Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-12-28 CVE-2017-17936 Cross-Site Request Forgery (CSRF) vulnerability in Vanguard Project Marketplace Digital products PHP
Vanguard Marketplace Digital Products PHP has CSRF via /search.
network
low complexity
vanguard-project CWE-352
8.8
2017-12-28 CVE-2015-3637 SQL Injection vulnerability in PHPmybackuppro
SQL injection vulnerability in phpMyBackupPro when run in multi-user mode before 2.5 allows remote attackers to execute arbitrary SQL commands via the username and password parameters.
network
high complexity
phpmybackuppro CWE-89
8.1
2017-12-27 CVE-2017-11698 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Network Security Services
Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
local
low complexity
mozilla CWE-119
7.8
2017-12-27 CVE-2017-11697 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Network Security Services
The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (floating point exception and crash) via a crafted cert8.db file.
local
low complexity
mozilla CWE-119
7.8
2017-12-27 CVE-2017-11696 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Network Security Services
Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
local
low complexity
mozilla CWE-119
7.8
2017-12-27 CVE-2017-11695 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Network Security Services
Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
local
low complexity
mozilla CWE-119
7.8
2017-12-27 CVE-2017-13056 Improper Input Validation vulnerability in Tracker-Software Pdf-Xchange Viewer 2.5
The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file.
local
low complexity
tracker-software CWE-20
7.8
2017-12-27 CVE-2016-6914 Incorrect Default Permissions vulnerability in UI Unifi Video
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privileges via a Trojan horse taskkill.exe file.
local
low complexity
ui CWE-276
7.8
2017-12-27 CVE-2017-7163 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple mac OS X
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-119
7.8
2017-12-27 CVE-2017-7162 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-119
7.8