Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-08-07 CVE-2015-7705 Improper Input Validation vulnerability in multiple products
The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.
network
low complexity
ntp netapp citrix siemens CWE-20
7.5
2017-08-07 CVE-2015-5244 Permissions, Privileges, and Access Controls vulnerability in MOD NSS Project MOD NSS
The NSSCipherSuite option with ciphersuites enabled in mod_nss before 1.0.12 allows remote attackers to bypass application restrictions.
network
low complexity
mod-nss-project CWE-264
7.5
2017-08-07 CVE-2017-12650 SQL Injection vulnerability in Loginizer
SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.
network
low complexity
loginizer CWE-89
7.5
2017-08-07 CVE-2017-12567 SQL Injection vulnerability in Quest products
SQL injection exists in Quest KACE Asset Management Appliance 6.4.120822 through 7.2, Systems Management Appliance 6.4.120822 through 7.2.101, and K1000 as a Service 7.0 through 7.2.
network
low complexity
quest CWE-89
7.5
2017-08-07 CVE-2017-9801 Improper Input Validation vulnerability in Apache Commons Email
When a call-site passes a subject for an email that contains line-breaks in Apache Commons Email 1.0 through 1.4, the caller can add arbitrary SMTP headers.
network
low complexity
apache CWE-20
7.5
2017-08-07 CVE-2017-12643 Allocation of Resources Without Limits or Throttling vulnerability in Imagemagick 7.0.61
ImageMagick 7.0.6-1 has a memory exhaustion vulnerability in ReadOneJNGImage in coders\png.c.
7.1
2017-08-07 CVE-2017-9647 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Infineon S-Gold 2 PMB 8876
A Stack-Based Buffer Overflow issue was discovered in the Continental AG Infineon S-Gold 2 (PMB 8876) chipset on BMW several models produced between 2009-2010, Ford a limited number of P-HEV vehicles, Infiniti 2013 JX35, Infiniti 2014-2016 QX60, Infiniti 2014-2016 QX60 Hybrid, Infiniti 2014-2015 QX50, Infiniti 2014-2015 QX50 Hybrid, Infiniti 2013 M37/M56, Infiniti 2014-2016 Q70, Infiniti 2014-2016 Q70L, Infiniti 2015-2016 Q70 Hybrid, Infiniti 2013 QX56, Infiniti 2014-2016 QX 80, and Nissan 2011-2015 Leaf.
local
low complexity
infineon CWE-119
7.2
2017-08-07 CVE-2017-9633 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Infineon S-Gold 2 PMB 8876
An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in the Continental AG Infineon S-Gold 2 (PMB 8876) chipset on BMW several models produced between 2009-2010, Ford a limited number of P-HEV vehicles, Infiniti 2013 JX35, Infiniti 2014-2016 QX60, Infiniti 2014-2016 QX60 Hybrid, Infiniti 2014-2015 QX50, Infiniti 2014-2015 QX50 Hybrid, Infiniti 2013 M37/M56, Infiniti 2014-2016 Q70, Infiniti 2014-2016 Q70L, Infiniti 2015-2016 Q70 Hybrid, Infiniti 2013 QX56, Infiniti 2014-2016 QX 80, and Nissan 2011-2015 Leaf.
low complexity
infineon CWE-119
8.3
2017-08-07 CVE-2017-9630 Improper Authentication vulnerability in Pdqinc products
An Improper Authentication issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash 360 and 360 Plus, all versions, LaserWash AutoXpress and AutoExpress Plus, all versions, LaserJet, all versions, ProTouch Tandem, all versions, ProTouch ICON, all versions, and ProTouch AutoGloss, all versions.
network
low complexity
pdqinc CWE-287
7.5
2017-08-07 CVE-2017-7928 Unspecified vulnerability in Selinc Sel-3620 Firmware and Sel-3622 Firmware
An Improper Access Control issue was discovered in Schweitzer Engineering Laboratories (SEL) SEL-3620 and SEL-3622 Security Gateway Versions R202 and, R203, R203-V1, R203-V2 and, R204, R204-V1.
network
low complexity
selinc
7.5