Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-12-11 CVE-2017-15942 Unspecified vulnerability in Paloaltonetworks Pan-Os
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.13, and 8.0.x before 8.0.6 allows remote attackers to cause a denial of service via vectors related to the management interface.
network
low complexity
paloaltonetworks
7.5
2017-12-11 CVE-2017-11319 Improper Privilege Management vulnerability in Resolver Perspective 5.1.1.16
Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and consequently gain privileges by leveraging insufficient validation methods and missing cross server side checking mechanisms.
network
low complexity
resolver CWE-269
8.8
2017-12-11 CVE-2017-13070 Untrusted Search Path vulnerability in Qnap Qsync 4.2.2.0724
A DLL Hijacking vulnerability in QNAP Qsync for Windows (exe) version 4.2.2.0724 and earlier could allow remote attackers to execute arbitrary code on Windows machines.
local
low complexity
qnap CWE-426
7.8
2017-12-11 CVE-2016-6904 Credentials Management vulnerability in Netapp Vasa Provider 6.0/6.X/7.0
Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentication.
network
high complexity
netapp CWE-255
8.1
2017-12-11 CVE-2017-17536 Unspecified vulnerability in Phacility Phabricator
Phabricator before 2017-11-10 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary code by using the web UI to browse a branch whose name begins with a --config= or --debugger= substring.
network
low complexity
phacility
8.8
2017-12-11 CVE-2017-17523 Injection vulnerability in Lilypond 2.19.80
lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by a --proxy-pac-file argument.
network
low complexity
lilypond CWE-74
8.8
2017-12-11 CVE-2017-17512 Injection vulnerability in Sensible-Utils Project Sensible-Utils
sensible-browser in sensible-utils before 0.0.11 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by a --proxy-pac-file argument.
network
low complexity
sensible-utils-project CWE-74
8.8
2017-12-11 CVE-2017-11463 Permission Issues vulnerability in Ivanti Endpoint Manager 2016.4/2017.1/2017.3
In Ivanti Service Desk (formerly LANDESK Management Suite) versions between 2016.3 and 2017.3, an Unrestricted Direct Object Reference leads to referencing/updating objects belonging to other users.
network
low complexity
ivanti CWE-275
8.8
2017-12-11 CVE-2017-17509 Out-of-bounds Write vulnerability in Hdfgroup Hdf5 1.10.1
In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5G__ent_decode_vec in H5Gcache.c in libhdf5.a.
network
low complexity
hdfgroup CWE-787
8.8
2017-12-11 CVE-2017-17503 Out-of-bounds Read vulnerability in multiple products
ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c ImportGrayQuantumType heap-based buffer over-read via a crafted file.
network
low complexity
graphicsmagick debian CWE-125
8.8