Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-10-18 CVE-2017-15590 Unspecified vulnerability in XEN 4.9.0
An issue was discovered in Xen through 4.9.x allowing x86 guest OS users to cause a denial of service (hypervisor crash) or possibly gain privileges because MSI mapping was mishandled.
local
low complexity
xen
8.8
2017-10-18 CVE-2017-15588 Race Condition vulnerability in XEN 4.9.0
An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to execute arbitrary code on the host OS because of a race condition that can cause a stale TLB entry.
local
high complexity
xen CWE-362
7.8
2017-10-18 CVE-2017-15587 Integer Overflow or Wraparound vulnerability in Artifex Mupdf 1.11
An integer overflow was discovered in pdf_read_new_xref_section in pdf/pdf-xref.c in Artifex MuPDF 1.11.
local
low complexity
artifex CWE-190
7.8
2017-10-18 CVE-2017-15578 SQL Injection vulnerability in PHPsugar PHP Melody
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.
network
low complexity
phpsugar CWE-89
8.8
2017-10-18 CVE-2017-15577 Information Exposure vulnerability in multiple products
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.
network
low complexity
redmine debian CWE-200
7.5
2017-10-18 CVE-2017-15576 Information Exposure vulnerability in multiple products
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.
network
low complexity
redmine debian CWE-200
7.5
2017-10-18 CVE-2017-15575 In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information or possibly have unspecified other impact.
network
low complexity
redmine debian
7.3
2017-10-18 CVE-2017-15572 Information Exposure Through Log Files vulnerability in multiple products
In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redirect.
network
low complexity
redmine debian CWE-532
7.5
2017-10-17 CVE-2017-9625 Improper Authentication vulnerability in Envitech Envidas Ultimate 1.0.0.4
An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5.
network
low complexity
envitech CWE-287
8.2
2017-10-17 CVE-2017-15565 NULL Pointer Dereference vulnerability in multiple products
In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document.
network
low complexity
freedesktop debian CWE-476
8.8