Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-05-17 CVE-2017-4014 Session Fixation vulnerability in Mcafee Network Data Loss Prevention 9.3.0
Session Side jacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view, add, and remove users via modification of the HTTP request.
network
low complexity
mcafee CWE-384
8.0
2017-05-17 CVE-2017-7493 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control issue.
local
low complexity
qemu debian CWE-732
7.8
2017-05-17 CVE-2017-9030 Path Traversal vulnerability in Codextrous B2J Contact 2.1.12
The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a directory traversal attack that bypasses a uniqid protection mechanism, and makes it easier to read arbitrary uploaded files.
network
low complexity
codextrous CWE-22
7.5
2017-05-17 CVE-2017-8849 Improper Input Validation vulnerability in multiple products
smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount helper DBUS service.
local
low complexity
smb4k-project debian CWE-20
7.8
2017-05-17 CVE-2017-8422 Authentication Bypass by Spoofing vulnerability in KDE Kauth
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
local
low complexity
kde CWE-290
7.8
2017-05-17 CVE-2017-5214 Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Codextrous B2J Contact 2.1.12
The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows prediction of a uniqid value based on knowledge of a time value.
network
low complexity
codextrous CWE-335
7.5
2017-05-17 CVE-2016-3403 Cross-Site Request Forgery (CSRF) vulnerability in Synacor Zimbra Collaboration Suite
Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Patch 8 allow remote attackers to hijack the authentication of administrators for requests that (1) add, (2) modify, or (3) remove accounts by leveraging failure to use of a CSRF token and perform referer header checks, aka bugs 100885 and 100899.
network
low complexity
synacor CWE-352
8.8
2017-05-16 CVE-2017-7662 Cross-Site Request Forgery (CSRF) vulnerability in Apache CXF Fediz
Apache CXF Fediz ships with an OpenId Connect (OIDC) service which has a Client Registration Service, which is a simple web application that allows clients to be created, deleted, etc.
network
low complexity
apache CWE-352
8.8
2017-05-16 CVE-2017-7661 Cross-Site Request Forgery (CSRF) vulnerability in Apache CXF Fediz
Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications.
network
low complexity
apache CWE-352
8.8
2017-05-16 CVE-2017-6658 Out-of-bounds Read vulnerability in Cisco Sourcefire Snort 3.0
Cisco Sourcefire Snort 3.0 before build 233 has a Buffer Overread related to use of a decoder array.
network
low complexity
cisco CWE-125
7.5