Vulnerabilities > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2016-06-14 | CVE-2016-5367 | Information Exposure vulnerability in Huawei Honor Ws851 Firmware Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to obtain sensitive information via unspecified vectors, aka HWPSIRT-2016-05053. | 5.0 |
2016-06-14 | CVE-2016-5366 | Improper Access Control vulnerability in Huawei Honor Ws851 Firmware Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to modify configuration data via vectors related to a "file injection vulnerability," aka HWPSIRT-2016-05052. | 5.0 |
2016-06-14 | CVE-2016-5337 | The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information. | 5.5 |
2016-06-13 | CVE-2016-4478 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a denial of service via vectors related to XMLRPC response encoding. | 5.0 |
2016-06-13 | CVE-2016-4414 | Remote Denial Of Service vulnerability in Quassel The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via invalid handshake data. | 5.0 |
2016-06-13 | CVE-2015-8869 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function. | 6.4 |
2016-06-13 | CVE-2014-9773 | Improper Access Control vulnerability in multiple products modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, (2) CLEAR, or (3) MODIFY keyword nicks. | 5.0 |
2016-06-13 | CVE-2016-5104 | Improper Access Control vulnerability in multiple products The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket. | 5.0 |
2016-06-13 | CVE-2016-4911 | Improper Access Control vulnerability in Keystone Openstack Identity 9.0.0.0 The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token. | 4.0 |
2016-06-13 | CVE-2016-3677 | 7PK - Security Features vulnerability in Huawei Hilink APP and Wear APP The Huawei Wear App application before 15.0.0.307 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008. | 6.8 |