Vulnerabilities > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-06-13 | CVE-2015-3220 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Tlslite Project Tlslite The tlslite library before 0.4.9 for Python allows remote attackers to trigger a denial of service (runtime exception and process crash). | 7.5 |
2017-06-13 | CVE-2017-9604 | Missing Encryption of Sensitive Data vulnerability in KDE Kmail and Messagelib KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network. | 7.5 |
2017-06-13 | CVE-2017-9552 | Improper Authentication vulnerability in Synology Photo Station A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. | 7.8 |
2017-06-13 | CVE-2017-6692 | Insecure Default Initialization of Resource vulnerability in Cisco Ultra Services Framework Element Manager 21.0.V0.65839 A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker to log in to the device with the privileges of the root user, aka an Insecure Default Account Information Vulnerability. | 8.8 |
2017-06-13 | CVE-2017-6689 | Insecure Default Initialization of Resource vulnerability in Cisco Elastic Services Controller 2.2(9.76) A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the admin user, aka an Insecure Default Administrator Credentials Vulnerability. | 8.8 |
2017-06-13 | CVE-2017-6688 | Insecure Default Initialization of Resource vulnerability in Cisco Elastic Services Controller 2.2(9.76) A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux root user, aka an Insecure Default Password Vulnerability. | 8.8 |
2017-06-13 | CVE-2017-6687 | Insecure Default Initialization of Resource vulnerability in Cisco Ultra Services Framework Element Manager 21.0.0 A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in to the affected device using default credentials present on the system, aka an Insecure Default Password Vulnerability. | 8.8 |
2017-06-13 | CVE-2017-6686 | Insecure Default Initialization of Resource vulnerability in Cisco Ultra Services Framework Element Manager 21.0.0 A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in as an admin or oper user of the affected device, aka an Insecure Default Credentials Vulnerability. | 8.8 |
2017-06-13 | CVE-2017-6685 | Insecure Default Initialization of Resource vulnerability in Cisco Ultra Services Framework Staging Server 21.0.0 A vulnerability in Cisco Ultra Services Framework Staging Server could allow an authenticated, remote attacker with access to the management network to log in as an admin user of the affected device, aka an Insecure Default Credentials Vulnerability. | 8.8 |
2017-06-13 | CVE-2017-6684 | Insecure Default Initialization of Resource vulnerability in Cisco Elastic Services Controller 21.0.0 A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux admin user, aka an Insecure Default Credentials Vulnerability. | 8.8 |