Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-10-28 CVE-2016-9018 NULL Pointer Dereference vulnerability in Realnetworks Realplayer 18.1.5.705
Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlayer 18.1.5.705 through a crafted .QCP media file.
4.3
2016-10-28 CVE-2016-9017 Information Exposure vulnerability in Artifex Mujs
Artifex Software, Inc.
network
low complexity
artifex CWE-200
5.0
2016-10-28 CVE-2016-8867 Permissions, Privileges, and Access Controls vulnerability in Docker 1.12.2
Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies.
network
low complexity
docker CWE-264
5.0
2016-10-28 CVE-2016-8600 Permissions, Privileges, and Access Controls vulnerability in Dotcms 3.2.1
In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.
network
low complexity
dotcms CWE-264
5.0
2016-10-28 CVE-2016-8583 Cross-site Scripting vulnerability in Alienvault products
Multiple GET parameters in the vulnerability scan scheduler of AlienVault OSSIM and USM before 5.3.2 are vulnerable to reflected XSS.
network
alienvault CWE-79
4.3
2016-10-28 CVE-2016-8581 Cross-site Scripting vulnerability in Alienvault products
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to steal session IDs of logged in users when the current sessions are viewed by an administrator.
network
alienvault CWE-79
4.3
2016-10-28 CVE-2016-8332 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Uclouvain Openjpeg 2.1.1
A buffer overflow in OpenJPEG 2.1.1 causes arbitrary code execution when parsing a crafted image.
network
uclouvain CWE-119
6.8
2016-10-28 CVE-2016-6372 Improper Input Validation vulnerability in Cisco products
A vulnerability in the email message and content filtering for malformed Multipurpose Internet Mail Extensions (MIME) headers of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of the targeted device.
network
low complexity
cisco CWE-20
5.0
2016-10-28 CVE-2016-6360 Improper Input Validation vulnerability in Cisco Email Security Appliance and web Security Appliance
A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition due to the AMP process unexpectedly restarting.
network
low complexity
cisco CWE-20
5.0
2016-10-28 CVE-2016-6358 Improper Input Validation vulnerability in Cisco Email Security Appliance
A vulnerability in local FTP to the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition when the FTP application unexpectedly quits.
network
low complexity
cisco CWE-20
5.0