Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-10-27 CVE-2017-15945 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages before 2017-09-29 have chown calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to the mysql account for creation of a link.
local
low complexity
mariadb mysql CWE-732
7.8
2017-10-27 CVE-2017-15938 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Binutils 2.29
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, miscalculates DW_FORM_ref_addr die refs in the case of a relocatable object file, which allows remote attackers to cause a denial of service (find_abstract_instance_name invalid memory read, segmentation fault, and application crash).
network
low complexity
gnu CWE-119
7.5
2017-10-27 CVE-2017-15935 Code Injection vulnerability in Artica Pandora FMS 7.0
Artica Pandora FMS version 7.0 is vulnerable to remote PHP code execution through the manager files function.
network
low complexity
artica CWE-94
7.2
2017-10-27 CVE-2017-15582 Use of Hard-coded Credentials vulnerability in Writediary Diary With Lock 4.72
In net.MCrypt in the "Diary with lock" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES parameters, which makes it easier for attackers to obtain the cleartext of stored diary entries.
network
low complexity
writediary CWE-798
7.5
2017-10-27 CVE-2017-15581 Missing Encryption of Sensitive Data vulnerability in Writediary Diary With Lock 4.72
In the "Diary with lock" (aka WriteDiary) application 4.72 for Android, neither HTTPS nor other encryption is used for transmitting data, despite the documentation that the product is intended for "a personal journal of ...
network
low complexity
writediary CWE-311
7.5
2017-10-27 CVE-2017-15933 SQL Injection vulnerability in Eyesofnetwork 5.10
SQL injection vulnerability vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute arbitrary SQL commands via the host parameter to module/capacity_per_device/index.php.
network
low complexity
eyesofnetwork CWE-89
7.2
2017-10-27 CVE-2017-13090 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The retr.c:fd_read_body() function is called when processing OK responses.
network
low complexity
gnu debian CWE-119
8.8
2017-10-27 CVE-2017-13089 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The http.c:skip_short_body() function is called in some circumstances, such as when processing redirects.
network
low complexity
gnu debian CWE-119
8.8
2017-10-27 CVE-2017-15932 Out-of-bounds Read vulnerability in Radare Radare2 2.0.1
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32bit systems.
local
low complexity
radare CWE-125
7.8
2017-10-27 CVE-2017-15931 Out-of-bounds Read vulnerability in Radare Radare2 2.0.1
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c via crafted ELF files on 32bit systems.
local
low complexity
radare CWE-125
7.8