Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-09-24 CVE-2016-0918 Information Exposure vulnerability in EMC products
EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x before 6.9.1 P15 and RSA Via Lifecycle and Governance before 7.0.0 P04 allow remote authenticated users to obtain User Detail Popup information via a modified URL.
network
low complexity
emc CWE-200
4.0
2016-09-24 CVE-2016-6413 Permissions, Privileges, and Access Controls vulnerability in Cisco Application Policy Infrastructure Controller 1.3(2F)
The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors, aka Bug ID CSCva50496.
local
low complexity
cisco CWE-264
6.8
2016-09-24 CVE-2016-6412 Improper Input Validation vulnerability in Cisco IOS 15.6(1)T1
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-middle attackers to trigger arbitrary downloads via crafted HTTP headers, aka Bug ID CSCuz84773.
network
cisco CWE-20
4.3
2016-09-24 CVE-2016-6411 Improper Input Validation vulnerability in Cisco Firesight System Software 6.0.1
Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote attackers to bypass intended do-not-decrypt settings via a crafted URL, aka Bug ID CSCva50585.
network
low complexity
cisco CWE-20
5.0
2016-09-24 CVE-2016-6410 Improper Input Validation vulnerability in Cisco IOS 15.5(2)T
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuy19856.
network
low complexity
cisco CWE-20
6.8
2016-09-24 CVE-2016-6409 Resource Management Errors vulnerability in Cisco IOS 15.6(1)T
The Data in Motion (DMo) component in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service (out-of-bounds access) via crafted traffic, aka Bug ID CSCuy54015.
network
cisco CWE-399
4.3
2016-09-24 CVE-2016-6408 XXE vulnerability in Cisco Prime Home 5.2.0
Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCvb17814.
network
cisco CWE-611
4.3
2016-09-22 CVE-2016-5283 Improper Access Control vulnerability in Mozilla Firefox
Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.
network
mozilla CWE-284
6.8
2016-09-22 CVE-2016-5282 Information Exposure vulnerability in Mozilla Firefox
Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.
network
mozilla CWE-200
4.3
2016-09-22 CVE-2016-5279 Information Exposure vulnerability in Mozilla Firefox
Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code.
network
mozilla CWE-200
4.3