Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-08-17 CVE-2017-7555 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Augeas
Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings.
network
low complexity
augeas CWE-119
7.5
2017-08-16 CVE-2017-7548 PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on a large object to overwrite the entire contents of the object, resulting in a denial of service.
network
low complexity
postgresql debian
7.5
2017-08-16 CVE-2017-7546 Improper Authentication vulnerability in multiple products
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.
network
low complexity
postgresql debian CWE-287
7.5
2017-08-16 CVE-2016-5867 Permissions, Privileges, and Access Controls vulnerability in Google Android
In a sound driver in Android for MSM, Firefox OS for MSM, QRD Android, some variables are from userspace and values can be chosen that could result in stack overflow.
network
high complexity
google CWE-264
7.6
2017-08-16 CVE-2016-5862 Permissions, Privileges, and Access Controls vulnerability in Google Android
When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, the type casting is done to the container structure instead of the codec's individual structure, resulting in a device restart after kernel crash occurs.
network
high complexity
google CWE-264
7.6
2017-08-16 CVE-2016-5861 Permissions, Privileges, and Access Controls vulnerability in Google Android
In a display driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a variable controlled by userspace is used to calculate offsets and sizes for copy operations, which could result in heap overflow.
low complexity
google CWE-264
8.3
2017-08-16 CVE-2016-5860 Permissions, Privileges, and Access Controls vulnerability in Google Android
In an audio driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is called with a very large length, an integer overflow could occur followed by a heap buffer overflow.
network
high complexity
google CWE-264
7.6
2017-08-16 CVE-2016-5859 Permissions, Privileges, and Access Controls vulnerability in Google Android
In a sound driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is called with a very large length, an integer overflow could occur followed by a buffer overflow.
network
high complexity
google CWE-264
7.6
2017-08-16 CVE-2016-5853 Permissions, Privileges, and Access Controls vulnerability in Google Android
In an audio driver in all Qualcomm products with Android releases from CAF using the Linux kernel, when a sanity check encounters a length value not in the correct range, an error message is printed, but code execution continues in the same way as for a correct length value.
network
high complexity
google CWE-264
7.6
2017-08-15 CVE-2017-8665 Incorrect Permission Assignment for Critical Resource vulnerability in Microsoft Xamarin.Ios 10.11
The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin.iOS Elevation Of Privilege Vulnerability."
local
low complexity
microsoft CWE-732
7.2