Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-07-02 CVE-2017-0377 Information Exposure vulnerability in Torproject TOR
Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow remote attackers to defeat intended anonymity properties by leveraging the existence of large families.
network
low complexity
torproject CWE-200
7.5
2017-07-02 CVE-2017-10790 NULL Pointer Dereference vulnerability in GNU Libtasn1
The _asn1_check_identifier function in GNU Libtasn1 through 4.12 causes a NULL pointer dereference and crash when reading crafted input that triggers assignment of a NULL value within an asn1_node structure.
network
low complexity
gnu CWE-476
7.5
2017-06-30 CVE-2017-7901 Use of Insufficiently Random Values vulnerability in Rockwellautomation products
A Predictable Value Range from Previous Values issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-Bradley MicroLogix 1400 programmable logic controllers 1766-L32AWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWAA, Series A and B, Version 16.00 and prior versions; 1766-L32BXB, Series A and B, Version 16.00 and prior versions; 1766-L32BXBA, Series A and B, Version 16.00 and prior versions; and 1766-L32AWAA, Series A and B, Version 16.00 and prior versions.
network
low complexity
rockwellautomation CWE-330
8.6
2017-06-30 CVE-2017-6046 Information Exposure vulnerability in Sierra Wireless products
An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11.
network
low complexity
sierra-wireless CWE-200
7.5
2017-06-30 CVE-2017-6042 Cross-Site Request Forgery (CSRF) vulnerability in Sierra Wireless products
A Cross-Site Request Forgery issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11.
network
low complexity
sierra-wireless CWE-352
8.8
2017-06-30 CVE-2017-6038 Cross-Site Request Forgery (CSRF) vulnerability in Belden Hirschmann Gecko Lite Managed Switch Firmware
A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions.
network
low complexity
belden-hirschmann CWE-352
7.1
2017-06-30 CVE-2017-6017 Resource Exhaustion vulnerability in Schneider-Electric products
A Resource Exhaustion issue was discovered in Schneider Electric Modicon M340 PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP341000, BMXP342000, BMXP3420102, BMXP3420102CL, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, and BMXP342030H.
network
low complexity
schneider-electric CWE-400
7.5
2017-06-29 CVE-2017-10688 Improper Input Validation vulnerability in Libtiff 4.0.8
In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c.
network
low complexity
libtiff CWE-20
7.5
2017-06-29 CVE-2017-10687 Out-of-bounds Read vulnerability in Libsass 3.4.5
In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp.
network
low complexity
libsass CWE-125
7.5
2017-06-29 CVE-2017-10686 Use After Free vulnerability in multiple products
In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm.
local
low complexity
nasm canonical CWE-416
7.8