Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-03-06 CVE-2016-1640 Code vulnerability in Google Chrome
The Web Store inline-installer implementation in the Extensions UI in Google Chrome before 49.0.2623.75 does not block installations upon deletion of an installation frame, which makes it easier for remote attackers to trick a user into believing that an installation request originated from the user's next navigation target via a crafted web site.
network
low complexity
google CWE-17
4.3
2016-03-06 CVE-2016-1638 Improper Access Control vulnerability in Google Chrome
extensions/renderer/resources/platform_app.js in the Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly restrict use of Web APIs, which allows remote attackers to bypass intended access restrictions via a crafted platform app.
network
low complexity
google CWE-284
6.3
2016-03-06 CVE-2016-1637 Information Exposure vulnerability in Google Chrome
The SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia, as used in Google Chrome before 49.0.2623.75, mishandles arctangent calculations, which allows remote attackers to obtain sensitive information via a crafted web site.
network
low complexity
google CWE-200
6.5
2016-03-04 CVE-2016-2283 Credentials Management vulnerability in Moxa Ioadmin Firmware and Iologik Firmware
Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt data, which makes it easier for remote attackers to obtain the associated cleartext via unspecified vectors.
network
low complexity
moxa CWE-255
5.3
2016-03-04 CVE-2016-2282 Credentials Management vulnerability in Moxa Ioadmin Firmware and Iologik Firmware
Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt credentials, which makes it easier for remote attackers to obtain the associated cleartext via unspecified vectors.
network
low complexity
moxa CWE-255
5.3
2016-03-04 CVE-2016-2244 Information Exposure vulnerability in HP Futuresmart Firmware 3.7
HP LaserJet printers and MFPs and OfficeJet Enterprise printers with firmware before 3.7.01 allow remote attackers to obtain sensitive information via unspecified vectors.
network
high complexity
hp CWE-200
5.9
2016-03-03 CVE-2016-1358 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Prime Infrastructure 2.2/3.0/3.1
Cisco Prime Infrastructure 2.2, 3.0, and 3.1(0.0) allows remote authenticated users to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCuw81497.
network
high complexity
cisco CWE-119
6.4
2016-03-03 CVE-2016-1357 Information Exposure vulnerability in Cisco Policy Suite
The password-management administration component in Cisco Policy Suite (CPS) 7.0.1.3, 7.0.2, 7.0.2-att, 7.0.3-att, 7.0.4-att, and 7.5.0 allows remote attackers to bypass intended RBAC restrictions and read unspecified data via unknown vectors, aka Bug ID CSCut85211.
network
low complexity
cisco CWE-200
5.3
2016-03-03 CVE-2016-1288 Improper Input Validation vulnerability in Cisco web Security Appliance 8.5.0497/9.0.0193
The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (service outage) by leveraging certain intranet connectivity and sending a malformed HTTPS request, aka Bug ID CSCuu24840.
network
low complexity
cisco CWE-20
5.3
2016-03-03 CVE-2016-0227 Cross-site Scripting vulnerability in IBM Business Process Manager
Cross-site scripting (XSS) vulnerability in the document-list control implementation in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, and 8.5.5 and 8.5.6 through 8.5.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
network
low complexity
ibm CWE-79
5.4