Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-10-13 CVE-2017-11762 Improper Input Validation vulnerability in Microsoft products
The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way it handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability".
network
low complexity
microsoft CWE-20
8.8
2017-10-13 CVE-2016-5789 Cross-Site Request Forgery (CSRF) vulnerability in Jantek Jtc-200 Firmware
A Cross-site Request Forgery issue was discovered in JanTek JTC-200, all versions.
network
low complexity
jantek CWE-352
8.0
2017-10-12 CVE-2017-15290 Cleartext Transmission of Sensitive Information vulnerability in Mirasys Video Management System
Mirasys Video Management System (VMS) 6.x before 6.4.6, 7.x before 7.5.15, and 8.x before 8.1.1 has a login process in which cleartext data is sent from a server to a client, and not all of this data is required for the client functionality.
network
low complexity
mirasys CWE-319
7.5
2017-10-12 CVE-2017-15268 Missing Release of Resource after Effective Lifetime vulnerability in Qemu
Qemu through 2.10.0 allows remote attackers to cause a memory leak by triggering slow data-channel read operations, related to io/channel-websock.c.
network
low complexity
qemu CWE-772
7.5
2017-10-12 CVE-2017-10865 Untrusted Search Path vulnerability in Hitachi-Solutions Confidential File Decryption
Untrusted search path vulnerability in HIBUN Confidential File Decryption program prior to 10.50.0.5 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
hitachi-solutions CWE-426
7.8
2017-10-12 CVE-2017-10864 Untrusted Search Path vulnerability in Hitachi-Solutions Confidential File Viewer
Untrusted search path vulnerability in Installer of HIBUN Confidential File Viewer prior to 11.20.0001 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
hitachi-solutions CWE-426
7.8
2017-10-12 CVE-2017-10863 Untrusted Search Path vulnerability in Hitachi-Solutions Confidential File Decryption
Untrusted search path vulnerability in HIBUN Confidential File Decryption program prior to 10.50.0.5 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
hitachi-solutions CWE-426
7.8
2017-10-12 CVE-2017-9514 Incorrect Permission Assignment for Critical Resource vulnerability in Atlassian Bamboo
Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded.
network
low complexity
atlassian CWE-732
8.8
2017-10-12 CVE-2017-15286 NULL Pointer Dereference vulnerability in Sqlite 3.20.1
SQLite 3.20.1 has a NULL pointer dereference in tableColumnList in shell.c because it fails to consider certain cases where `sqlite3_step(pStmt)==SQLITE_ROW` is false and a data structure is never initialized.
network
low complexity
sqlite CWE-476
7.5
2017-10-12 CVE-2017-15285 Improper Input Validation vulnerability in Qualiteam X-Cart
X-Cart 5.2.23, 5.3.1.9, 5.3.2.13, and 5.3.3 is vulnerable to Remote Code Execution.
network
low complexity
qualiteam CWE-20
8.8