Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-11-25 CVE-2016-2928 Information Exposure Through Log Files vulnerability in IBM Bigfix Remote Control 9.1.2
IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to obtain sensitive information by reading error logs.
network
low complexity
ibm CWE-532
4.0
2016-11-25 CVE-2016-2927 Information Exposure vulnerability in IBM Bigfix Remote Control 9.1.2
IBM BigFix Remote Control before 9.1.3 does not properly restrict the set of available encryption algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.
network
ibm CWE-200
4.3
2016-11-25 CVE-2016-0319 Improper Access Control vulnerability in IBM Jazz Reporting Service 6.0/6.0.1
The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administrators to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
network
low complexity
ibm CWE-284
5.0
2016-11-25 CVE-2016-0318 Improper Access Control vulnerability in IBM Jazz Reporting Service 6.0/6.0.1
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, which allows remote attackers to obtain access by leveraging an unattended workstation.
network
ibm CWE-284
6.0
2016-11-25 CVE-2016-0317 Improper Access Control vulnerability in IBM Jazz Reporting Service 6.0/6.0.1
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
network
ibm CWE-284
4.3
2016-11-25 CVE-2016-9452 Improper Input Validation vulnerability in Drupal
The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafted URL.
network
drupal CWE-20
4.3
2016-11-25 CVE-2016-9451 Open Redirect vulnerability in Drupal
Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.
network
drupal CWE-601
4.9
2016-11-25 CVE-2016-9450 Insufficient Verification of Data Authenticity vulnerability in Drupal
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.
network
low complexity
drupal CWE-345
5.0
2016-11-25 CVE-2016-9449 Information Exposure vulnerability in Drupal
The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.
network
low complexity
drupal CWE-200
4.0
2016-11-25 CVE-2016-6754 Injection vulnerability in Google Android
A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is navigating to a website.
network
google CWE-74
6.8