Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-09-21 CVE-2017-12219 Unspecified vulnerability in Cisco products
A vulnerability in the handling of IP fragments for the Cisco Small Business SPA300, SPA500, and SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
7.5
2017-09-21 CVE-2017-12215 Improper Input Validation vulnerability in Cisco Asyncos
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance could allow an unauthenticated, remote attacker to cause an affected device to run out of memory and stop scanning and forwarding email messages.
local
low complexity
cisco CWE-20
7.1
2017-09-21 CVE-2017-12214 Improper Input Validation vulnerability in Cisco Unified Customer Voice Portal 10.5/11.0/11.5
A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges.
network
low complexity
cisco CWE-20
8.8
2017-09-20 CVE-2017-14623 Improper Authentication vulnerability in Go-Ldap Project Ldap 2.5.0
In the ldap.v2 (aka go-ldap) package through 2.5.0 for Go, an attacker may be able to login with an empty password.
network
high complexity
go-ldap-project CWE-287
8.1
2017-09-20 CVE-2017-14617 Improper Input Validation vulnerability in Freedesktop Poppler 0.59.0
In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malicious PDF files.
local
low complexity
freedesktop CWE-20
7.8
2017-09-20 CVE-2017-14616 Resource Exhaustion vulnerability in Watchguard Fireware
An FBX-5312 issue was discovered in WatchGuard Fireware before 12.0.
network
low complexity
watchguard CWE-400
7.5
2017-09-20 CVE-2015-9231 Information Exposure vulnerability in Iterm2
iTerm2 3.x before 3.1.1 allows remote attackers to discover passwords by reading DNS queries.
network
low complexity
iterm2 CWE-200
7.5
2017-09-20 CVE-2017-14610 Improper Initialization vulnerability in Bareos
bareos-dir, bareos-fd, and bareos-sd in bareos-core in Bareos 16.2.6 and earlier create a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command.
local
low complexity
bareos CWE-665
7.8
2017-09-20 CVE-2017-14609 Improper Initialization vulnerability in Kannel
The server daemons in Kannel 1.5.0 and earlier create a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by bearerbox.
local
low complexity
kannel CWE-665
7.8
2017-09-20 CVE-2015-5395 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
network
low complexity
debian alinto CWE-352
8.8