Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-07-12 CVE-2016-6174 PHP Code Injection vulnerability in IPS Community Suite
applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute arbitrary code via the content_class parameter.
6.8
2016-07-12 CVE-2016-5774 Cryptographic Issues vulnerability in Blue Coat Packetshaper S-Series
The HTTPS server in Blue Coat PacketShaper S-Series 11.5.x before 11.5.3.2 might allow remote attackers to obtain sensitive credentials and other information via unspecified vectors, related to use of insecure cryptographic parameters.
network
blue-coat CWE-310
4.3
2016-07-12 CVE-2016-5009 Improper Input Validation vulnerability in Redhat products
The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
network
low complexity
redhat CWE-20
6.5
2016-07-12 CVE-2016-4428 Cross-site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS template in a dashboard form.
network
low complexity
openstack redhat debian CWE-79
5.4
2016-07-12 CVE-2015-3192 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
4.3
2016-07-12 CVE-2016-5781 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Wecon Levistudio
Stack-based buffer overflow in WECON LeviStudio allows remote attackers to execute arbitrary code via a crafted file.
network
wecon CWE-119
6.8
2016-07-12 CVE-2016-4533 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Wecon Levistudiou
Heap-based buffer overflow in WECON LeviStudio allows remote attackers to execute arbitrary code via a crafted file.
network
wecon CWE-119
6.8
2016-07-12 CVE-2016-4503 Improper Authentication vulnerability in Moxa Device Server web Console 5232-N Firmware
Moxa Device Server Web Console 5232-N allows remote attackers to bypass authentication, and consequently modify settings and data, via vectors related to reading a cookie parameter containing a UserId value.
network
low complexity
moxa CWE-287
5.0
2016-07-12 CVE-2016-2205 Path Traversal vulnerability in Symantec Workspace Streaming and Workspace Virtualization
Directory traversal vulnerability in the file-download configuration file in the management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 allows remote authenticated users to read unspecified application files via unknown vectors.
low complexity
symantec CWE-22
6.1
2016-07-12 CVE-2016-1445 Unspecified vulnerability in Cisco Adaptive Security Appliance Software
Cisco Adaptive Security Appliance (ASA) Software 8.2 through 9.4.3.3 allows remote attackers to bypass intended ICMP Echo Reply ACLs via vectors related to subtypes.
network
low complexity
cisco
5.3