Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-01-28 CVE-2016-9554 Command Injection vulnerability in Sophos web Appliance 4.2.1.3
The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface.
network
low complexity
sophos CWE-77
7.2
2017-01-28 CVE-2016-9553 Command Injection vulnerability in Sophos web Appliance 4.2.1.3
The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface.
network
low complexity
sophos CWE-77
7.2
2017-01-27 CVE-2017-5601 Out-of-bounds Read vulnerability in Libarchive 3.2.2
An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-of-bounds read memory access and subsequently cause a crash via a specially crafted archive.
network
low complexity
libarchive CWE-125
7.5
2017-01-27 CVE-2017-5329 Out-of-bounds Write vulnerability in Paloaltonetworks Terminal Services Agent
Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger an out-of-bounds write operation.
local
low complexity
paloaltonetworks CWE-787
7.8
2017-01-27 CVE-2017-5328 Unspecified vulnerability in Paloaltonetworks Terminal Services Agent
Palo Alto Networks Terminal Services Agent before 7.0.7 allows attackers to spoof arbitrary users via unspecified vectors.
network
low complexity
paloaltonetworks
7.5
2017-01-27 CVE-2017-3443 Unspecified vulnerability in Oracle Common Applications
Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: User Interface).
network
low complexity
oracle
8.2
2017-01-27 CVE-2017-3442 Unspecified vulnerability in Oracle Customer Interaction History 12.1.1/12.1.2/12.1.3
Vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite (subcomponent: User Interface).
network
low complexity
oracle
8.2
2017-01-27 CVE-2017-3441 Unspecified vulnerability in Oracle Customer Interaction History 12.1.1/12.1.2/12.1.3
Vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite (subcomponent: User Interface).
network
low complexity
oracle
8.2
2017-01-27 CVE-2017-3440 Unspecified vulnerability in Oracle Customer Interaction History 12.1.1/12.1.2/12.1.3
Vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite (subcomponent: User Interface).
network
low complexity
oracle
8.2
2017-01-27 CVE-2017-3439 Unspecified vulnerability in Oracle One-To-One Fulfillment
Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: User Interface).
network
low complexity
oracle
8.2