Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-11-25 CVE-2016-0317 Improper Access Control vulnerability in IBM Jazz Reporting Service 6.0/6.0.1
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
network
ibm CWE-284
4.3
2016-11-25 CVE-2016-9452 Improper Input Validation vulnerability in Drupal
The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafted URL.
network
drupal CWE-20
4.3
2016-11-25 CVE-2016-9451 Open Redirect vulnerability in Drupal
Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.
network
drupal CWE-601
4.9
2016-11-25 CVE-2016-9450 Insufficient Verification of Data Authenticity vulnerability in Drupal
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.
network
low complexity
drupal CWE-345
5.0
2016-11-25 CVE-2016-9449 Information Exposure vulnerability in Drupal
The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.
network
low complexity
drupal CWE-200
4.0
2016-11-25 CVE-2016-6754 Injection vulnerability in Google Android
A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is navigating to a website.
network
google CWE-74
6.8
2016-11-25 CVE-2016-6753 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in kernel components, including the process-grouping subsystem and the networking subsystem, in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels.
network
google CWE-200
4.3
2016-11-25 CVE-2016-6752 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels.
network
google CWE-200
4.3
2016-11-25 CVE-2016-6751 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels.
network
google CWE-200
4.3
2016-11-25 CVE-2016-6750 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels.
network
google CWE-200
4.3