Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-11-07 CVE-2017-2898 Race Condition vulnerability in Meetcircle Circle With Disney Firmware 2.0.1
An exploitable vulnerability exists in the signature verification of the firmware update functionality of Circle with Disney.
network
high complexity
meetcircle CWE-362
7.5
2017-11-07 CVE-2017-2895 Out-of-bounds Read vulnerability in Cesanta Mongoose 6.8
An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.
network
low complexity
cesanta CWE-125
8.2
2017-11-07 CVE-2017-2893 NULL Pointer Dereference vulnerability in Cesanta Mongoose 6.8
An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8.
network
low complexity
cesanta CWE-476
7.5
2017-11-07 CVE-2017-2890 OS Command Injection vulnerability in Meetcircle Circle With Disney Firmware 2.0.1
An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1.
network
low complexity
meetcircle CWE-78
8.8
2017-11-07 CVE-2017-2889 Resource Exhaustion vulnerability in Meetcircle Circle With Disney Firmware 2.0.1
An exploitable Denial of Service vulnerability exists in the API daemon of Circle with Disney running firmware 2.0.1.
network
low complexity
meetcircle CWE-400
7.5
2017-11-07 CVE-2017-2884 Resource Exhaustion vulnerability in Meetcircle Circle With Disney Firmware 2.0.1
An exploitable vulnerability exists in the user photo update functionality of Circle with Disney running firmware 2.0.1.
network
low complexity
meetcircle CWE-400
7.5
2017-11-07 CVE-2017-2883 Unspecified vulnerability in Meetcircle Circle With Disney Firmware 2.0.1
An exploitable vulnerability exists in the database update functionality of Circle with Disney running firmware 2.0.1.
network
high complexity
meetcircle
8.1
2017-11-07 CVE-2017-2882 Unspecified vulnerability in Meetcircle Circle With Disney Firmware 2.0.1
An exploitable vulnerability exists in the servers update functionality of Circle with Disney running firmware 2.0.1.
network
high complexity
meetcircle
8.1
2017-11-07 CVE-2017-2881 Unspecified vulnerability in Meetcircle Circle With Disney Firmware 2.0.1
An exploitable vulnerability exists in the torlist update functionality of Circle with Disney running firmware 2.0.1.
low complexity
meetcircle
8.8
2017-11-07 CVE-2017-2866 OS Command Injection vulnerability in Meetcircle Circle With Disney Firmware 2.0.1
An exploitable vulnerability exists in the /api/CONFIG/backup functionality of Circle with Disney.
network
low complexity
meetcircle CWE-78
8.8