Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2015-04-01 CVE-2015-2814 Permissions, Privileges, and Access Controls vulnerability in SAP Clinical Task Tracker and EMR Unwired
SAP EMR Unwired (com.sap.mobile.healthcare.emr.v2) and Clinical Task Tracker (com.sap.mobile.healthcare.ctt) does not properly restrict access, which allows remote attackers to change the backendurl, clientid, ssourl, and infopageurl settings via unspecified vectors, aka SAP Security Note 2117079.
network
low complexity
sap CWE-264
6.4
2015-04-01 CVE-2015-2813 XML External Entity Injection vulnerability in SAP Mobile Platform
XML external entity (XXE) vulnerability in SAP Mobile Platform allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2125358.
network
low complexity
sap
5.0
2015-04-01 CVE-2015-2812 XML External Entity Information Disclosure vulnerability in SAP Netweaver Enterprise Portal 7.31
XML external entity (XXE) vulnerability in XMLValidationComponent in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2093966.
network
low complexity
sap
5.0
2015-04-01 CVE-2015-2811 Unspecified vulnerability in SAP Netweaver Enterprise Portal 7.31
XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2111939.
network
low complexity
sap
5.0
2015-04-01 CVE-2015-2756 Permissions, Privileges, and Access Controls vulnerability in multiple products
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.
local
low complexity
debian xen fedoraproject canonical CWE-264
4.9
2015-04-01 CVE-2015-2755 Cross-Site Request Forgery (CSRF) vulnerability in AB Google MAP Travel Project AB Google MAP Travel 3.4
Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) lat (Latitude), (2) long (Longitude), (3) map_width, (4) map_height, or (5) zoom (Map Zoom) parameter in the ab_map_options page to wp-admin/admin.php.
6.8
2015-04-01 CVE-2015-2752 Improper Input Validation vulnerability in multiple products
The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via a crafted request to the device model (qemu-dm).
local
low complexity
fedoraproject xen CWE-20
4.9
2015-04-01 CVE-2015-2294 Cross-site Scripting vulnerability in Netgate Pfsense
Multiple cross-site scripting (XSS) vulnerabilities in the WebGUI in pfSense before 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) zone parameter to status_captiveportal.php; (2) if or (3) dragtable parameter to firewall_rules.php; (4) queue parameter in an add action to firewall_shaper.php; (5) id parameter in an edit action to services_unbound_acls.php; or (6) filterlogentries_time, (7) filterlogentries_sourceipaddress, (8) filterlogentries_sourceport, (9) filterlogentries_destinationipaddress, (10) filterlogentries_interfaces, (11) filterlogentries_destinationport, (12) filterlogentries_protocolflags, or (13) filterlogentries_qty parameter to diag_logs_filter.php.
network
netgate CWE-79
4.3
2015-04-01 CVE-2014-9713 Permissions, Privileges, and Access Controls vulnerability in multiple products
The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attributes via unspecified vectors.
network
low complexity
openldap debian CWE-264
4.0
2015-04-01 CVE-2015-0816 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox, Firefox ESR and Thunderbird
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.
network
low complexity
mozilla CWE-264
5.0