Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-10-04 CVE-2017-15010 Resource Exhaustion vulnerability in Salesforce Tough-Cookie
A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js.
network
low complexity
salesforce CWE-400
7.5
2017-10-04 CVE-2017-12820 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Sentinel LDK RTE Firmware 7.50
Arbitrary memory read from controlled memory pointer in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to remote denial of service.
network
low complexity
sentinel CWE-119
7.5
2017-10-04 CVE-2017-12818 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Sentinel LDK RTE Firmware 7.50
Stack overflow in custom XML-parser in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to remote denial of service.
network
low complexity
sentinel CWE-119
7.5
2017-10-04 CVE-2017-12617 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.
network
high complexity
apache canonical oracle debian netapp redhat CWE-434
8.1
2017-10-04 CVE-2017-11122 Information Exposure vulnerability in multiple products
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56, an attacker can trigger an information leak due to insufficient length validation, related to ICMPv6 router advertisement offloading.
network
low complexity
broadcom apple CWE-200
7.5
2017-10-04 CVE-2017-0827 Unspecified vulnerability in Google Android
An elevation of privilege vulnerability in the MediaTek soc driver.
local
low complexity
google
7.8
2017-10-04 CVE-2017-0826 Unspecified vulnerability in Google Android
An elevation of privilege vulnerability in the HTC bootloader.
local
low complexity
google
7.8
2017-10-04 CVE-2017-0825 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Broadcom wifi driver.
network
low complexity
google CWE-200
7.5
2017-10-04 CVE-2017-0823 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in the Android system (rild).
network
low complexity
google CWE-200
7.5
2017-10-04 CVE-2017-0820 Unspecified vulnerability in Google Android
A vulnerability in the Android media framework (n/a).
network
low complexity
google
7.5