Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-07-07 CVE-2017-1000381 Information Exposure vulnerability in multiple products
The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.
network
low complexity
c-ares-project c-ares nodejs CWE-200
7.5
2017-07-07 CVE-2014-7953 Race Condition vulnerability in Google Android 4.4.4
Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows local users with adb shell access to execute arbitrary code or any valid package as system by running "pm install" with the target apk, and simultaneously running a crafted script to process logcat's output looking for a dexopt line, which once found should execute bindBackupAgent with the uid member of the ApplicationInfo parameter set to 1000.
local
high complexity
google CWE-362
7.0
2017-07-07 CVE-2017-10994 Write-what-where Condition vulnerability in Foxitsoftware Foxit Reader
Foxit Reader before 8.3.1 and PhantomPDF before 8.3.1 have an Arbitrary Write vulnerability, which allows remote attackers to execute arbitrary code via a crafted document.
local
low complexity
foxitsoftware CWE-123
7.3
2017-07-07 CVE-2015-3297 Path Traversal vulnerability in Etherpad
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by leveraging replacement of backslashes with slashes in the path parameter of HTTP API requests.
network
low complexity
etherpad CWE-22
7.5
2017-07-07 CVE-2017-0340 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android 7.1.2
An elevation of privilege vulnerability in the NVIDIA Libnvparser component due to a memcpy into a fixed sized buffer with a user-controlled size could lead to a memory corruption and possible remote code execution.
local
low complexity
google CWE-119
7.8
2017-07-07 CVE-2017-2244 Cross-Site Request Forgery (CSRF) vulnerability in Brother Mfc-J960Dwn Firmware D
Cross-site request forgery (CSRF) vulnerability in MFC-J960DWN firmware ver.D and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
network
low complexity
brother CWE-352
8.8
2017-07-07 CVE-2017-2238 Cross-Site Request Forgery (CSRF) vulnerability in Toshiba Hem-Gw16A Firmware and Hem-Gw26A Firmware
Cross-site request forgery (CSRF) vulnerability in Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier and Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
network
low complexity
toshiba CWE-352
8.8
2017-07-07 CVE-2017-2233 Untrusted Search Path vulnerability in MOJ PDF Digital Signature G2.30
Untrusted search path vulnerability in Installer of PDF Digital Signature Plugin (G2.30) and earlier, distributed till June 29, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
moj CWE-426
7.8
2017-07-07 CVE-2017-2232 Untrusted Search Path vulnerability in MOJ Shinseiyo Sogo Soft 4.8A
Untrusted search path vulnerability in Installer of Shinseiyo Sogo Soft (4.8A) and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
moj CWE-426
7.8
2017-07-07 CVE-2017-2231 Untrusted Search Path vulnerability in Mlit Denshiseikabutsusakuseishienkensa 3.0.2
Untrusted search path vulnerability in The installer of MLIT DenshiSeikabutsuSakuseiShienKensa system Ver3.02 and earlier, distributed till June 20, 2017, The self-extracting archive including the installer of MLIT DenshiSeikabutsuSakuseiShienKensa system Ver3.02 and earlier, distributed till June 20, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
mlit CWE-426
7.8