Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-10-19 CVE-2017-15647 Path Traversal vulnerability in Fiberhome Routerfiberhome Firmware
On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value.
network
low complexity
fiberhome CWE-22
7.5
2017-10-19 CVE-2017-15645 Cross-Site Request Forgery (CSRF) vulnerability in Webmin
CSRF exists in Webmin 1.850.
network
low complexity
webmin CWE-352
8.8
2017-10-19 CVE-2017-15644 Server-Side Request Forgery (SSRF) vulnerability in Webmin
SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.
network
low complexity
webmin CWE-918
8.6
2017-10-19 CVE-2017-15643 HTTP Request Smuggling vulnerability in Ikarussecurity Ikarus Antivirus 2.16.7
An active network attacker (MiTM) can achieve remote code execution on a machine that runs IKARUS Anti Virus 2.16.7.
local
high complexity
ikarussecurity CWE-444
7.4
2017-10-19 CVE-2017-10933 Path Traversal vulnerability in ZTE Zxdt22 Sf01 Firmware V2.06.00.00
All versions prior to V2.06.00.00 of ZTE ZXDT22 SF01, an monitoring system of ZTE energy product, are impacted by directory traversal vulnerability that allows remote attackers to read arbitrary files on the system via a full path name after host address.
network
low complexity
zte CWE-22
7.5
2017-10-19 CVE-2015-6668 Information Exposure vulnerability in Wp-Jobmanager JOB Manager
The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object reference.
network
low complexity
wp-jobmanager CWE-200
7.5
2017-10-19 CVE-2015-4422 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei Mate 7 Firmware
The TEEOS module in Huawei Mate 7 (Mate7-TL10) smartphones before V100R001CHNC00B126SP03 allows local users with root permissions to gain privileges or cause a denial of service (memory corruption) via a crafted application.
local
high complexity
huawei CWE-119
7.0
2017-10-19 CVE-2015-4421 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei Mate 7 Firmware
The tzdriver module in Huawei Mate 7 (Mate7-TL10) smartphones before V100R001CHNC00B126SP03 allows local users to gain privileges or cause a denial of service (memory corruption) via an unspecified input.
network
high complexity
huawei CWE-119
7.5
2017-10-19 CVE-2012-4380 Improper Access Control vulnerability in Mediawiki
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address blocking and create an account via unspecified vectors.
network
low complexity
mediawiki CWE-284
7.5
2017-10-19 CVE-2017-5635 Improper Authentication vulnerability in Apache Nifi
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originating node identity is used rather than the "anonymous" user.
network
low complexity
apache CWE-287
7.5