Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-04-19 CVE-2017-7978 Information Exposure vulnerability in Samsung Mobile
Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by reading a world-readable log file after an unexpected reboot.
network
low complexity
samsung CWE-200
7.5
2017-04-19 CVE-2017-7976 Integer Overflow or Wraparound vulnerability in Artifex Jbig2Dec 0.13
Artifex jbig2dec 0.13 allows out-of-bounds writes and reads because of an integer overflow in the jbig2_image_compose function in jbig2_image.c during operations on a crafted .jb2 file, leading to a denial of service (application crash) or disclosure of sensitive information from process memory.
local
low complexity
artifex CWE-190
7.1
2017-04-19 CVE-2013-7463 Use of Insufficiently Random Values vulnerability in Aescrypt Project Aescrypt 1.0.0
The aescrypt gem 1.0.0 for Ruby does not randomize the CBC IV for use with the AESCrypt.encrypt and AESCrypt.decrypt functions, which allows attackers to defeat cryptographic protection mechanisms via a chosen plaintext attack.
network
low complexity
aescrypt-project CWE-330
7.5
2017-04-19 CVE-2017-7975 Integer Overflow or Wraparound vulnerability in Artifex Jbig2Dec 0.13
Artifex jbig2dec 0.13, as used in Ghostscript, allows out-of-bounds writes because of an integer overflow in the jbig2_build_huffman_table function in jbig2_huffman.c during operations on a crafted JBIG2 file, leading to a denial of service (application crash) or possibly execution of arbitrary code.
local
low complexity
artifex CWE-190
7.8
2017-04-19 CVE-2017-7963 Allocation of Resources Without Limits or Throttling vulnerability in PHP
The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial of service (memory consumption and application crash) via operations on long strings.
network
low complexity
php CWE-770
7.5
2017-04-19 CVE-2017-7961 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Gnome Libcroco 0.6.11/0.6.12
The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable values of type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CSS file.
local
low complexity
gnome CWE-119
7.8
2017-04-19 CVE-2017-7948 Integer Overflow or Wraparound vulnerability in Artifex Ghostscript 9.21
Integer overflow in the mark_curve function in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via a crafted PostScript document.
local
low complexity
artifex CWE-190
7.8
2017-04-19 CVE-2017-7850 Incorrect Permission Assignment for Critical Resource vulnerability in Tenable Nessus
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode.
local
low complexity
tenable CWE-732
7.8
2017-04-18 CVE-2016-10345 Permissions, Privileges, and Access Controls vulnerability in Phusion Passenger
In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.
local
low complexity
phusion CWE-264
7.8
2017-04-18 CVE-2017-5656 Session Fixation vulnerability in Apache CXF
Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.
network
low complexity
apache CWE-384
7.5