Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-04-17 CVE-2016-7551 Resource Management Errors vulnerability in multiple products
chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allows remote attackers to cause a denial of service (port exhaustion).
network
low complexity
digium debian CWE-399
7.5
2017-04-17 CVE-2017-7889 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to read or write to kernel memory locations in the first megabyte (and bypass slab-allocation access restrictions) via an application that opens the /dev/mem file, related to arch/x86/mm/init.c and drivers/char/mem.c.
local
low complexity
linux debian canonical CWE-732
7.8
2017-04-17 CVE-2017-7885 Integer Overflow or Wraparound vulnerability in Artifex Jbig2Dec 0.13
Artifex jbig2dec 0.13 has a heap-based buffer over-read leading to denial of service (application crash) or disclosure of sensitive information from process memory, because of an integer overflow in the jbig2_decode_symbol_dict function in jbig2_symbol_dict.c in libjbig2dec.a during operation on a crafted .jb2 file.
local
low complexity
artifex CWE-190
7.1
2017-04-16 CVE-2017-7615 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Mantisbt
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
network
low complexity
mantisbt CWE-640
8.8
2017-04-15 CVE-2017-7881 Cross-Site Request Forgery (CSRF) vulnerability in Bigtreecms Bigtree CMS
BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header.
network
low complexity
bigtreecms CWE-352
8.8
2017-04-14 CVE-2017-7879 SQL Injection vulnerability in Flatcore Flatcore-Cms 1.4.6
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database.
network
low complexity
flatcore CWE-89
7.5
2017-04-14 CVE-2017-7877 Cross-Site Request Forgery (CSRF) vulnerability in Flatcore Flatcore-Cms 1.4.6
CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations.
network
low complexity
flatcore CWE-352
8.8
2017-04-14 CVE-2017-7717 SQL Injection vulnerability in SAP Netweaver Application Server Java 7.40
SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2356504.
network
low complexity
sap CWE-89
8.8
2017-04-14 CVE-2017-7696 Allocation of Resources Without Limits or Throttling vulnerability in SAP SSO Authentication Library 2.0/3.0
SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large values in the width and height parameters to otp_logon_ui_resources/qr, aka SAP Security Note 2389042.
network
low complexity
sap CWE-770
7.5
2017-04-14 CVE-2017-7690 OS Command Injection vulnerability in Proxifier
Proxifier for Mac before 2.19.2, when first run, allows local users to gain privileges by replacing the KLoader binary with a Trojan horse program.
local
low complexity
proxifier CWE-78
7.8