Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-04-28 CVE-2017-2154 Improper Input Validation vulnerability in Justsystems products
Untrusted search path vulnerability in Hanako 2017, Hanako 2016, Hanako 2015, Hanako Pro 3, JUST Office 3 [Standard], JUST Office 3 [Eco Print Package], JUST Office 3 & Tri-De DataProtect Package, JUST Government 3, JUST Jump Class 2, JUST Frontier 3, JUST School 6 Premium, Hanako Police 5, JUST Police 3, Hanako 2017 trial version allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
justsystems CWE-20
7.8
2017-04-28 CVE-2017-2153 Improper Input Validation vulnerability in Seil products
SEIL/x86 Fuji 1.70 to 5.62, SEIL/BPV4 5.00 to 5.62, SEIL/X1 1.30 to 5.62, SEIL/X2 1.30 to 5.62, SEIL/B1 1.00 to 5.62 allows remote attackers to cause a denial of service via specially crafted IPv4 UDP packets.
network
low complexity
seil CWE-20
7.5
2017-04-28 CVE-2017-2149 Untrusted Search Path vulnerability in Toshiba Flashair
Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series<W-03>) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series<W-02>) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
network
low complexity
toshiba CWE-426
8.8
2017-04-28 CVE-2017-2141 OS Command Injection vulnerability in Iodata Wn-G300R3 Firmware 1.01/1.03
WN-G300R3 firmware 1.03 and earlier allows attackers with administrator rights to execute arbitrary OS commands via unspecified vectors.
network
low complexity
iodata CWE-78
7.2
2017-04-28 CVE-2017-2140 Injection vulnerability in Gaku Tablacus Explorer 17.3.30
Tablacus Explorer 17.3.30 and earlier allows arbitrary scripts to be executed in the context of the application due to specially crafted directory.
network
low complexity
gaku CWE-74
8.8
2017-04-28 CVE-2017-2130 Untrusted Search Path vulnerability in Securebrain Phishwall Client 3.7.13/3.7.8.1
Untrusted search path vulnerability in the installer of PhishWall Client Internet Explorer version Ver.
local
low complexity
securebrain CWE-426
7.8
2017-04-28 CVE-2017-2128 OS Command Injection vulnerability in Information-Technology Promotion Agency Introduction to Safe Website Operation
Security guide for website operators allows remote attackers to execute arbitrary OS commands via specially crafted saved data.
8.8
2017-04-28 CVE-2017-2125 Unspecified vulnerability in Allied Telesis K.K. Centrecom Ar260S V2 Firmware
Privilege escalation vulnerability in CentreCOM AR260S V2 remote authenticated attackers to gain privileges via the guest account.
network
low complexity
allied-telesis-k-k
8.8
2017-04-28 CVE-2017-2120 SQL Injection vulnerability in Wbce CMS
SQL injection vulnerability in the WBCE CMS 1.1.10 and earlier allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
wbce CWE-89
7.2
2017-04-28 CVE-2017-2119 Path Traversal vulnerability in Wbce CMS
Directory traversal vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
wbce CWE-22
8.6