casebook Plugin 0.9.2
Cross-site scripting (XSS) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
hiniarata CWE-79
6.1
2016-04-06 CVE-2016-1171 Cross-site Scripting vulnerability in Hiniarata Casebook Plugin 0.9.2
Cross-site scripting (XSS) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
hiniarata CWE-79
6.1
2016-04-06 CVE-2016-1169 Cross-site Scripting vulnerability in Hiniarata Casebook Plugin 0.9.2/0.9.3
Cross-site scripting (XSS) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
hiniarata CWE-79
6.1
2016-04-06 CVE-2016-3969 Cross-site Scripting vulnerability in Mcafee Email Gateway
Cross-site scripting (XSS) vulnerability in McAfee Email Gateway (MEG) 7.6.x before 7.6.404, when File Filtering is enabled with the action set to ESERVICES:REPLACE, allows remote attackers to inject arbitrary web script or HTML via an attachment in a blocked email.
network
low complexity
mcafee CWE-79
6.1
2016-04-06 CVE-2016-3968 Cross-site Scripting vulnerability in Sophos products
Multiple cross-site scripting (XSS) vulnerabilities in Sophos Cyberoam CR100iNG UTM appliance with firmware 10.6.3 MR-1 build 503, CR35iNG UTM appliance with firmware 10.6.2 MR-1 build 383, and CR35iNG UTM appliance with firmware 10.6.2 Build 378 allow remote attackers to inject arbitrary web script or HTML via the (1) ipFamily parameter to corporate/webpages/trafficdiscovery/LiveConnections.jsp; the (2) ipFamily, (3) applicationname, or (4) username parameter to corporate/webpages/trafficdiscovery/LiveConnectionDetail.jsp; or the (5) X-Forwarded-For HTTP header.
network
low complexity
sophos CWE-79
6.1