Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-06-15 CVE-2017-0283 Unspecified vulnerability in Microsoft products
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, Windows Server 2016, Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office Word Viewer, Microsoft Lync 2013 SP1, Skype for Business 2016, Microsoft Silverlight 5 Developer Runtime when installed on Microsoft Windows, and Microsoft Silverlight 5 when installed on Microsoft Windows allows a remote code execution vulnerability due to the way it handles objects in memory, aka "Windows Uniscribe Remote Code Execution Vulnerability".
network
low complexity
microsoft
8.8
2017-06-15 CVE-2017-0260 Unspecified vulnerability in Microsoft Office, Windows 7 and Windows Server 2008
A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability".
local
low complexity
microsoft
7.8
2017-06-15 CVE-2017-0193 Improper Handling of Exceptional Conditions vulnerability in Microsoft products
Windows Hyper-V in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to gain elevated privileges on a target guest operating system when Windows Hyper-V instruction emulation fails to properly enforce privilege levels, aka "Hypervisor Code Integrity Elevation of Privilege Vulnerability".
local
low complexity
microsoft CWE-755
7.8
2017-06-14 CVE-2017-7914 Missing Authorization vulnerability in Rockwellautomation Panelview Plus 6 700-1500 Firmware
A Missing Authorization issue was discovered in Rockwell Automation PanelView Plus 6 700-1500 6.00.04, 6.00.05, 6.00.42, 6.00-20140306, 6.10.20121012, 6.10-20140122, 7.00-20121012, 7.00-20130108, 7.00-20130325, 7.00-20130619, 7.00-20140128, 7.00-20140310, 7.00-20140429, 7.00-20140621, 7.00-20140729, 7.00-20141022, 8.00-20140730, and 8.00-20141023.
network
low complexity
rockwellautomation CWE-862
8.6
2017-06-14 CVE-2017-7910 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Digital Canal Structural Wind Analysis 9.1
A Stack-Based Buffer Overflow issue was discovered in Digital Canal Structural Wind Analysis versions 9.1 and prior.
network
low complexity
digital-canal-structural CWE-119
7.5
2017-06-14 CVE-2017-4981 Improper Certificate Validation vulnerability in Dell Bsafe Cert-C 2.7
EMC RSA BSAFE Cert-C before 2.9.0.5 contains a potential improper certificate processing vulnerability.
network
low complexity
dell CWE-295
7.5
2017-06-14 CVE-2017-8907 Incorrect Authorization vulnerability in Atlassian Bamboo
Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so.
network
low complexity
atlassian CWE-863
8.8
2017-06-14 CVE-2017-0663 Out-of-bounds Write vulnerability in Google Android
A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process.
local
low complexity
google CWE-787
7.8
2017-06-14 CVE-2017-0649 Unspecified vulnerability in Google Android 7.1.2
An elevation of privilege vulnerability in the MediaTek sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
local
high complexity
google
7.0
2017-06-14 CVE-2017-0648 Unspecified vulnerability in Linux Kernel 3.10
An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the context of the kernel.
local
low complexity
linux
7.8