Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2016-10-31 CVE-2016-8856 Permission Issues vulnerability in Foxitsoftware Reader 2.1.0.0804/2.1.0.0805
Foxit Reader for Mac 2.1.0.0804 and earlier and Foxit Reader for Linux 2.1.0.0805 and earlier suffered from a vulnerability where weak file permissions could be exploited by attackers to execute arbitrary code.
local
low complexity
foxitsoftware CWE-275
7.8
2016-10-31 CVE-2016-7991 7PK - Errors vulnerability in Google Android
On Samsung Galaxy S4 through S7 devices, the "omacp" app ignores security information embedded in the OMACP messages resulting in remote unsolicited WAP Push SMS messages being accepted, parsed, and handled by the device, leading to unauthorized configuration changes, a subset of SVE-2016-6542.
network
low complexity
google CWE-388
7.5
2016-10-31 CVE-2016-7989 7PK - Security Features vulnerability in Google Android
On Samsung Galaxy S4 through S7 devices, a malformed OTA WAP PUSH SMS containing an OMACP message sent remotely triggers an unhandled ArrayIndexOutOfBoundsException in Samsung's implementation of the WifiServiceImpl class within wifi-service.jar.
network
low complexity
google CWE-254
7.5
2016-10-31 CVE-2016-7988 7PK - Errors vulnerability in Google Android
On Samsung Galaxy S4 through S7 devices, absence of permissions on the BroadcastReceiver responsible for handling the com.[Samsung].android.intent.action.SET_WIFI intent leads to unsolicited configuration messages being handled by wifi-service.jar within the Android Framework, a subset of SVE-2016-6542.
network
low complexity
google CWE-388
7.5
2016-10-31 CVE-2016-7964 Server-Side Request Forgery (SSRF) vulnerability in Dokuwiki 20160626A
The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no way to restrict access to private networks.
network
low complexity
dokuwiki CWE-918
8.6
2016-10-30 CVE-2016-9114 NULL Pointer Dereference vulnerability in Uclouvain Openjpeg 2.1.2
There is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2.
network
low complexity
uclouvain CWE-476
7.5
2016-10-30 CVE-2016-9113 NULL Pointer Dereference vulnerability in Uclouvain Openjpeg 2.1.2
There is a NULL pointer dereference in function imagetobmp of convertbmp.c:980 of OpenJPEG 2.1.2.
network
low complexity
uclouvain CWE-476
7.5
2016-10-29 CVE-2016-9112 Divide By Zero vulnerability in Uclouvain Openjpeg 2.1.2
Floating Point Exception (aka FPE or divide by zero) in opj_pi_next_cprl function in openjp2/pi.c:523 in OpenJPEG 2.1.2.
network
low complexity
uclouvain CWE-369
7.5
2016-10-29 CVE-2016-7506 Out-of-bounds Read vulnerability in Artifex Mujs
An out-of-bounds read vulnerability was observed in Sp_replace_regexp function of Artifex Software, Inc.
network
low complexity
artifex CWE-125
7.5
2016-10-28 CVE-2016-4396 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HP System Management Homepage
HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" issue.
network
low complexity
hp CWE-119
7.5