Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-06-07 CVE-2015-7723 Link Following vulnerability in AMD Fglrx-Driver 14.4.2
AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.
local
low complexity
amd CWE-59
7.8
2017-06-07 CVE-2017-7314 Improper Authentication vulnerability in Personify Personify360 E-Business
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1.
network
low complexity
personify CWE-287
7.5
2017-06-07 CVE-2017-7313 Information Exposure vulnerability in Personify Personify360 E-Business
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1.
network
low complexity
personify CWE-200
7.5
2017-06-07 CVE-2017-9469 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory.
network
low complexity
irssi debian CWE-119
7.5
2017-06-07 CVE-2017-9468 NULL Pointer Dereference vulnerability in multiple products
In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer.
network
low complexity
irssi debian CWE-476
7.5
2017-06-06 CVE-2017-9465 Out-of-bounds Read vulnerability in Virustotal Yara 3.6.1
The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from process memory via a crafted file that is mishandled in the yr_re_fast_exec function in libyara/re.c and the _yr_scan_match_callback function in libyara/scan.c.
local
low complexity
virustotal CWE-125
7.1
2017-06-06 CVE-2017-9462 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.
network
low complexity
mercurial debian redhat CWE-732
8.8
2017-06-06 CVE-2016-0768 Improper Access Control vulnerability in Postgresql
PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.
network
low complexity
postgresql CWE-284
7.5
2017-06-06 CVE-2017-5243 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Rapid7 Nexpose
The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exchange and other important functions.
network
high complexity
rapid7 CWE-327
8.5
2017-06-06 CVE-2017-9449 SQL Injection vulnerability in Bigtreecms Bigtree CMS
SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin/modules/developer/modules/views/create.php.
network
low complexity
bigtreecms CWE-89
8.8