Weekly Vulnerabilities Reports > February 20 to 26, 2017
Overview
262 new vulnerabilities reported during this period, including 20 critical vulnerabilities and 127 high severity vulnerabilities. This weekly summary report vulnerabilities in 92 products from 45 vendors including Apple, Cisco, Debian, IBM, and Webkitgtk. Vulnerabilities are notably categorized as "Improper Restriction of Operations within the Bounds of a Memory Buffer", "Information Exposure", "Improper Input Validation", "Cross-site Scripting", and "Permissions, Privileges, and Access Controls".
- 143 reported vulnerabilities are remotely exploitables.
- 78 reported vulnerabilities have public exploit available.
- 38 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 200 reported vulnerabilities are exploitable by an anonymous user.
- Apple has the most reported vulnerabilities, with 152 reported vulnerabilities.
- Dell has the most reported critical vulnerabilities, with 3 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
20 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2017-02-21 | CVE-2016-9269 | Trendmicro | Permissions, Privileges, and Access Controls vulnerability in Trendmicro Interscan web Security Virtual Appliance Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to run arbitrary commands on the system as root via Patch Update functionality. | 9.9 |
2017-02-24 | CVE-2017-2790 | Justsystems | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Justsystems Ichitaro When processing a record type of 0x3c from a Workbook stream from an Excel file (.xls), JustSystems Ichitaro Office trusts that the size is greater than zero, subtracts one from the length, and uses this result as the size for a memcpy. | 9.8 |
2017-02-24 | CVE-2017-2789 | Justsystems | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Justsystems Ichitaro When copying filedata into a buffer, JustSystems Ichitaro Office 2016 Trial will calculate two values to determine how much data to copy from the document. | 9.8 |
2017-02-23 | CVE-2017-6205 | Dlink | Unspecified vulnerability in Dlink Websmart Dgs-1510 Series Firmware 1.31.B001 D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devices with firmware before 1.31.B003 allow attackers to conduct Unauthenticated Command Bypass attacks via unspecified vectors. | 9.8 |
2017-02-22 | CVE-2017-6187 | Disksavvy | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Disksavvy Enterprise 9.4.18 Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary code via a long URI in a GET request. | 9.8 |
2017-02-22 | CVE-2017-6077 | Netgear | OS Command Injection vulnerability in Netgear Dgn2200 Firmware ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request. | 9.8 |
2017-02-22 | CVE-2016-1245 | Quagga Debian | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. | 9.8 |
2017-02-22 | CVE-2017-5586 | Opentext | Improper Input Validation vulnerability in Opentext Documentum D2 OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries. | 9.8 |
2017-02-22 | CVE-2016-9400 | Teeworlds Fedoraproject | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory locations and possibly execute arbitrary code via vectors involving snap handling. | 9.8 |
2017-02-22 | CVE-2016-9684 | Dell | Command Injection vulnerability in Dell Sonicwall Secure Remote Access Server 8.1.0.214Sv The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. | 9.8 |
2017-02-22 | CVE-2016-9683 | Dell | Command Injection vulnerability in Dell Sonicwall Secure Remote Access Server 8.1.0.214Sv The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. | 9.8 |
2017-02-22 | CVE-2016-9682 | Dell | Command Injection vulnerability in Dell Sonicwall Secure Remote Access Server 8.1.0.214Sv The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. | 9.8 |
2017-02-21 | CVE-2016-9053 | Aerospike | Improper Validation of Array Index vulnerability in Aerospike Database Server 3.10.0.3 An exploitable out-of-bounds indexing vulnerability exists within the RW fabric message particle type of Aerospike Database Server 3.10.0.3. | 9.8 |
2017-02-21 | CVE-2016-9051 | Aerospike | Out-of-bounds Write vulnerability in Aerospike Database Server 3.10.0.3 An exploitable out-of-bounds write vulnerability exists in the batch transaction field parsing functionality of Aerospike Database Server 3.10.0.3. | 9.8 |
2017-02-21 | CVE-2017-6095 | Mail Masta Project | SQL Injection vulnerability in Mail-Masta Project Mail-Masta 1.0 A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. | 9.8 |
2017-02-21 | CVE-2017-6070 | Cmsmadesimple | Information Exposure vulnerability in Cmsmadesimple CMS Made Simple and Form Builder CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to execute PHP code via the cntnt01fbrp_forma_form_template parameter in admin_store_form. | 9.8 |
2017-02-21 | CVE-2017-5959 | Metalgenix | Cross-Site Request Forgery (CSRF) vulnerability in Metalgenix Genixcms CSRF token bypass in GeniXCMS before 1.0.2 could result in escalation of privileges. | 9.8 |
2017-02-20 | CVE-2016-7663 | Apple | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 9.8 |
2017-02-20 | CVE-2016-7630 | Apple | 7PK - Security Features vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 9.8 |
2017-02-22 | CVE-2017-2684 | Siemens | Unspecified vulnerability in Siemens Simatic Logon 1.5 Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access to the affected system, to bypass the application-level authentication. | 9.0 |
127 High Vulnerabilities
100 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2017-02-20 | CVE-2016-7601 | Apple | 7PK - Security Features vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 6.8 |
2017-02-20 | CVE-2016-4781 | Apple | 7PK - Security Features vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 6.8 |
2017-02-20 | CVE-2016-4690 | Apple | Improper Input Validation vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 6.8 |
2017-02-21 | CVE-2015-4056 | Dell | Cryptographic Issues vulnerability in Dell VCE Vision Intelligent Operations 2.5/2.6/2.6.4 The System Library in VCE Vision Intelligent Operations before 2.6.5 does not properly implement cryptography, which makes it easier for local users to discover credentials by leveraging administrative access. | 6.7 |
2017-02-22 | CVE-2016-8986 | IBM | Improper Access Control vulnerability in IBM Websphere MQ IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using specially crafted HTTP requests. | 6.5 |
2017-02-22 | CVE-2016-8915 | IBM | Improper Access Control vulnerability in IBM Websphere MQ IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to other channels running under the same process. | 6.5 |
2017-02-22 | CVE-2016-3013 | IBM | Data Processing Errors vulnerability in IBM Websphere MQ IBM WebSphere MQ 8.0 could allow an authenticated user to crash the MQ channel due to improper data conversion handling. | 6.5 |
2017-02-22 | CVE-2016-9384 | XEN | Information Exposure vulnerability in XEN 4.7.0/4.7.1 Xen 4.7 allows local guest OS users to obtain sensitive host information by loading a 32-bit ELF symbol table. | 6.5 |
2017-02-20 | CVE-2017-2371 | Apple | Improper Input Validation vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 6.5 |
2017-02-20 | CVE-2017-2365 | Apple Webkitgtk | Information Exposure vulnerability in multiple products An issue was discovered in certain Apple products. | 6.5 |
2017-02-20 | CVE-2017-2364 | Apple | Information Exposure vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 6.5 |
2017-02-20 | CVE-2017-2363 | Apple Webkitgtk | Information Exposure vulnerability in multiple products An issue was discovered in certain Apple products. | 6.5 |
2017-02-20 | CVE-2017-2359 | Apple | Unspecified vulnerability in Apple Safari An issue was discovered in certain Apple products. | 6.5 |
2017-02-20 | CVE-2017-2350 | Apple Webkitgtk | Information Exposure vulnerability in multiple products An issue was discovered in certain Apple products. | 6.5 |
2017-02-20 | CVE-2016-7627 | Apple | NULL Pointer Dereference vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 6.5 |
2017-02-20 | CVE-2016-7623 | Apple | Information Exposure vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 6.5 |
2017-02-20 | CVE-2016-7599 | Apple | Information Exposure vulnerability in Apple products An issue was discovered in certain Apple products. | 6.5 |
2017-02-20 | CVE-2016-7598 | Apple | Information Exposure vulnerability in Apple products An issue was discovered in certain Apple products. | 6.5 |
2017-02-20 | CVE-2016-7591 | Apple | Use After Free vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 6.5 |
2017-02-20 | CVE-2016-7586 | Apple | Information Exposure vulnerability in Apple products An issue was discovered in certain Apple products. | 6.5 |
2017-02-20 | CVE-2016-7580 | Apple | Improper Input Validation vulnerability in Apple mac OS X An issue was discovered in certain Apple products. | 6.5 |
2017-02-20 | CVE-2016-4613 | Apple | Information Exposure vulnerability in Apple products An issue was discovered in certain Apple products. | 6.5 |
2017-02-20 | CVE-2016-7609 | Apple | NULL Pointer Dereference vulnerability in Apple mac OS X An issue was discovered in certain Apple products. | 6.2 |
2017-02-20 | CVE-2016-7600 | Apple | Information Exposure vulnerability in Apple mac OS X An issue was discovered in certain Apple products. | 6.2 |
2017-02-24 | CVE-2017-6099 | Paypal | Cross-site Scripting vulnerability in Paypal Merchant-Sdk-PHP 3.9.1 Cross-site scripting (XSS) vulnerability in GetAuthDetails.html.php in PayPal PHP Merchant SDK (aka merchant-sdk-php) 3.9.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter. | 6.1 |
2017-02-24 | CVE-2014-9916 | Bilboplanet | Cross-site Scripting vulnerability in Bilboplanet 2.0 Multiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) tribe_name or (2) tags parameter in a tribes page request to user/ or the (3) user_id or (4) fullname parameter to signup.php. | 6.1 |
2017-02-23 | CVE-2016-5883 | IBM | Cross-site Scripting vulnerability in IBM Inotes IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. | 6.1 |
2017-02-22 | CVE-2016-9910 | Html5Lib | Cross-site Scripting vulnerability in Html5Lib 0.99999999 The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of special characters in attribute values, a different vulnerability than CVE-2016-9909. | 6.1 |
2017-02-22 | CVE-2016-9909 | Html5Lib | Cross-site Scripting vulnerability in Html5Lib 0.99999999 The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of the < (less than) character in attribute values. | 6.1 |
2017-02-22 | CVE-2017-3845 | Cisco | Cross-site Scripting vulnerability in Cisco Prime Collaboration Assurance 11.0.0/11.1.0/11.5.0 A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. | 6.1 |
2017-02-22 | CVE-2017-3840 | Cisco | Open Redirect vulnerability in Cisco Secure Access Control System 5.8(2.5) A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect Vulnerability. | 6.1 |
2017-02-22 | CVE-2017-3838 | Cisco | Cross-site Scripting vulnerability in Cisco Secure Access Control System 5.8(2.5) A vulnerability in Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against the user of the web interface of the affected system. | 6.1 |
2017-02-22 | CVE-2017-3833 | Cisco | Cross-site Scripting vulnerability in Cisco Unified Communications Manager 12.0(0.99999.2) A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. | 6.1 |
2017-02-22 | CVE-2017-3829 | Cisco | Cross-site Scripting vulnerability in Cisco Unified Communications Manager 11.0(1.10000.10)/11.5(1.10000.6) A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. | 6.1 |
2017-02-22 | CVE-2017-3828 | Cisco | Cross-site Scripting vulnerability in Cisco Unified Communications Manager 11.0(1.10000.10)/11.5(1.10000.6) A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. | 6.1 |
2017-02-22 | CVE-2017-3821 | Cisco | Cross-site Scripting vulnerability in Cisco Unified Communications Manager 10.5(2.14076.1) A vulnerability in the serviceability page of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct reflected cross-site scripting (XSS) attacks. | 6.1 |
2017-02-20 | CVE-2017-2361 | Apple | Cross-site Scripting vulnerability in Apple mac OS X An issue was discovered in certain Apple products. | 6.1 |
2017-02-20 | CVE-2016-7762 | Apple | Cross-site Scripting vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 6.1 |
2017-02-22 | CVE-2016-3052 | IBM | Information Exposure vulnerability in IBM Websphere MQ Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network. | 5.9 |
2017-02-20 | CVE-2016-7636 | Apple | Improper Input Validation vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 5.9 |
2017-02-20 | CVE-2016-7579 | Apple | Information Exposure vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 5.9 |
2017-02-20 | CVE-2016-4721 | Apple | 7PK - Security Features vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 5.9 |
2017-02-20 | CVE-2016-4685 | Apple | Inadequate Encryption Strength vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 5.9 |
2017-02-22 | CVE-2017-3827 | Cisco | Improper Input Validation vulnerability in Cisco products A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device. | 5.8 |
2017-02-24 | CVE-2016-5027 | Libdwarf Project | NULL Pointer Dereference vulnerability in Libdwarf Project Libdwarf 20160115 dwarf_form.c in libdwarf 20160115 allows remote attackers to cause a denial of service (crash) via a crafted elf file. | 5.5 |
2017-02-24 | CVE-2016-4493 | GNU | Out-of-bounds Read vulnerability in GNU Libiberty The demangle_template_value_parm and do_hpacc_template_literal functions in cplus-dem.c in libiberty allow remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted binary. | 5.5 |
2017-02-24 | CVE-2016-4491 | GNU | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Libiberty The d_print_comp function in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, which triggers infinite recursion and a buffer overflow, related to a node having "itself as ancestor more than once." | 5.5 |
2017-02-24 | CVE-2016-4490 | GNU | Integer Overflow or Wraparound vulnerability in GNU Libiberty Integer overflow in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to inconsistent use of the long and int types for lengths. | 5.5 |
2017-02-24 | CVE-2016-4489 | GNU | Integer Overflow or Wraparound vulnerability in GNU Libiberty Integer overflow in the gnu_special function in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to the "demangling of virtual tables." | 5.5 |
2017-02-24 | CVE-2016-4488 | GNU | Use After Free vulnerability in GNU Libiberty Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "ktypevec." | 5.5 |
2017-02-24 | CVE-2016-4487 | GNU | Use After Free vulnerability in GNU Libiberty Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "btypevec." | 5.5 |
2017-02-24 | CVE-2017-6299 | Ytnef Project Debian | Infinite Loop vulnerability in multiple products An issue was discovered in ytnef before 1.9.1. | 5.5 |
2017-02-24 | CVE-2017-6197 | Radare | NULL Pointer Dereference vulnerability in Radare Radare2 1.2.1 The r_read_* functions in libr/include/r_endian.h in radare2 1.2.1 allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by the r_read_le32 function. | 5.5 |
2017-02-24 | CVE-2017-6076 | Wolfssl | Information Exposure vulnerability in Wolfssl In versions of wolfSSL before 3.10.2 the function fp_mul_comba makes it easier to extract RSA key information for a malicious user who has access to view cache on a machine. | 5.5 |
2017-02-22 | CVE-2017-6188 | Munin Monitoring Debian | Improper Input Validation vulnerability in multiple products Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. | 5.5 |
2017-02-22 | CVE-2016-9378 | XEN | Improper Access Control vulnerability in XEN Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging an incorrect choice for software interrupt delivery. | 5.5 |
2017-02-22 | CVE-2016-9377 | XEN | Incorrect Calculation vulnerability in XEN Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation. | 5.5 |
2017-02-21 | CVE-2017-6078 | Faststone | Improper Input Validation vulnerability in Faststone Maxview 3.0/3.1 FastStone MaxView 3.0 and 3.1 allows user-assisted attackers to cause a denial of service (application crash) via a malformed BMP image with a crafted biSize field in the BITMAPINFOHEADER section. | 5.5 |
2017-02-20 | CVE-2017-0038 | Microsoft | Information Exposure vulnerability in Microsoft products gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process heap memory via a crafted EMF file, as demonstrated by an EMR_SETDIBITSTODEVICE record with modified Device Independent Bitmap (DIB) dimensions. | 5.5 |
2017-02-20 | CVE-2017-2368 | Apple | Improper Input Validation vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 5.5 |
2017-02-20 | CVE-2016-7761 | Apple | Information Exposure vulnerability in Apple mac OS X An issue was discovered in certain Apple products. | 5.5 |
2017-02-20 | CVE-2016-7666 | Apple | Information Exposure vulnerability in Apple Transporter 1.9.1 An issue was discovered in certain Apple products. | 5.5 |
2017-02-20 | CVE-2016-7665 | Apple | Improper Input Validation vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 5.5 |
2017-02-20 | CVE-2016-7628 | Apple | Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X An issue was discovered in certain Apple products. | 5.5 |
2017-02-20 | CVE-2016-7619 | Apple | Link Following vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 5.5 |
2017-02-20 | CVE-2016-7615 | Apple | Unspecified vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 5.5 |
2017-02-20 | CVE-2016-7614 | Apple | Information Exposure vulnerability in Apple Icloud An issue was discovered in certain Apple products. | 5.5 |
2017-02-20 | CVE-2016-7608 | Apple | Information Exposure vulnerability in Apple mac OS X An issue was discovered in certain Apple products. | 5.5 |
2017-02-20 | CVE-2016-7607 | Apple | Information Exposure vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 5.5 |
2017-02-20 | CVE-2016-7605 | Apple | NULL Pointer Dereference vulnerability in Apple mac OS X An issue was discovered in certain Apple products. | 5.5 |
2017-02-20 | CVE-2016-7604 | Apple | NULL Pointer Dereference vulnerability in Apple mac OS X An issue was discovered in certain Apple products. | 5.5 |
2017-02-20 | CVE-2016-7603 | Apple | NULL Pointer Dereference vulnerability in Apple mac OS X An issue was discovered in certain Apple products. | 5.5 |
2017-02-20 | CVE-2016-4680 | Apple | Information Exposure vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 5.5 |
2017-02-20 | CVE-2016-4679 | Apple | Link Following vulnerability in Apple products An issue was discovered in certain Apple products. | 5.5 |
2017-02-20 | CVE-2016-4663 | Apple | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X An issue was discovered in certain Apple products. | 5.5 |
2017-02-20 | CVE-2016-4661 | Apple | Improper Input Validation vulnerability in Apple mac OS X An issue was discovered in certain Apple products. | 5.5 |
2017-02-23 | CVE-2016-6055 | IBM | Cross-site Scripting vulnerability in IBM products IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. | 5.4 |
2017-02-22 | CVE-2017-3847 | Cisco | Cross-site Scripting vulnerability in Cisco Secure Firewall Management Center 6.2.1 A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. | 5.4 |
2017-02-21 | CVE-2016-9316 | Trendmicro | Cross-site Scripting vulnerability in Trendmicro Interscan web Security Virtual Appliance Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allow authenticated, remote users with least privileges to inject arbitrary HTML/JavaScript code into web pages. | 5.4 |
2017-02-24 | CVE-2016-4042 | Plone | Information Exposure vulnerability in Plone Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ID of sensitive content via unspecified vectors. | 5.3 |
2017-02-22 | CVE-2017-3842 | Cisco | Information Exposure vulnerability in Cisco Intrusion Prevention System Device Manager 7.2(1)V7 A vulnerability in the web-based management interface of the Cisco Intrusion Prevention System Device Manager (IDM) could allow an unauthenticated, remote attacker to view sensitive information stored in certain HTML comments. | 5.3 |
2017-02-21 | CVE-2017-6072 | Cmsmadesimple | Information Exposure vulnerability in Cmsmadesimple CMS Made Simple and Form Builder CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via defaultadmin. | 5.3 |
2017-02-21 | CVE-2017-6071 | Cmsmadesimple | Information Exposure vulnerability in Cmsmadesimple CMS Made Simple and Form Builder CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml. | 5.3 |
2017-02-20 | CVE-2016-6249 | F5 | Information Exposure vulnerability in F5 products F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext to /var/log/restjavad.0.log. | 5.3 |
2017-02-20 | CVE-2016-7651 | Apple | Improper Authorization vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 5.3 |
2017-02-24 | CVE-2016-4043 | Plone | Permissions, Privileges, and Access Controls vulnerability in Plone Chameleon (five.pt) in Plone 5.0rc1 through 5.1a1 allows remote authenticated users to bypass Restricted Python by leveraging permissions to create or edit templates. | 4.9 |
2017-02-20 | CVE-2016-7650 | Apple | Cross-site Scripting vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 4.7 |
2017-02-20 | CVE-2017-2352 | Apple | Unspecified vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 4.6 |
2017-02-20 | CVE-2016-7638 | Apple | 7PK - Security Features vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 4.6 |
2017-02-20 | CVE-2016-7634 | Apple | Information Exposure vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 4.6 |
2017-02-20 | CVE-2016-7597 | Apple | 7PK - Security Features vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 4.6 |
2017-02-24 | CVE-2016-4492 | GNU | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Libiberty Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary. | 4.4 |
2017-02-20 | CVE-2016-4686 | Apple | Permissions, Privileges, and Access Controls vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 4.4 |
2017-02-22 | CVE-2017-3844 | Cisco | Improper Input Validation vulnerability in Cisco Prime Collaboration Assurance 11.0.0/11.1.0/11.5.0 A vulnerability in exporting functions of the user interface for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to view file directory listings and download files. | 4.3 |
2017-02-22 | CVE-2017-3843 | Cisco | Improper Input Validation vulnerability in Cisco Prime Collaboration Assurance 11.0.0/11.1.0/11.5.0 A vulnerability in the file download functions for Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to download system files that should be restricted. | 4.3 |
2017-02-22 | CVE-2017-3839 | Cisco | XXE vulnerability in Cisco Secure Access Control System 5.8(2.5) An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to have read access to part of the information stored in the affected system. | 4.3 |
2017-02-22 | CVE-2017-3836 | Cisco | Information Exposure vulnerability in Cisco Unified Communications Manager 11.5(1.11007.2) A vulnerability in the web framework Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitive data. | 4.3 |
2017-02-20 | CVE-2016-7759 | Apple | Information Exposure vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 4.3 |
2017-02-20 | CVE-2016-7592 | Apple | Information Exposure vulnerability in Apple products An issue was discovered in certain Apple products. | 4.3 |
2017-02-20 | CVE-2016-7581 | Apple | Improper Input Validation vulnerability in Apple Iphone OS An issue was discovered in certain Apple products. | 4.3 |