Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-06-19 CVE-2016-4811 Improper Access Control vulnerability in Ntt-Bp Japan Connected-Free Wi-Fi 1.13.0/1.15.1
The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.15.1 and earlier for Android and 1.13.0 and earlier for iOS allows man-in-the-middle attackers to obtain API access via unspecified vectors.
network
high complexity
ntt-bp CWE-284
5.1
2016-06-19 CVE-2016-4530 Improper Input Validation vulnerability in Osisoft PI SQL Data Access Server 2016 1.5
OSIsoft PI SQL Data Access Server (aka OLE DB) 2016 1.5 allows remote authenticated users to cause a denial of service (service outage and data loss) via a message.
network
low complexity
osisoft CWE-20
4.0
2016-06-19 CVE-2016-4518 Improper Input Validation vulnerability in Osisoft PI AF Server 2016
OSIsoft PI AF Server before 2016 2.8.0 allows remote authenticated users to cause a denial of service (service outage) via a message.
network
low complexity
osisoft CWE-20
4.0
2016-06-19 CVE-2016-4514 Incorrect Authorization vulnerability in Moxa Pt-7728 and Pt-7728 Firmware
Moxa PT-7728 devices with software 3.4 build 15081113 allow remote authenticated users to change the configuration via vectors involving a local proxy.
network
high complexity
moxa CWE-863
4.6
2016-06-19 CVE-2016-1864 Information Exposure vulnerability in Apple Iphone OS and Safari
The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode, which allows remote attackers to obtain sensitive information via a crafted URL.
network
low complexity
apple CWE-200
5.0
2016-06-19 CVE-2016-1862 Information Exposure vulnerability in Apple mac OS X
Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1860.
network
apple CWE-200
4.3
2016-06-19 CVE-2016-1860 Information Exposure vulnerability in Apple mac OS X
Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1862.
network
apple CWE-200
4.3
2016-06-19 CVE-2016-1196 Permissions, Privileges, and Access Controls vulnerability in Cybozu Garoon
Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive Address Book information via an API call, a different vulnerability than CVE-2015-7776.
network
low complexity
cybozu CWE-264
4.0
2016-06-19 CVE-2016-1192 Path Traversal vulnerability in Cybozu Garoon
Directory traversal vulnerability in the logging implementation in Cybozu Garoon 3.7 through 4.2 allows remote authenticated users to read a log file via unspecified vectors.
network
low complexity
cybozu CWE-22
4.0
2016-06-19 CVE-2016-1191 Path Traversal vulnerability in Cybozu Garoon
Directory traversal vulnerability in the Files function in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to modify settings via unspecified vectors.
network
low complexity
cybozu CWE-22
5.0