Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-08-16 CVE-2017-12892 Untrusted Search Path vulnerability in Foxitsoftware PDF Compressor
Foxit PDF Compressor installers from versions from 7.0.0.183 to 7.7.2.10 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
local
low complexity
foxitsoftware CWE-426
7.8
2017-08-16 CVE-2017-7548 PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on a large object to overwrite the entire contents of the object, resulting in a denial of service.
network
low complexity
postgresql debian
7.5
2017-08-16 CVE-2017-7547 Unspecified vulnerability in Postgresql
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers to retrieve passwords from the user mappings defined by the foreign server owners without actually having the privileges to do so.
network
low complexity
postgresql
8.8
2017-08-16 CVE-2017-8243 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Android
A buffer overflow can occur in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android when processing a firmware image file.
local
low complexity
google CWE-119
7.8
2017-08-16 CVE-2017-6421 Classic Buffer Overflow vulnerability in Google Android
In the touch controller function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a variable may be controlled by the user and can lead to a buffer overflow.
low complexity
google CWE-120
8.8
2017-08-16 CVE-2016-5867 Permissions, Privileges, and Access Controls vulnerability in Google Android
In a sound driver in Android for MSM, Firefox OS for MSM, QRD Android, some variables are from userspace and values can be chosen that could result in stack overflow.
local
high complexity
google CWE-264
7.0
2017-08-16 CVE-2016-5864 Permissions, Privileges, and Access Controls vulnerability in Google Android
In an audio driver function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, some parameters are from userspace, and if they are set to a large value, integer overflow is possible followed by buffer overflow.
local
low complexity
google CWE-264
7.8
2017-08-16 CVE-2016-5863 Permissions, Privileges, and Access Controls vulnerability in Google Android
In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lead to out-of-bounds accesses.
local
low complexity
google CWE-264
7.8
2017-08-16 CVE-2016-5862 Permissions, Privileges, and Access Controls vulnerability in Google Android
When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, the type casting is done to the container structure instead of the codec's individual structure, resulting in a device restart after kernel crash occurs.
local
high complexity
google CWE-264
7.0
2017-08-16 CVE-2016-5861 Permissions, Privileges, and Access Controls vulnerability in Google Android
In a display driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a variable controlled by userspace is used to calculate offsets and sizes for copy operations, which could result in heap overflow.
low complexity
google CWE-264
8.8