Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-06-04 CVE-2018-11697 Out-of-bounds Read vulnerability in Sass-Lang Libsass
An issue was discovered in LibSass through 3.5.4.
network
low complexity
sass-lang CWE-125
8.1
2018-06-04 CVE-2018-11696 NULL Pointer Dereference vulnerability in Sass-Lang Libsass
An issue was discovered in LibSass through 3.5.4.
network
low complexity
sass-lang CWE-476
8.8
2018-06-04 CVE-2018-11695 NULL Pointer Dereference vulnerability in Sass-Lang Libsass
An issue was discovered in LibSass <3.5.3.
network
low complexity
sass-lang CWE-476
8.8
2018-06-04 CVE-2018-11694 NULL Pointer Dereference vulnerability in Sass-Lang Libsass
An issue was discovered in LibSass through 3.5.4.
network
low complexity
sass-lang CWE-476
8.8
2018-06-04 CVE-2018-11693 Out-of-bounds Read vulnerability in Sass-Lang Libsass
An issue was discovered in LibSass through 3.5.4.
network
low complexity
sass-lang CWE-125
8.1
2018-06-04 CVE-2018-11685 Out-of-bounds Write vulnerability in multiple products
Liblouis 3.5.0 has a stack-based Buffer Overflow in the function compileHyphenation in compileTranslationTable.c.
network
low complexity
liblouis canonical opensuse CWE-787
8.8
2018-06-04 CVE-2018-11684 Out-of-bounds Write vulnerability in multiple products
Liblouis 3.5.0 has a stack-based Buffer Overflow in the function includeFile in compileTranslationTable.c.
network
low complexity
liblouis canonical opensuse CWE-787
8.8
2018-06-04 CVE-2018-11683 Out-of-bounds Write vulnerability in multiple products
Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440.
network
low complexity
liblouis canonical opensuse CWE-787
8.8
2018-06-04 CVE-2017-18285 Incorrect Permission Assignment for Critical Resource vulnerability in Burp Project Burp
The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain read and write access to arbitrary files by leveraging access to a certain account for a burp-server.conf change.
local
low complexity
burp-project CWE-732
7.1
2018-06-04 CVE-2017-18284 Incorrect Permission Assignment for Critical Resource vulnerability in Burp Project Burp
The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL.
local
low complexity
burp-project CWE-732
7.1