Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-10-25 CVE-2016-3495 Unspecified vulnerability in Oracle Mysql
Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: InnoDB.
network
low complexity
oracle
6.8
2016-10-25 CVE-2016-3492 Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier allows remote authenticated users to affect availability via vectors related to Server: Optimizer.
network
low complexity
oracle mariadb redhat
6.8
2016-10-25 CVE-2016-3473 Information Exposure vulnerability in Oracle Business Intelligence Publisher 11.1.1.7.0/11.1.1.9.0/12.2.1.0.0
Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality via unknown vectors.
network
low complexity
oracle CWE-200
4.0
2016-10-25 CVE-2016-1000215 Unspecified vulnerability in Ruckus Wireless H500
Ruckus Wireless H500 web management interface denial of service
network
low complexity
ruckus
5.0
2016-10-25 CVE-2016-1000214 Information Exposure vulnerability in Ruckus Wireless H500
Ruckus Wireless H500 web management interface authentication bypass
network
low complexity
ruckus CWE-200
5.0
2016-10-25 CVE-2016-1000213 Cross-Site Request Forgery (CSRF) vulnerability in Ruckus Wireless H500
Ruckus Wireless H500 web management interface CSRF
network
ruckus CWE-352
6.8
2016-10-25 CVE-2016-1000033 Improper Certificate Validation vulnerability in multiple products
Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.
network
gnome redhat CWE-295
4.3
2016-10-25 CVE-2016-1000032 Improper Access Control vulnerability in Python Tgcaptcha2 0.3.0
TGCaptcha2 version 0.3.0 is vulnerable to a replay attack due to a missing nonce allowing attackers to use a single solved CAPTCHA multiple times.
network
low complexity
python CWE-284
5.0
2016-10-22 CVE-2016-0377 Information Exposure vulnerability in IBM Websphere Application Server
The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, and 8.5.x before 8.5.5.10 mishandles CSRFtoken cookies, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
network
low complexity
ibm CWE-200
4.0
2016-10-22 CVE-2016-0326 Command Injection vulnerability in IBM products
IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iFix17, and 6.x before 6.0.1 ifix3 allow remote authenticated users to execute arbitrary OS commands via a crafted "HTML request."
network
low complexity
ibm CWE-77
6.5