Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-10-19 CVE-2017-10034 Unspecified vulnerability in Oracle Business Intelligence Publisher 11.1.1.7.0/11.1.1.9.0
Vulnerability in the Oracle BI Publisher component of Oracle Fusion Middleware (subcomponent: Core Formatting API).
network
low complexity
oracle
8.2
2017-10-19 CVE-2017-10026 Unspecified vulnerability in Oracle SOA Suite 11.1.1.7.0
Vulnerability in the Oracle SOA Suite component of Oracle Fusion Middleware (subcomponent: Fabric Layer).
network
low complexity
oracle
8.2
2017-10-19 CVE-2017-12579 Uncontrolled Search Path Element vulnerability in Hashicorp Vagrant VMWare Fusion
An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and earlier allows a non-root user to obtain a root shell.
local
low complexity
hashicorp CWE-427
7.8
2017-10-19 CVE-2017-3883 Allocation of Resources Without Limits or Throttling vulnerability in Cisco Firepower Extensible Operating System
A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
low complexity
cisco CWE-770
8.6
2017-10-19 CVE-2017-15609 Missing Encryption of Sensitive Data vulnerability in Octopus Deploy
Octopus before 3.17.7 allows attackers to obtain sensitive cleartext information by reading a variable JSON file in certain situations involving Offline Drop Targets.
network
low complexity
octopus CWE-311
7.5
2017-10-19 CVE-2017-12293 Resource Exhaustion vulnerability in Cisco Webex Meetings Server 2.7
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-400
8.6
2017-10-19 CVE-2017-12271 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Spa300 Firmware and Spa500 Firmware
A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device.
network
low complexity
cisco CWE-352
8.8
2017-10-19 CVE-2017-12260 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA50x, SPA51x, and SPA52x Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to become unresponsive, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-119
7.5
2017-10-19 CVE-2017-12259 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Small Business IP Phone Firmware 7.6.2
A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to become unresponsive, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-119
7.5
2017-10-18 CVE-2017-15602 Infinite Loop vulnerability in GNU Libextractor 1.4
In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extractor.c, leading to an infinite loop for a crafted size.
network
low complexity
gnu CWE-835
7.5