Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-10-27 CVE-2016-6438 Permissions, Privileges, and Access Controls vulnerability in Cisco IOS XE
A vulnerability in Cisco IOS XE Software running on Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause a configuration integrity change to the vty line configuration on an affected device.
network
cisco CWE-264
4.3
2016-10-27 CVE-2016-1000122 SQL Injection vulnerability in Huge-It Slider 1.0.9
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
network
low complexity
huge-it CWE-89
6.5
2016-10-27 CVE-2016-1000120 SQL Injection vulnerability in Huge-It Catalog 1.0.4
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
network
low complexity
huge-it CWE-89
6.5
2016-10-27 CVE-2016-1598 Cross-site Scripting vulnerability in Novell products
XSS in NetIQ IDM 4.5 Identity Applications before 4.5.4 allows attackers able to change their username to inject arbitrary HTML code into the Role Assignment administrator HTML pages.
network
low complexity
novell CWE-79
5.4
2016-10-27 CVE-2016-1592 Cross-site Scripting vulnerability in Netiq Identity Manager 4.5
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the nrfEntitlementReport.do CGI.
network
low complexity
netiq CWE-79
6.1
2016-10-27 CVE-2015-0787 Cross-site Scripting vulnerability in Netiq Identity Manager 4.5
XSS in NetIQ Designer for Identity Manager before 4.5.3 allows remote attackers to inject arbitrary HTML code via the accessMgrDN value of the forgotUser.do CGI.
network
low complexity
netiq CWE-79
6.1
2016-10-26 CVE-2016-8506 Cross-site Scripting vulnerability in Yandex Browser
XSS in Yandex Browser Translator in Yandex browser for desktop for versions from 15.12 to 16.2 could be used by remote attacker for evaluation arbitrary javascript code.
network
yandex CWE-79
4.3
2016-10-26 CVE-2016-8505 Cross-site Scripting vulnerability in Yandex Yandex.Browser
XSS in Yandex Browser BookReader in Yandex browser for desktop for versions before 16.6.
network
yandex CWE-79
4.3
2016-10-26 CVE-2016-8504 Cross-Site Request Forgery (CSRF) vulnerability in Yandex Browser
CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile.
network
yandex CWE-352
4.3
2016-10-26 CVE-2016-8503 7PK - Security Features vulnerability in Yandex Browser 16.7.0.3342/16.7.1.20808/16.9.1.1131
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.
network
low complexity
yandex CWE-254
5.0