Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-07-17 CVE-2017-11318 OS Command Injection vulnerability in Cobiansoft Cobian Backup 11
Cobian Backup 11 client allows man-in-the-middle attackers to add and execute new backup tasks when the master server is spoofed.
network
high complexity
cobiansoft CWE-78
8.1
2017-07-17 CVE-2017-11311 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Openmpt Libopenmpt and Openmpt
soundlib/Load_psm.cpp in OpenMPT through 1.26.12.00 and libopenmpt before 0.2.8461-beta26 has a heap buffer overflow with the potential for arbitrary code execution via a crafted PSM File that triggers use of the same sample slot for two samples.
local
low complexity
openmpt CWE-119
7.8
2017-07-17 CVE-2017-10605 Improper Input Validation vulnerability in Juniper Junos 12.1X46/12.3X48/15.1X49
On all vSRX and SRX Series devices, when the DHCP or DHCP relay is configured, specially crafted packet might cause the flowd process to crash, halting or interrupting traffic from flowing through the device(s).
network
low complexity
juniper CWE-20
7.5
2017-07-17 CVE-2017-10603 XML Injection (aka Blind XPath Injection) vulnerability in Juniper Junos 15.1/15.1X53
An XML injection vulnerability in Junos OS CLI can allow a locally authenticated user to elevate privileges and run arbitrary commands as the root user.
local
low complexity
juniper CWE-91
7.8
2017-07-17 CVE-2017-10602 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Juniper Junos
A buffer overflow vulnerability in Junos OS CLI may allow a local authenticated user with read only privileges and access to Junos CLI, to execute code with root privileges.
local
low complexity
juniper CWE-119
7.8
2017-07-17 CVE-2017-1000363 Out-of-bounds Write vulnerability in multiple products
Linux drivers/char/lp.c Out-of-Bounds Write.
local
low complexity
linux debian CWE-787
7.8
2017-07-17 CVE-2017-1000080 Unspecified vulnerability in Onosproject Onos 1.8.0/1.9.0
Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets.
network
low complexity
onosproject
7.5
2017-07-17 CVE-2017-1000079 Unspecified vulnerability in Onosproject Onos 1.8.0/1.9.0
Linux foundation ONOS 1.9.0 is vulnerable to a DoS.
network
low complexity
onosproject
7.5
2017-07-17 CVE-2017-1000071 Improper Authentication vulnerability in Apereo PHPcas 1.3.4
Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.
network
high complexity
apereo CWE-287
8.1
2017-07-17 CVE-2017-1000069 Cross-Site Request Forgery (CSRF) vulnerability in Oauth2 Proxy Project Oauth2 Proxy 2.1
CSRF in Bitly oauth2_proxy 2.1 during authentication flow
network
low complexity
oauth2-proxy-project CWE-352
8.8