Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-04-22 CVE-2016-4063 Remote Code Execution vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via an object with a revision number of -1 in a PDF document.
network
foxitsoftware
6.8
2016-04-22 CVE-2016-4062 Data Processing Errors vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Foxit Reader and PhantomPDF before 7.3.4 on Windows improperly report format errors recursively, which allows remote attackers to cause a denial of service (application hang) via a crafted PDF.
4.3
2016-04-22 CVE-2016-4061 Improper Input Validation vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Foxit Reader and PhantomPDF before 7.3.4 on Windows allow remote attackers to cause a denial of service (application crash) via a crafted content stream.
network
low complexity
foxitsoftware CWE-20
5.0
2016-04-22 CVE-2016-4060 Remote Code Execution vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
network
low complexity
foxitsoftware
5.0
2016-04-22 CVE-2016-4059 Remote Code Execution vulnerability in Foxitsoftware Foxit Reader and Phantompdf
Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted FlateDecode stream in a PDF document.
network
foxitsoftware
6.8
2016-04-22 CVE-2016-1596 Cross-site Scripting vulnerability in Novell Service Desk 7.1
Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary web script or HTML via a certain (1) user name, (2) tf_aClientFirstName, (3) tf_aClientLastName, (4) ta_selectedTopicContent, (5) tf_orgUnitName, (6) tf_aManufacturerFullName, (7) tf_aManufacturerName, (8) tf_aManufacturerAddress, or (9) tf_aManufacturerCity parameter.
network
low complexity
novell CWE-79
5.4
2016-04-22 CVE-2016-1595 Information Exposure vulnerability in Novell Service Desk 7.1
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.
network
low complexity
novell CWE-200
6.5
2016-04-22 CVE-2016-1594 Information Exposure vulnerability in Novell Service Desk 7.1
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFiles or (2) downloadFile action.
network
low complexity
novell CWE-200
6.5
2016-04-22 CVE-2016-2305 Cross-site Scripting vulnerability in Ecava Integraxor
Cross-site scripting (XSS) vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
network
ecava CWE-79
4.3
2016-04-22 CVE-2016-2304 Information Exposure vulnerability in Ecava Integraxor
Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
network
ecava CWE-200
4.3