Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-06-08 CVE-2015-2251 Information Exposure vulnerability in Huawei Oceanstor UDS Firmware V100R002C01Spc101
The DeviceManager in Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to obtain sensitive information via a crafted UDS patch with JavaScript.
network
low complexity
huawei CWE-200
7.5
2017-06-08 CVE-2017-9519 Cross-Site Request Forgery (CSRF) vulnerability in Atmail
atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.
network
low complexity
atmail CWE-352
8.8
2017-06-08 CVE-2017-9518 Cross-Site Request Forgery (CSRF) vulnerability in Atmail
atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.
network
low complexity
atmail CWE-352
8.8
2017-06-08 CVE-2017-9517 Cross-Site Request Forgery (CSRF) vulnerability in Atmail
atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.
network
low complexity
atmail CWE-352
8.8
2017-06-08 CVE-2017-6648 Unspecified vulnerability in Cisco Telepresence CE Software and Telepresence TC Software
A vulnerability in the Session Initiation Protocol (SIP) of the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software could allow an unauthenticated, remote attacker to cause a TelePresence endpoint to reload unexpectedly, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
7.5
2017-06-08 CVE-2017-6638 Improper Input Validation vulnerability in Cisco Anyconnect Secure Mobility Client
A vulnerability in how DLL files are loaded with Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to install and run an executable file with privileges equivalent to the Microsoft Windows SYSTEM account.
local
low complexity
cisco CWE-20
7.8
2017-06-08 CVE-2017-4913 Integer Overflow or Wraparound vulnerability in VMWare Horizon View and Workstation
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain an integer-overflow vulnerability in the True Type Font parser in the TPView.dll.
local
high complexity
vmware CWE-190
7.8
2017-06-08 CVE-2017-4912 Out-of-bounds Read vulnerability in VMWare Horizon View and Workstation
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in TrueType Font (TTF) parser in the TPView.dll.
local
high complexity
vmware CWE-125
7.8
2017-06-08 CVE-2017-4911 Out-of-bounds Write vulnerability in VMWare Horizon View and Workstation
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds write vulnerabilities in JPEG2000 parser in the TPView.dll.
local
high complexity
vmware CWE-787
7.8
2017-06-08 CVE-2017-4910 Out-of-bounds Read vulnerability in VMWare Horizon View and Workstation
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in JPEG2000 parser in the TPView.dll.
local
high complexity
vmware CWE-125
7.8