Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-09-01 CVE-2016-3064 Information Exposure vulnerability in Netapp Clustered Data Ontap
NetApp Clustered Data ONTAP before 8.2.4P4 and 8.3.x before 8.3.2P2 allows remote authenticated users to obtain sensitive cluster and tenant information via unspecified vectors.
network
low complexity
netapp CWE-200
4.0
2016-09-01 CVE-2016-0293 Cross-site Scripting vulnerability in IBM Bigfix Platform
Cross-site scripting (XSS) vulnerability in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.1.8 and 9.2.x before 9.2.8 allows remote attackers to inject arbitrary web script or HTML via a modified .beswrpt file.
network
ibm CWE-79
4.3
2016-08-31 CVE-2016-5677 Information Exposure vulnerability in multiple products
NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng account, which allows remote attackers to obtain sensitive information via an __nvr_status___.php request.
network
low complexity
netgear nuuo CWE-200
5.0
2016-08-31 CVE-2016-5676 Improper Authorization vulnerability in multiple products
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the administrator password via a cmd=loaddefconfig action.
network
low complexity
netgear nuuo CWE-285
5.0
2016-08-31 CVE-2016-7118 NULL Pointer Dereference vulnerability in Debian Linux 7.0
fs/fcntl.c in the "aufs 3.2.x+setfl-debian" patch in the linux-image package 3.2.0-4 (kernel 3.2.81-1) in Debian wheezy mishandles F_SETFL fcntl calls on directories, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via standard filesystem operations, as demonstrated by scp from an AUFS filesystem.
local
low complexity
debian CWE-476
4.9
2016-08-31 CVE-2016-5332 Path Traversal vulnerability in VMWare Vrealize LOG Insight
Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
vmware CWE-22
5.0
2016-08-30 CVE-2016-0397 Information Exposure vulnerability in IBM Bigfix Webreports
WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic.
network
ibm CWE-200
4.3
2016-08-29 CVE-2016-5721 Cross-site Scripting vulnerability in Zimbra Collaboration Server
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
zimbra CWE-79
4.3
2016-08-26 CVE-2016-5683 Multiple Security vulnerability in Readydesk 9.1
ReadyDesk 9.1 allows local users to determine cleartext SQL Server credentials by reading the SQL_Config.aspx file and decrypting data with a hardcoded key in the ReadyDesk.dll file.
local
low complexity
readydesk
4.6
2016-08-26 CVE-2016-5664 Path Traversal vulnerability in Accellion Kiteworks Appliance Kw2016.03.00
Directory traversal vulnerability on Accellion Kiteworks appliances before kw2016.03.00 allows remote attackers to read files via a crafted URI.
network
low complexity
accellion CWE-22
5.0