Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-05-24 CVE-2017-9217 NULL Pointer Dereference vulnerability in Systemd Project Systemd
systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty question section.
network
low complexity
systemd-project CWE-476
7.5
2017-05-23 CVE-2017-8311 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Videolan VLC Media Player
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.
local
low complexity
videolan CWE-119
7.8
2017-05-23 CVE-2017-0374 Unspecified vulnerability in Config-Model Project Config-Model
lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a crafted model in the current working directory, related to use of .
local
low complexity
config-model-project
7.8
2017-05-23 CVE-2017-0373 Improper Input Validation vulnerability in Config-Model Project Config-Model
The gen_class_pod implementation in lib/Config/Model/Utils/GenClassPod.pm in Config-Model (aka libconfig-model-perl) before 2.102 has a dangerous "use lib" line, which allows remote attackers to have an unspecified impact via a crafted Debian package file.
local
low complexity
config-model-project CWE-20
7.3
2017-05-23 CVE-2017-2797 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Marklogic 8.06
An exploitable heap overflow vulnerability exists in the ParseEnvironment functionality of AntennaHouse DMC HTMLFilter as used by MarkLogic 8.0-6.
local
low complexity
marklogic CWE-119
7.8
2017-05-23 CVE-2017-2794 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Marklogic 8.06
An exploitable stack-based buffer overflow vulnerability exists in the DHFSummary functionality of AntennaHouse DMC HTMLFilter as used by MarkLogic 8.0-6.
local
low complexity
marklogic CWE-119
7.8
2017-05-23 CVE-2017-2793 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Marklogic 8.06
An exploitable heap corruption vulnerability exists in the UnCompressUnicode functionality of Antenna House DMC HTMLFilter used by MarkLogic 8.0-6.
local
low complexity
marklogic CWE-119
7.8
2017-05-23 CVE-2017-2783 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Marklogic 8.06
An exploitable heap corruption vulnerability exists in the FillRowFormat functionality of Antenna House DMC HTMLFilter that is shipped with MarkLogic 8.0-6.
local
low complexity
marklogic CWE-119
7.8
2017-05-23 CVE-2017-9212 Use of Externally-Controlled Format String vulnerability in Bavarian Motor Works Bluetooth Stack
The Bluetooth stack on the BMW 330i 2011 allows a remote crash of the CD/Multimedia software via %x or %c format string specifiers in a device name.
network
low complexity
bavarian-motor-works CWE-134
7.5
2017-05-23 CVE-2017-9190 Use After Free vulnerability in Autotrace Project Autotrace 0.31.1
libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid free), related to the free_bitmap function in bitmap.c:24:5.
network
low complexity
autotrace-project CWE-416
7.5