Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-03-24 CVE-2016-10149 XXE vulnerability in multiple products
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
network
low complexity
pysaml2-project debian CWE-611
7.5
2017-03-24 CVE-2017-6369 Missing Authorization vulnerability in Firebirdsql Firebird
Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.
network
low complexity
firebirdsql CWE-862
8.8
2017-03-24 CVE-2017-5199 Incorrect Permission Assignment for Critical Resource vulnerability in Solarwinds LOG and Event Manager
The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/contego/scripts/mgrconfig.pl.
network
low complexity
solarwinds CWE-732
8.8
2017-03-24 CVE-2017-5198 Unspecified vulnerability in Solarwinds LOG and Event Manager
SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root access by editing /usr/local/contego/scripts/hostname.sh.
local
low complexity
solarwinds
8.8
2017-03-23 CVE-2017-7246 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Pcre 8.40
Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 268) or possibly have unspecified other impact via a crafted file.
local
low complexity
pcre CWE-119
7.8
2017-03-23 CVE-2017-7245 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Pcre 8.40
Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 4) or possibly have unspecified other impact via a crafted file.
local
low complexity
pcre CWE-119
7.8
2017-03-23 CVE-2015-8625 Information Exposure vulnerability in Mediawiki
MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly sanitize parameters when calling the cURL library, which allows remote attackers to read arbitrary files via an @ (at sign) character in unspecified POST array parameters.
network
low complexity
mediawiki CWE-200
7.5
2017-03-23 CVE-2015-8624 Cross-Site Request Forgery (CSRF) vulnerability in Mediawiki
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623.
network
low complexity
mediawiki CWE-352
8.8
2017-03-23 CVE-2015-8623 Cross-Site Request Forgery (CSRF) vulnerability in Mediawiki
The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.
network
low complexity
mediawiki CWE-352
8.8
2017-03-23 CVE-2016-9399 Reachable Assertion vulnerability in multiple products
The calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
network
low complexity
jasper-project fedoraproject opensuse CWE-617
7.5