Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-04-07 CVE-2016-2858 Insufficient Entropy vulnerability in multiple products
QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbitrary stack based allocation and memory corruption.
local
low complexity
qemu canonical debian CWE-331
6.5
2016-04-07 CVE-2016-0734 7PK - Security Features vulnerability in Apache Activemq
The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.
network
low complexity
apache CWE-254
6.1
2016-04-07 CVE-2016-3948 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Squid-Cache Squid
Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking, which allows remote attackers to cause a denial of service via a crafted HTTP response, related to Vary headers.
network
low complexity
squid-cache CWE-119
5.0
2016-04-07 CVE-2016-1563 Improper Input Validation vulnerability in Netapp Clustered Data Ontap 8.3.1
NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
network
netapp CWE-20
5.8
2016-04-06 CVE-2016-2292 Out-of-bounds Write vulnerability in Schneider-Electric products
Stack-based buffer overflow in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allows remote attackers to execute arbitrary code via unspecified vectors.
4.3
2016-04-06 CVE-2016-2291 Out-of-bounds Read vulnerability in Schneider-Electric products
Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allow remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
4.3
2016-04-06 CVE-2016-2290 Out-of-bounds Write vulnerability in Schneider-Electric products
Heap-based buffer overflow in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allows remote attackers to execute arbitrary code via unspecified vectors.
6.8
2016-04-06 CVE-2016-2277 Improper Access Control vulnerability in Rockwellautomation Integrated Architecture Builder 9.6.0.7/9.7.0.0/9.7.0.1
IAB.exe in Rockwell Automation Integrated Architecture Builder (IAB) before 9.6.0.8 and 9.7.x before 9.7.0.2 allows remote attackers to execute arbitrary code via a crafted project file.
6.9
2016-04-06 CVE-2016-2272 Improper Access Control vulnerability in Eaton Lighting Systems EG2 web Control
Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to have an unspecified impact via a modified cookie.
network
low complexity
eaton-lighting-systems CWE-284
5.0
2016-04-06 CVE-2016-1290 Permissions, Privileges, and Access Controls vulnerability in Cisco products
The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent with a pattern filter, aka Bug ID CSCuy10227.
network
low complexity
cisco CWE-264
5.5