Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-11-05 CVE-2017-16545 NULL Pointer Dereference vulnerability in Graphicsmagick 1.3.26
The ReadWPGImage function in coders/wpg.c in GraphicsMagick 1.3.26 does not properly validate colormapped images, which allows remote attackers to cause a denial of service (ImportIndexQuantumType invalid write and application crash) or possibly have unspecified other impact via a malformed WPG image.
network
low complexity
graphicsmagick CWE-476
8.8
2017-11-05 CVE-2017-16542 SQL Injection vulnerability in Zohocorp Manageengine Applications Manager 13.0
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.
network
low complexity
zohocorp CWE-89
8.8
2017-11-04 CVE-2017-16540 Information Exposure vulnerability in Open-Emr Openemr
OpenEMR before 5.0.0 Patch 5 allows unauthenticated remote database copying because setup.php exposes functionality for cloning an existing OpenEMR site to an arbitrary attacker-controlled MySQL server via vectors involving a crafted state parameter.
network
low complexity
open-emr CWE-200
7.5
2017-11-04 CVE-2017-16526 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
drivers/uwb/uwbd.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafted USB device.
local
low complexity
linux canonical debian CWE-119
7.8
2017-11-03 CVE-2017-1000151 Information Exposure vulnerability in Mahara
Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to passwords or other sensitive information being passed by unusual parameters to end up in an error log.
network
low complexity
mahara CWE-200
7.5
2017-11-03 CVE-2017-1000150 Session Fixation vulnerability in Mahara
Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout.
network
low complexity
mahara CWE-384
8.8
2017-11-03 CVE-2017-1000148 Deserialization of Untrusted Data vulnerability in Mahara
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of the XML through the PHP "unserialize()" function when importing a skin from an XML file.
network
low complexity
mahara CWE-502
8.8
2017-11-03 CVE-2017-1000139 Server-Side Request Forgery (SSRF) vulnerability in Mahara
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as not all processes of curl redirects are checked against a white or black list.
network
low complexity
mahara CWE-918
8.0
2017-11-03 CVE-2017-1000134 Incorrect Permission Assignment for Critical Resource vulnerability in Mahara
Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable because group members can lose access to the group files they uploaded if another group member changes the access permissions on them.
network
low complexity
mahara CWE-732
8.1
2017-11-03 CVE-2017-1000133 Information Exposure vulnerability in Mahara
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to a user - in some circumstances causing another user's artefacts to be included in a Leap2a export of their own pages.
network
low complexity
mahara CWE-200
7.5