Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-05-01 CVE-2017-8373 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Underbit MAD Libmad 0.15.1B
The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.
local
low complexity
underbit CWE-119
7.8
2017-04-30 CVE-2017-8367 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ether Software products
Buffer overflow in Ether Software Easy MOV Converter 1.4.24, Easy DVD Creator, Easy MPEG/AVI/DIVX/WMV/RM to DVD, Easy Avi/Divx/Xvid to DVD Burner, Easy MPEG to DVD Burner, Easy WMV/ASF/ASX to DVD Burner, Easy RM RMVB to DVD Burner, Easy CD DVD Copy, MP3/AVI/MPEG/WMV/RM to Audio CD Burner, MP3/WAV/OGG/WMA/AC3 to CD Burner, MP3 WAV to CD Burner, My Video Converter, Easy AVI DivX Converter, Easy Video to iPod Converter, Easy Video to PSP Converter, Easy Video to 3GP Converter, Easy Video to MP4 Converter, and Easy Video to iPod/MP4/PSP/3GP Converter allows local attackers to cause a denial of service (SEH overwrite) or possibly have unspecified other impact via a long username.
local
low complexity
ether-software CWE-119
7.8
2017-04-30 CVE-2017-8364 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Rzip Project Rzip 2.1
The read_buf function in stream.c in rzip 2.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive.
local
low complexity
rzip-project CWE-119
7.8
2017-04-30 CVE-2017-8361 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.
network
low complexity
libsndfile-project debian CWE-119
8.8
2017-04-30 CVE-2017-8081 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Cagintranetworks Getsimple CMS 3.3.13
Poor cryptographic salt initialization in admin/inc/template_functions.php in GetSimple CMS 3.3.13 allows a network attacker to escalate privileges to an arbitrary user or conduct CSRF attacks via calculation of a session cookie or CSRF nonce.
network
low complexity
cagintranetworks CWE-338
8.8
2017-04-30 CVE-2017-7721 Improper Input Validation vulnerability in Irfanview FPX and Irfanview
IrfanView version 4.44 (32bit) with FPX Plugin before 4.45 has an Access Violation and crash in processing a FlashPix (.FPX) file.
local
low complexity
irfanview CWE-20
7.8
2017-04-30 CVE-2017-8342 Race Condition vulnerability in Radicale
Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.
network
high complexity
radicale CWE-362
8.1
2017-04-29 CVE-2017-8326 Incorrect Calculation vulnerability in Entropymine Imageworsener
libimageworsener.a in ImageWorsener before 1.3.1 has "left shift cannot be represented in type int" undefined behavior issues, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image, related to imagew-bmp.c and imagew-util.c.
network
low complexity
entropymine CWE-682
8.8
2017-04-29 CVE-2017-8325 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Entropymine Imageworsener
The iw_process_cols_to_intermediate function in imagew-main.c in libimageworsener.a in ImageWorsener before 1.3.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted image.
network
low complexity
entropymine CWE-119
8.8
2017-04-29 CVE-2017-8114 Improper Privilege Management vulnerability in Roundcube Webmail
Roundcube Webmail allows arbitrary password resets by authenticated users.
network
low complexity
roundcube CWE-269
8.8