Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-08-25 CVE-2015-4017 Improper Certificate Validation vulnerability in Saltstack Salt 2014.7.5
Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.
network
low complexity
saltstack CWE-295
7.5
2017-08-25 CVE-2015-1395 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a ..
network
low complexity
fedoraproject canonical gnu CWE-22
7.8
2017-08-25 CVE-2015-1324 Permissions, Privileges, and Access Controls vulnerability in Canonical Ubuntu Linux
Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubuntu 12.04 LTS allow local users to write to arbitrary files and gain root privileges by leveraging incorrect handling of permissions when generating core dumps for setuid binaries.
local
low complexity
canonical CWE-264
7.2
2017-08-25 CVE-2014-9637 Resource Management Errors vulnerability in multiple products
GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
7.1
2017-08-24 CVE-2017-13686 NULL Pointer Dereference vulnerability in Linux Kernel 4.13
net/ipv4/route.c in the Linux kernel 4.13-rc1 through 4.13-rc6 is too late to check for a NULL fi field when RTM_F_FIB_MATCH is set, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via crafted system calls.
local
low complexity
linux CWE-476
7.2
2017-08-24 CVE-2015-7516 NULL Pointer Dereference vulnerability in Onosproject Onos
ONOS before 1.5.0 when using the ifwd app allows remote attackers to cause a denial of service (NULL pointer dereference and switch disconnect) by sending two Ethernet frames with ether_type Jumbo Frame (0x8870).
network
low complexity
onosproject CWE-476
7.8
2017-08-24 CVE-2015-7257 Weak Password Recovery Mechanism for Forgotten Password vulnerability in ZTE Zxv10 W300 Firmware W300V2.1.0Fer7Peo57/W300V2.1.0Her7Peo57
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from "support" to "admin".
network
zte CWE-640
8.5
2017-08-24 CVE-2017-13669 SQL Injection vulnerability in Nexusphp 1.5
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php.
network
low complexity
nexusphp CWE-89
7.5
2017-08-24 CVE-2017-12679 SQL Injection vulnerability in Nexusphp 1.5
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php.
network
low complexity
nexusphp CWE-89
7.5
2017-08-24 CVE-2017-12137 Classic Buffer Overflow vulnerability in multiple products
arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.
local
low complexity
xen citrix debian CWE-120
7.2