Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-02-02 CVE-2017-5727 NULL Pointer Dereference vulnerability in Intel Graphics Driver
Pointer dereference in subsystem in Intel Graphics Driver 15.40.x.x, 15.45.x.x, 15.46.x.x allows unprivileged user to elevate privileges via local access.
local
low complexity
intel CWE-476
7.8
2018-02-02 CVE-2017-18122 Improper Verification of Cryptographic Signature vulnerability in multiple products
A signature-validation bypass issue was discovered in SimpleSAMLphp through 1.14.16.
network
high complexity
simplesamlphp debian CWE-347
8.1
2018-02-02 CVE-2018-6560 Interpretation Conflict vulnerability in multiple products
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.
local
low complexity
flatpak redhat CWE-436
8.8
2018-02-02 CVE-2017-18080 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Bamboo
The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site request forgery (CSRF) vulnerability.
network
low complexity
atlassian CWE-352
8.8
2018-02-02 CVE-2017-18042 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Bamboo
The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability.
network
low complexity
atlassian CWE-352
8.8
2018-02-02 CVE-2017-14180 Resource Exhaustion vulnerability in multiple products
Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges, a different vulnerability than CVE-2017-14179.
local
low complexity
apport-project canonical CWE-400
7.8
2018-02-02 CVE-2017-14179 Resource Exhaustion vulnerability in multiple products
Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root privileges, or escape from containers.
local
low complexity
apport-project canonical CWE-400
7.8
2018-02-02 CVE-2017-14178 Improper Handling of Exceptional Conditions vulnerability in Snapcraft Snapd
In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and therefore allow unprivileged, unauthenticated users to bypass systemd-journald's access restrictions.
network
low complexity
snapcraft CWE-755
7.5
2018-02-02 CVE-2017-14177 Resource Exhaustion vulnerability in multiple products
Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges.
local
low complexity
apport-project canonical CWE-400
7.8
2018-02-02 CVE-2018-6543 Integer Overflow or Wraparound vulnerability in GNU Binutils 2.30
In GNU Binutils 2.30, there's an integer overflow in the function load_specific_debug_section() in objdump.c, which results in `malloc()` with 0 size.
local
low complexity
gnu CWE-190
7.8