Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-08-07 CVE-2017-12641 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.61
ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadOneJNGImage in coders\png.c.
network
low complexity
imagemagick CWE-772
8.8
2017-08-07 CVE-2017-12640 Out-of-bounds Read vulnerability in multiple products
ImageMagick 7.0.6-1 has an out-of-bounds read vulnerability in ReadOneMNGImage in coders/png.c.
network
low complexity
imagemagick debian CWE-125
8.8
2017-08-07 CVE-2017-12479 Unspecified vulnerability in Kaseya Unitrends Backup
It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existing low-privilege user to root privileges.
network
low complexity
kaseya
8.8
2017-08-07 CVE-2017-9633 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Infineon S-Gold 2 PMB 8876
An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in the Continental AG Infineon S-Gold 2 (PMB 8876) chipset on BMW several models produced between 2009-2010, Ford a limited number of P-HEV vehicles, Infiniti 2013 JX35, Infiniti 2014-2016 QX60, Infiniti 2014-2016 QX60 Hybrid, Infiniti 2014-2015 QX50, Infiniti 2014-2015 QX50 Hybrid, Infiniti 2013 M37/M56, Infiniti 2014-2016 Q70, Infiniti 2014-2016 Q70L, Infiniti 2015-2016 Q70 Hybrid, Infiniti 2013 QX56, Infiniti 2014-2016 QX 80, and Nissan 2011-2015 Leaf.
low complexity
infineon CWE-119
8.8
2017-08-07 CVE-2017-7920 Improper Authentication vulnerability in ABB Vsn300 Firmware and Vsn300 for React Firmware
An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior.
network
low complexity
abb CWE-287
7.5
2017-08-07 CVE-2017-6766 Unspecified vulnerability in Cisco Firesight System Software
A vulnerability in the Secure Sockets Layer (SSL) Decryption and Inspection feature of Cisco Firepower System Software 5.4.0, 5.4.1, 6.0.0, 6.1.0, 6.2.0, 6.2.1, and 6.2.2 could allow an unauthenticated, remote attacker to bypass the SSL policy for decrypting and inspecting traffic on an affected system.
network
low complexity
cisco
7.5
2017-08-07 CVE-2017-6763 Improper Input Validation vulnerability in Cisco Meeting Server 2.1.4
A vulnerability in the implementation of the H.264 protocol in Cisco Meeting Server (CMS) 2.1.4 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system.
network
low complexity
cisco CWE-20
7.5
2017-08-07 CVE-2017-6757 SQL Injection vulnerability in Cisco Unified Communications Manager 10.5(2.10000.5)/11.0(1.10000.10)/11.5(1.10000.6)
A vulnerability in Cisco Unified Communications Manager 10.5(2.10000.5), 11.0(1.10000.10), and 11.5(1.10000.6) could allow an authenticated, remote attacker to conduct a blind SQL injection attack.
network
low complexity
cisco CWE-89
8.8
2017-08-07 CVE-2017-6756 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Prime Collaboration Provisioning 12.2
A vulnerability in the Web UI Application of the Cisco Prime Collaboration Provisioning Tool through 12.2 could allow an unauthenticated, remote attacker to execute unwanted actions.
network
low complexity
cisco CWE-352
8.8
2017-08-07 CVE-2017-6752 Information Exposure vulnerability in Cisco Adaptive Security Appliance Software 9.3.3/9.6.2
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) 9.3(3) and 9.6(2) could allow an unauthenticated, remote attacker to determine valid usernames.
network
low complexity
cisco CWE-200
7.5