Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-03-30 CVE-2018-7566 Race Condition vulnerability in multiple products
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
local
low complexity
linux suse canonical debian redhat oracle CWE-362
7.8
2018-03-30 CVE-2018-7171 Path Traversal vulnerability in Lynxtechnology Twonky Server
Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a ..
network
low complexity
lynxtechnology CWE-22
7.5
2018-03-30 CVE-2018-5708 Insufficiently Protected Credentials vulnerability in Dlink Dir-601 Firmware 2.02Na
An issue was discovered on D-Link DIR-601 B1 2.02NA devices.
low complexity
dlink CWE-522
8.0
2018-03-30 CVE-2018-1232 Out-of-bounds Write vulnerability in RSA Authentication Agent for web 8.0/8.0.1
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow which may occur when handling certain malicious web cookies that have invalid formats.
network
low complexity
rsa CWE-787
7.5
2018-03-30 CVE-2017-9723 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
The touchscreen driver synaptics_dsx in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-05, the size of a stack-allocated buffer can be set to a value which exceeds the size of the stack.
local
low complexity
google CWE-119
7.8
2018-03-30 CVE-2017-9694 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qcacld 2.0 Project Qcacld 2.0
While parsing Netlink attributes in QCA_WLAN_VENDOR_ATTR_EXTSCAN_BSSID_HOTLIST_PARAMS_LOST_AP_SAMPLE_SIZE in qcacld 2.0 before 2017-05-16, a buffer overread could occur.
local
low complexity
qcacld-2-0-project CWE-119
7.8
2018-03-30 CVE-2017-9692 NULL Pointer Dereference vulnerability in Google Android
When an atomic commit is issued on a writeback panel with a NULL output_layer parameter in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-03, a NULL pointer dereference may potentially occur.
local
low complexity
google CWE-476
7.8
2018-03-30 CVE-2017-17771 Classic Buffer Overflow vulnerability in Google Android
In msm_isp_prepare_v4l2_buf in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-02-12, an array out of bounds can occur.
local
low complexity
google CWE-120
7.8
2018-03-30 CVE-2017-15859 Out-of-bounds Write vulnerability in Google Android
While processing the QCA_NL80211_VENDOR_SUBCMD_SET_TXPOWER_SCALE_DECR_DB vendor command, in which attribute QCA_WLAN_VENDOR_ATTR_TXPOWER_SCALE_DECR_DB contains fewer than 1 byte, in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-08-11 a buffer overrun occurs.
network
low complexity
google CWE-787
7.5
2018-03-30 CVE-2017-15852 Information Exposure vulnerability in Google Android
Information leak of the ISPIF base address in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the camera driver.
local
low complexity
google CWE-200
7.8