Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-03-21 CVE-2017-7208 Out-of-bounds Read vulnerability in Libav 9.21
The decode_residual function in libavcodec in libav 9.21 allows remote attackers to cause a denial of service (buffer over-read) or obtain sensitive information from process memory via a crafted h264 video file.
local
low complexity
libav CWE-125
7.1
2017-03-21 CVE-2017-7206 Out-of-bounds Read vulnerability in Libav 9.21
The ff_h2645_extract_rbsp function in libavcodec in libav 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read) or obtain sensitive information from process memory via a crafted h264 video file.
local
low complexity
libav CWE-125
7.1
2017-03-20 CVE-2016-4929 Command Injection vulnerability in Juniper Junos Space
Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary code as a root user.
network
low complexity
juniper CWE-77
8.8
2017-03-20 CVE-2016-4928 Cross-Site Request Forgery (CSRF) vulnerability in Juniper Junos Space
Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Space.
network
low complexity
juniper CWE-352
8.8
2017-03-20 CVE-2016-4927 Improper Input Validation vulnerability in Juniper Junos Space
Insufficient validation of SSH keys in Junos Space before 15.2R2 allows man-in-the-middle (MITM) type of attacks while a Space device is communicating with managed devices.
network
high complexity
juniper CWE-20
8.1
2017-03-20 CVE-2016-6816 Improper Input Validation vulnerability in Apache Tomcat
The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters.
network
low complexity
apache CWE-20
7.1
2017-03-20 CVE-2017-6803 Cross-Site Request Forgery (CSRF) vulnerability in Solarwinds FTP Voyager 16.2.0
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for requests that (1) change the admin password, (2) terminate the scheduler, or (3) possibly execute arbitrary commands via crafted requests to Admin/XML/Result.xml.
network
low complexity
solarwinds CWE-352
8.8
2017-03-20 CVE-2017-6318 Information Exposure vulnerability in multiple products
saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.
network
low complexity
opensuse sane-backends-project CWE-200
7.5
2017-03-20 CVE-2017-6178 NULL Pointer Dereference vulnerability in Usbpcap Project Usbpcap 1.1.0.0
The IofCallDriver function in USBPcap 1.1.0.0 allows local users to gain privileges via a crafted 0x00090028 IOCTL call, which triggers a NULL pointer dereference.
local
low complexity
usbpcap-project CWE-476
7.8
2017-03-20 CVE-2017-6058 Classic Buffer Overflow vulnerability in Qemu
Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of service (out-of-bounds access and QEMU process crash) via vectors related to VLAN stripping.
network
low complexity
qemu CWE-120
7.5