Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-06-30 CVE-2016-3647 Security Bypass vulnerability in Symantec Endpoint Protection Manager 12.1.6
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and trigger network traffic to arbitrary intranet hosts, via a crafted request.
network
low complexity
symantec
4.0
2016-06-30 CVE-2016-5301 Improper Input Validation vulnerability in multiple products
The parse_chunk_header function in libtorrent before 1.1.1 allows remote attackers to cause a denial of service (crash) via a crafted (1) HTTP response or possibly a (2) UPnP broadcast.
network
low complexity
opensuse arvidn CWE-20
5.0
2016-06-30 CVE-2016-4803 Email Header Injection vulnerability in dotCMS
CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email headers via CRLF sequences in the subject.
network
low complexity
dotcms
5.0
2016-06-30 CVE-2016-3189 Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.
network
low complexity
bzip python
6.5
2016-06-30 CVE-2016-5729 Permissions, Privileges, and Access Controls vulnerability in Lenovo Bios EFI Driver
Lenovo BIOS EFI Driver allows local administrators to execute arbitrary code with System Management Mode (SMM) privileges via unspecified vectors.
local
low complexity
lenovo CWE-264
6.8
2016-06-30 CVE-2016-5231 Permissions, Privileges, and Access Controls vulnerability in Huawei Mate 8 Firmware NXT
Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to bypass permission checks and delete user data via a crafted app.
network
low complexity
huawei CWE-264
5.0
2016-06-30 CVE-2016-5230 Permissions, Privileges, and Access Controls vulnerability in Huawei Mate 8 Firmware NXT
Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to bypass permission checks and control partial module functions via a crafted app.
network
huawei CWE-264
6.8
2016-06-30 CVE-2016-4057 Resource Management Errors vulnerability in Huawei Fusioncompute V100R005C00
Huawei FusionCompute before V100R005C10SPC700 allows remote authenticated users to cause a denial of service (resource consumption) via a large number of crafted packets.
network
low complexity
huawei CWE-399
6.8
2016-06-30 CVE-2016-0349 Improper Access Control vulnerability in IBM Business Process Manager 8.5.6.0/8.5.7.0
IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to bypass intended access restrictions and update process-instance variables via a REST API call.
network
low complexity
ibm CWE-284
4.0
2016-06-29 CVE-2016-5839 Security vulnerability in WordPress
WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors.
network
low complexity
wordpress
5.0