Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-03-18 CVE-2016-10253 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Erlang Erlang/Otp
An issue was discovered in Erlang/OTP 18.x.
network
low complexity
erlang CWE-119
critical
9.8
2017-03-17 CVE-2017-7174 Unspecified vulnerability in Chef Manage Project Chef Manage
The user-account creation feature in Chef Manage 2.1.0 through 2.4.4 allows remote attackers to execute arbitrary code.
network
low complexity
chef-manage-project
critical
9.8
2017-03-17 CVE-2017-3881 Improper Input Validation vulnerability in Cisco IOS
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.
network
low complexity
cisco CWE-20
critical
9.8
2017-03-17 CVE-2017-6880 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cerberus FTP Server 8.0.10.3
Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long MLST command.
network
low complexity
cerberus CWE-119
critical
9.8
2017-03-17 CVE-2014-9852 Improper Control of Dynamically-Managed Code Resources vulnerability in multiple products
distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact via unspecified vectors.
network
low complexity
imagemagick suse opensuse CWE-913
critical
9.8
2017-03-17 CVE-2014-8708 Permissions, Privileges, and Access Controls vulnerability in Pluck-Cms Pluck 4.7.2
Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.
network
low complexity
pluck-cms CWE-264
critical
9.8
2017-03-17 CVE-2014-8705 Improper Input Validation vulnerability in Wondercms 2014
PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URL in the hook parameter.
network
low complexity
wondercms CWE-20
critical
9.8
2017-03-17 CVE-2014-8704 Path Traversal vulnerability in Wondercms 2014
Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via a crafted theme.
network
low complexity
wondercms CWE-22
critical
9.8
2017-03-17 CVE-2017-6969 Out-of-bounds Read vulnerability in GNU Binutils 2.28
readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries.
network
low complexity
gnu CWE-125
critical
9.1
2017-03-17 CVE-2017-0021 Unspecified vulnerability in Microsoft Windows 10 and Windows Server 2016
Hyper-V in Microsoft Windows 10 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary code on a target OS, aka "Hyper-V System Data Structure Vulnerability." This vulnerability is different from that described in CVE-2017-0095.
low complexity
microsoft
critical
9.0