Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-10-02 CVE-2017-14975 NULL Pointer Dereference vulnerability in multiple products
The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is not initialized, which allows an attacker to launch a denial of service attack.
network
low complexity
freedesktop debian CWE-476
7.5
2017-10-02 CVE-2017-14958 Unrestricted Upload of File with Dangerous Type vulnerability in Pivotx 2.3.11
lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file.
network
low complexity
pivotx CWE-434
7.2
2017-10-01 CVE-2017-14797 Inadequate Encryption Strength vulnerability in Philips HUE Bridge Bsb002 Firmware 1707040932
Lack of Transport Encryption in the public API in Philips Hue Bridge BSB002 SW 1707040932 allows remote attackers to read API keys (and consequently bypass the pushlink protection mechanism, and obtain complete control of the connected accessories) by leveraging the ability to sniff HTTP traffic on the local intranet network.
high complexity
philips CWE-326
7.5
2017-09-30 CVE-2017-14947 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Artifex Gsview 6.0
Artifex GSView 6.0 Beta on Windows allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Block Data Move starting at mupdfnet64!mIncrementalSaveFile+0x0000000000193359."
local
low complexity
artifex CWE-119
7.8
2017-09-30 CVE-2017-14946 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Artifex Gsview 6.0
Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at mupdfnet64!mIncrementalSaveFile+0x000000000000344e."
local
low complexity
artifex CWE-119
7.8
2017-09-30 CVE-2017-14945 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Artifex Gsview 6.0
Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Possible Stack Corruption starting at KERNELBASE!RaiseException+0x0000000000000068."
local
low complexity
artifex CWE-119
7.8
2017-09-30 CVE-2017-14944 Improper Input Validation vulnerability in Inedo Proget
Inedo ProGet before 4.7.14 does not properly address dangerous package IDs during package addition, aka PG-1060.
network
low complexity
inedo CWE-20
7.5
2017-09-30 CVE-2017-14935 Improper Input Validation vulnerability in Pulsesecure Pulse ONE On-Premise 2.0.1649
Pulse Secure Pulse One On-Premise 2.0.1649 and below does not properly validate requests, which allows remote users to query and obtain sensitive information.
network
low complexity
pulsesecure CWE-20
7.5
2017-09-30 CVE-2017-14929 Infinite Loop vulnerability in Freedesktop Poppler 0.59.0
In Poppler 0.59.0, memory corruption occurs in a call to Object::dictLookup() in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opFill, Gfx::doPatternFill, Gfx::doTilingPatternFill and Gfx::drawForm calls (aka a Gfx.cc infinite loop), a different vulnerability than CVE-2017-14519.
network
low complexity
freedesktop CWE-835
7.5
2017-09-30 CVE-2017-14925 Cross-Site Request Forgery (CSRF) vulnerability in Tiki Tikiwiki Cms/Groupware
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php.
network
low complexity
tiki CWE-352
8.0