Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-06-07 CVE-2017-7563 Incorrect Permission Assignment for Critical Resource vulnerability in ARM Trusted Firmware
In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism.
network
high complexity
arm CWE-732
8.1
2017-06-07 CVE-2015-7888 Path Traversal vulnerability in Samsung Galaxy S6 Edge Firmware G925Vvru1Aoe2
Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remote attackers to overwrite or create arbitrary files as the system-level user via a ..
network
low complexity
samsung CWE-22
7.5
2017-06-07 CVE-2015-7724 Link Following vulnerability in AMD Fglrx-Driver 14.4.2/15.7
AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack.
local
low complexity
amd CWE-59
7.8
2017-06-07 CVE-2015-7723 Link Following vulnerability in AMD Fglrx-Driver 14.4.2
AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.
local
low complexity
amd CWE-59
7.8
2017-06-07 CVE-2017-7314 Improper Authentication vulnerability in Personify Personify360 E-Business
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1.
network
low complexity
personify CWE-287
7.5
2017-06-07 CVE-2017-7313 Information Exposure vulnerability in Personify Personify360 E-Business
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1.
network
low complexity
personify CWE-200
7.5
2017-06-07 CVE-2017-9469 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory.
network
low complexity
irssi debian CWE-119
7.5
2017-06-07 CVE-2017-9468 NULL Pointer Dereference vulnerability in multiple products
In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer.
network
low complexity
irssi debian CWE-476
7.5
2017-06-06 CVE-2017-9465 Out-of-bounds Read vulnerability in Virustotal Yara 3.6.1
The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from process memory via a crafted file that is mishandled in the yr_re_fast_exec function in libyara/re.c and the _yr_scan_match_callback function in libyara/scan.c.
local
low complexity
virustotal CWE-125
7.1
2017-06-06 CVE-2017-9462 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.
network
low complexity
mercurial debian redhat CWE-732
8.8