Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-03-12 CVE-2017-5624 Improper Privilege Management vulnerability in Oneplus Oxygenos 3.2.8/3.5.4/4.0.2
An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T.
network
low complexity
oneplus CWE-269
critical
9.8
2017-03-11 CVE-2017-6513 Permission Issues vulnerability in Softaculous Whmcs Reseller Module 2.0.2
The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which allows remote authenticated users to control other virtual machines managed by Virtualizor by accessing a modified URL.
network
low complexity
softaculous CWE-275
critical
9.9
2017-03-11 CVE-2017-5638 Improper Handling of Exceptional Conditions vulnerability in multiple products
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
network
low complexity
apache ibm lenovo hp oracle arubanetworks netapp CWE-755
critical
9.8
2017-03-10 CVE-2017-6506 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Azure DEX Data Expert Ultimate 2.2.16
In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution.
network
low complexity
azure-dex CWE-119
critical
9.8
2017-03-10 CVE-2017-5859 Unspecified vulnerability in Cambiumnetworks Cnpilot R200 Series Firmware 4.2
On Cambium Networks cnPilot R200/201 devices before 4.3, there is a vulnerability involving the certificate of the device and its RSA keys, aka RBN-183.
network
low complexity
cambiumnetworks
critical
9.8
2017-03-10 CVE-2017-2788 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Pharos Popup 9.0
A buffer overflows exists in the psnotifyd application of the Pharos PopUp printer client version 9.0.
network
low complexity
pharos CWE-119
critical
10.0
2017-03-10 CVE-2017-2787 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Pharos Popup 9.0
A buffer overflows exists in the psnotifyd application of the Pharos PopUp printer client version 9.0.
network
high complexity
pharos CWE-119
critical
9.0
2017-03-10 CVE-2017-2785 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Pharos Popup 9.0
An exploitable buffer overflow exists in the psnotifyd application of the Pharos PopUp printer client version 9.0.
network
low complexity
pharos CWE-119
critical
10.0
2017-03-10 CVE-2017-6465 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ftpshell Client 6.53
Remote Code Execution was discovered in FTPShell Client 6.53.
network
low complexity
ftpshell CWE-119
critical
9.8
2017-03-09 CVE-2017-6526 Improper Authentication vulnerability in Dnatools Dnalims 42015S13
An issue was discovered in dnaTools dnaLIMS 4-2015s13.
network
low complexity
dnatools CWE-287
critical
9.8