Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-03-22 CVE-2017-7226 Out-of-bounds Read vulnerability in GNU Binutils 2.28
The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-based buffer over-read of size 4049 because it uses the strlen function instead of strnlen, leading to program crashes in several utilities such as addr2line, size, and strings.
network
low complexity
gnu CWE-125
critical
9.1
2017-03-21 CVE-2017-7214 Information Exposure Through Log Files vulnerability in Openstack Nova
An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1.
network
low complexity
openstack CWE-532
critical
9.8
2017-03-21 CVE-2014-9939 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Binutils
ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.
network
low complexity
gnu CWE-119
critical
9.8
2017-03-20 CVE-2016-4926 Improper Authentication vulnerability in Juniper Junos Space
Insufficient authentication vulnerability in Junos Space before 15.2R2 allows remote network based users with access to Junos Space web interface to perform certain administrative tasks without authentication.
network
low complexity
juniper CWE-287
critical
9.8
2017-03-20 CVE-2017-6550 SQL Injection vulnerability in Kinsey Infor-Lawson
Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitrary SQL commands via the (1) TABLE parameter to esbus/servlet/GetSQLData or (2) QUERY parameter to KK_LS9ReportingPortal/GetData.
network
low complexity
kinsey CWE-89
critical
9.8
2017-03-20 CVE-2015-8954 Permissions, Privileges, and Access Controls vulnerability in Openinfosecfoundation Suricata
The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functionality via a crafted HTTP request.
network
low complexity
openinfosecfoundation CWE-264
critical
9.8
2017-03-20 CVE-2014-9847 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
network
low complexity
opensuse-project opensuse canonical imagemagick CWE-119
critical
9.8
2017-03-20 CVE-2014-9846 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
network
low complexity
opensuse-project suse opensuse canonical imagemagick CWE-119
critical
9.8
2017-03-20 CVE-2014-9843 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
network
low complexity
opensuse-project opensuse canonical imagemagick CWE-119
critical
9.8
2017-03-20 CVE-2014-9841 7PK - Errors vulnerability in multiple products
The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions."
network
low complexity
opensuse-project opensuse canonical imagemagick CWE-388
critical
9.8