Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-08-08 CVE-2017-10001 Unspecified vulnerability in Oracle Hospitality Simphony 1.7.1
Vulnerability in the Oracle Hospitality Simphony First Edition component of Oracle Hospitality Applications (subcomponent: Core).
network
low complexity
oracle
7.6
2017-08-08 CVE-2017-10000 Improper Privilege Management vulnerability in Oracle Hospitality Reporting and Analytics 8.5.1/9.0.0
Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Reporting).
network
low complexity
oracle CWE-269
7.7
2017-08-08 CVE-2017-12678 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
In TagLib 1.11.1, the rebuildAggregateFrames function in id3v2framefactory.cpp has a pointer to cast vulnerability, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted audio file.
network
low complexity
taglib debian CWE-434
8.8
2017-08-08 CVE-2017-9942 Unspecified vulnerability in Siemens Sipass Integrated 2.65
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated server or SiPass integrated client to potentially obtain credentials from the systems.
local
low complexity
siemens
7.8
2017-08-08 CVE-2017-9941 Unspecified vulnerability in Siemens Sipass Integrated 2.65
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker in a Man-in-the-Middle position between the SiPass integrated server and SiPass integrated clients to read or modify the network communication.
network
high complexity
siemens
7.4
2017-08-08 CVE-2017-9940 Improper Privilege Management vulnerability in Siemens Sipass Integrated 2.65
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with access to a low-privileged user account to read or write files on the file system of the SiPass integrated server over the network.
network
low complexity
siemens CWE-269
8.1
2017-08-08 CVE-2017-9938 Improper Input Validation vulnerability in Siemens Simatic Logon 1.5
A vulnerability was discovered in Siemens SIMATIC Logon (All versions before V1.6) that could allow specially crafted packets sent to the SIMATIC Logon Remote Access service on port 16389/tcp to cause a Denial-of-Service condition.
network
low complexity
siemens CWE-20
7.5
2017-08-08 CVE-2017-6873 Unspecified vulnerability in Siemens Ozw672 Firmware and Ozw772 Firmware
A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack on the integrated web server on port 443/tcp.
network
high complexity
siemens
7.4
2017-08-08 CVE-2017-6870 Unspecified vulnerability in Siemens Simatic Wincc Sm@Rtclient 1.0/1.0.2.1
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2).
network
high complexity
siemens
7.4
2017-08-07 CVE-2017-12669 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick 7.0.62
ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteCALSImage in coders/cals.c.
network
low complexity
imagemagick CWE-772
8.8