Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-05-22 CVE-2016-1564 Cross-site Scripting vulnerability in Wordpress
Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name or (2) template name to wp-admin/customize.php.
network
wordpress CWE-79
4.3
2016-05-22 CVE-2015-8879 Improper Input Validation vulnerability in PHP
The odbc_bindcols function in ext/odbc/php_odbc.c in PHP before 5.6.12 mishandles driver behavior for SQL_WVARCHAR columns, which allows remote attackers to cause a denial of service (application crash) in opportunistic circumstances by leveraging use of the odbc_fetch_array function to access a certain type of Microsoft SQL Server table.
network
low complexity
php CWE-20
5.0
2016-05-22 CVE-2015-8877 Resource Management Errors vulnerability in multiple products
The gdImageScaleTwoPass function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in PHP before 5.6.12, uses inconsistent allocate and free approaches, which allows remote attackers to cause a denial of service (memory consumption) via a crafted call, as demonstrated by a call to the PHP imagescale function.
network
low complexity
libgd php CWE-399
5.0
2016-05-22 CVE-2015-8834 Cross-site Scripting vulnerability in Wordpress
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.
network
wordpress CWE-79
4.3
2016-05-22 CVE-2015-5715 Permissions, Privileges, and Access Controls vulnerability in Wordpress
The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.
network
low complexity
wordpress CWE-264
4.0
2016-05-22 CVE-2015-5714 Cross-site Scripting vulnerability in Wordpress
Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.
network
wordpress CWE-79
4.3
2016-05-22 CVE-2014-9767 Path Traversal vulnerability in PHP
Directory traversal vulnerability in the ZipArchive::extractTo function in ext/zip/php_zip.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 and ext/zip/ext_zip.cpp in HHVM before 3.12.1 allows remote attackers to create arbitrary empty directories via a crafted ZIP archive.
4.3
2016-05-21 CVE-2016-1402 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Identity Services Engine Software 1.2.0.899
The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (authentication outage) via a crafted Password Authentication Protocol (PAP) authentication request, aka Bug ID CSCun25815.
network
low complexity
cisco CWE-119
5.0
2016-05-21 CVE-2016-1401 Cross-site Scripting vulnerability in Cisco Unified Computing System Central Software 1.4(1A)
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Computing System (UCS) Central Software 1.4(1a) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuy91250.
network
cisco CWE-79
4.3
2016-05-20 CVE-2016-4439 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or potentially execute arbitrary code on the QEMU host via unspecified vectors.
local
low complexity
canonical qemu debian CWE-119
4.6