Vulnerabilities > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-10-02 | CVE-2017-14975 | NULL Pointer Dereference vulnerability in multiple products The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is not initialized, which allows an attacker to launch a denial of service attack. | 7.5 |
2017-10-02 | CVE-2017-14958 | Unrestricted Upload of File with Dangerous Type vulnerability in Pivotx 2.3.11 lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file. | 7.2 |
2017-10-01 | CVE-2017-14797 | Inadequate Encryption Strength vulnerability in Philips HUE Bridge Bsb002 Firmware 1707040932 Lack of Transport Encryption in the public API in Philips Hue Bridge BSB002 SW 1707040932 allows remote attackers to read API keys (and consequently bypass the pushlink protection mechanism, and obtain complete control of the connected accessories) by leveraging the ability to sniff HTTP traffic on the local intranet network. | 7.5 |
2017-09-30 | CVE-2017-14947 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Artifex Gsview 6.0 Artifex GSView 6.0 Beta on Windows allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Block Data Move starting at mupdfnet64!mIncrementalSaveFile+0x0000000000193359." | 7.8 |
2017-09-30 | CVE-2017-14946 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Artifex Gsview 6.0 Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at mupdfnet64!mIncrementalSaveFile+0x000000000000344e." | 7.8 |
2017-09-30 | CVE-2017-14945 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Artifex Gsview 6.0 Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Possible Stack Corruption starting at KERNELBASE!RaiseException+0x0000000000000068." | 7.8 |
2017-09-30 | CVE-2017-14944 | Improper Input Validation vulnerability in Inedo Proget Inedo ProGet before 4.7.14 does not properly address dangerous package IDs during package addition, aka PG-1060. | 7.5 |
2017-09-30 | CVE-2017-14935 | Improper Input Validation vulnerability in Pulsesecure Pulse ONE On-Premise 2.0.1649 Pulse Secure Pulse One On-Premise 2.0.1649 and below does not properly validate requests, which allows remote users to query and obtain sensitive information. | 7.5 |
2017-09-30 | CVE-2017-14929 | Infinite Loop vulnerability in Freedesktop Poppler 0.59.0 In Poppler 0.59.0, memory corruption occurs in a call to Object::dictLookup() in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opFill, Gfx::doPatternFill, Gfx::doTilingPatternFill and Gfx::drawForm calls (aka a Gfx.cc infinite loop), a different vulnerability than CVE-2017-14519. | 7.5 |
2017-09-30 | CVE-2017-14925 | Cross-Site Request Forgery (CSRF) vulnerability in Tiki Tikiwiki Cms/Groupware Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php. | 8.0 |