Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-07-04 CVE-2017-10810 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-initialization failures.
network
low complexity
linux debian CWE-772
7.5
2017-07-04 CVE-2017-10805 Incorrect Authorization vulnerability in Odoo 10.0/8.0/9.0
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the OAuth module allows remote authenticated users to hijack OAuth sessions of other users.
network
low complexity
odoo CWE-863
8.8
2017-07-03 CVE-2017-5944 Improper Input Validation vulnerability in Bestpractical Request Tracker
The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated users with certain privileges to execute arbitrary code via a crafted saved search name.
network
low complexity
bestpractical CWE-20
8.8
2017-07-03 CVE-2017-5943 Cross-Site Request Forgery (CSRF) vulnerability in Bestpractical Request Tracker
Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information about cross-site request forgery (CSRF) verification tokens via a crafted URL.
network
low complexity
bestpractical CWE-352
8.8
2017-07-03 CVE-2016-5045 Information Exposure vulnerability in Netapp Oncommand System Manager 8.3/8.3.1/8.3.2
NetApp OnCommand System Manager before 9.0 allows remote attackers to obtain sensitive credentials via vectors related to cluster peering setup.
network
high complexity
netapp CWE-200
8.1
2017-07-03 CVE-2016-3998 Permissions, Privileges, and Access Controls vulnerability in Netapp Altavault
NetApp AltaVault 4.1 and earlier allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol.
network
high complexity
netapp CWE-264
8.1
2017-07-03 CVE-2016-3997 7PK - Security Features vulnerability in Netapp Clustered Data Ontap 8.3.1
NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leveraging failure to enable SMB signing enforcement in its default state.
network
high complexity
netapp CWE-254
7.5
2017-07-03 CVE-2016-3400 7PK - Security Features vulnerability in Netapp Data Ontap 8.1/8.2
NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol.
network
high complexity
netapp CWE-254
7.5
2017-07-02 CVE-2017-8894 HTTP Request Smuggling vulnerability in Aeroadmin 4.1
AeroAdmin 4.1 uses an insecure protocol (HTTP) to perform software updates.
network
high complexity
aeroadmin CWE-444
8.1
2017-07-02 CVE-2017-8893 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Aeroadmin 4.1
AeroAdmin 4.1 uses a function to copy data between two pointers where the size of the data copied is taken directly from a network packet.
network
low complexity
aeroadmin CWE-119
7.5