Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-07-23 CVE-2017-11556 Uncontrolled Recursion vulnerability in Libsass 3.4.5
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5.
network
low complexity
libsass CWE-674
7.5
2017-07-23 CVE-2017-11555 Improper Input Validation vulnerability in Libsass 3.4.5
There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5.
network
low complexity
libsass CWE-20
7.5
2017-07-23 CVE-2017-11554 Uncontrolled Recursion vulnerability in Libsass 3.4.5
There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5.
network
low complexity
libsass CWE-674
7.5
2017-07-23 CVE-2017-11553 Improper Input Validation vulnerability in Exiv2 0.26
There is an illegal address access in the extend_alias_table function in localealias.c of Exiv2 0.26.
network
low complexity
exiv2 CWE-20
7.5
2017-07-22 CVE-2017-11521 Resource Exhaustion vulnerability in multiple products
The SdpContents::Session::Medium::parse function in resip/stack/SdpContents.cxx in reSIProcate 1.10.2 allows remote attackers to cause a denial of service (memory consumption) by triggering many media connections.
network
low complexity
resiprocate debian CWE-400
7.5
2017-07-22 CVE-2016-10400 Path Traversal vulnerability in Atutor
Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php.
network
low complexity
atutor CWE-22
7.5
2017-07-22 CVE-2017-2276 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Sony Wg-C10 Firmware 3.0.79
Buffer overflow in WG-C10 v3.0.79 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.
network
low complexity
sony CWE-119
7.2
2017-07-22 CVE-2017-2275 OS Command Injection vulnerability in Sony Wg-C10 Firmware 3.0.79
WG-C10 v3.0.79 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
network
low complexity
sony CWE-78
7.2
2017-07-22 CVE-2017-2273 Cross-Site Request Forgery (CSRF) vulnerability in Buffalo Wmr-433 Firmware and Wmr-433W Firmware
Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
network
low complexity
buffalo CWE-352
8.8
2017-07-21 CVE-2017-7523 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cygwin
Cygwin versions 1.7.2 up to and including 1.8.0 are vulnerable to buffer overflow vulnerability in wcsxfrm/wcsxfrm_l functions resulting into denial-of-service by crashing the process or potential hijack of the process running with administrative privileges triggered by specially crafted input string.
network
low complexity
cygwin CWE-119
7.5