Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-10-11 CVE-2017-5721 Improper Input Validation vulnerability in Intel products
Insufficient input validation in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to execute arbitrary code via manipulation of memory.
local
high complexity
intel CWE-20
7.5
2017-10-11 CVE-2017-5701 Unspecified vulnerability in Intel products
Insecure platform configuration in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows an attacker with physical presence to run arbitrary code via unauthorized firmware modification during BIOS Recovery.
high complexity
intel
7.1
2017-10-11 CVE-2017-5700 Insufficiently Protected Credentials vulnerability in Intel products
Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to bypass Administrator and User passwords via access to password storage.
local
low complexity
intel CWE-522
8.4
2017-10-10 CVE-2017-15193 Resource Exhaustion vulnerability in Wireshark
In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the MBIM dissector could crash or exhaust system memory.
network
low complexity
wireshark CWE-400
7.5
2017-10-10 CVE-2017-15192 Unspecified vulnerability in Wireshark
In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the BT ATT dissector could crash.
network
low complexity
wireshark
7.5
2017-10-10 CVE-2017-15191 Use of Externally-Controlled Format String vulnerability in multiple products
In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissector could crash.
network
low complexity
wireshark debian CWE-134
7.5
2017-10-10 CVE-2017-15190 Unspecified vulnerability in Wireshark 2.4.0/2.4.1
In Wireshark 2.4.0 to 2.4.1, the RTSP dissector could crash.
network
low complexity
wireshark
7.5
2017-10-10 CVE-2017-15189 Missing Release of Resource after Effective Lifetime vulnerability in Wireshark 2.4.0/2.4.1
In Wireshark 2.4.0 to 2.4.1, the DOCSIS dissector could go into an infinite loop.
network
low complexity
wireshark CWE-772
7.5
2017-10-10 CVE-2017-9717 Out-of-bounds Read vulnerability in Google Android 8.0
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while parsing Netlink attributes, a buffer overread can occur.
network
low complexity
google CWE-125
7.5
2017-10-10 CVE-2017-9715 Out-of-bounds Read vulnerability in Google Android 8.0
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a vendor command, a buffer over-read can occur.
network
low complexity
google CWE-125
7.5