Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-12-27 CVE-2017-17847 Improper Verification of Cryptographic Signature vulnerability in multiple products
An issue was discovered in Enigmail before 1.9.9.
network
low complexity
enigmail debian CWE-347
7.5
2017-12-27 CVE-2017-17846 Improper Input Validation vulnerability in multiple products
An issue was discovered in Enigmail before 1.9.9.
network
low complexity
enigmail debian CWE-20
7.5
2017-12-27 CVE-2017-17845 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in multiple products
An issue was discovered in Enigmail before 1.9.9.
network
low complexity
enigmail debian CWE-338
7.3
2017-12-27 CVE-2017-17840 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Open-Iscsi Project Open-Iscsi 2.0.873/2.0.874/2.0.875
An issue was discovered in Open-iSCSI through 2.0.875.
local
low complexity
open-iscsi-project CWE-119
7.8
2017-12-27 CVE-2017-17010 Untrusted Search Path vulnerability in Sony Content Manager Assistant 3.55.7671.0901
Untrusted search path vulnerability in Content Manager Assistant for PlayStation version 3.55.7671.0901 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
sony CWE-426
7.8
2017-12-27 CVE-2017-16996 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging register truncation mishandling.
local
low complexity
linux debian CWE-119
7.8
2017-12-27 CVE-2017-16995 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging incorrect sign extension.
local
low complexity
linux debian canonical CWE-119
7.8
2017-12-27 CVE-2017-16897 Authentication Bypass by Spoofing vulnerability in Auth0 Passport-Wsfed-Saml2
A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5.
network
high complexity
auth0 CWE-290
8.1
2017-12-26 CVE-2017-12741 Unspecified vulnerability in Siemens products
Specially crafted packets sent to port 161/udp could cause a denial of service condition.
network
low complexity
siemens
7.5
2017-12-26 CVE-2017-12736 Improper Initialization vulnerability in Siemens products
A vulnerability has been identified in RUGGEDCOM ROS for RSL910 devices (All versions < ROS V5.0.1), RUGGEDCOM ROS for all other devices (All versions < ROS V4.3.4), SCALANCE XB-200/XC-200/XP-200/XR300-WG (All versions between V3.0 (including) and V3.0.2 (excluding)), SCALANCE XR-500/XM-400 (All versions between V6.1 (including) and V6.1.1 (excluding)).
low complexity
siemens CWE-665
8.8