Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-05-08 CVE-2016-8202 Permissions, Privileges, and Access Controls vulnerability in Broadcom Fabric Operating System
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface.
network
low complexity
broadcom CWE-264
8.8
2017-05-08 CVE-2016-10369 Improper Access Control vulnerability in Lxterminal Project Lxterminal 0.3.0
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).
local
low complexity
lxterminal-project CWE-284
7.8
2017-05-08 CVE-2017-6953 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Gemalto Smartdiag Diagnosis Tool 2.5
Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card" input fields.
local
low complexity
gemalto CWE-119
7.8
2017-05-08 CVE-2017-6051 Uncontrolled Search Path Element vulnerability in Blftech Visualview HMI 9.9.14.0
An Uncontrolled Search Path Element issue was discovered in BLF-Tech LLC VisualView HMI Version 9.9.14.0 and prior.
local
high complexity
blftech CWE-427
7.0
2017-05-08 CVE-2017-8825 NULL Pointer Dereference vulnerability in Libetpan Project Libetpan
A null dereference vulnerability has been found in the MIME handling component of LibEtPan before 1.8, as used in MailCore and MailCore 2.
network
low complexity
libetpan-project CWE-476
7.5
2017-05-08 CVE-2017-8844 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive.
local
low complexity
long-range-zip-project debian CWE-119
7.8
2017-05-08 CVE-2017-8829 Deserialization of Untrusted Data vulnerability in Debian Lintian
Deserialization vulnerability in lintian through 2.5.50.3 allows attackers to trigger code execution by requesting a review of a source package with a crafted YAML file.
local
low complexity
debian CWE-502
7.8
2017-05-07 CVE-2017-8804 Deserialization of Untrusted Data vulnerability in GNU Glibc 2.25
The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remote attackers to cause a denial of service (virtual memory allocation, or memory consumption if an overcommit setting is not used) via a crafted UDP packet to port 111, a related issue to CVE-2017-8779.
network
low complexity
gnu CWE-502
7.5
2017-05-06 CVE-2017-7929 Path Traversal vulnerability in Advantech Webaccess
An Absolute Path Traversal issue was discovered in Advantech WebAccess Version 8.1 and prior.
network
low complexity
advantech CWE-22
7.1
2017-05-06 CVE-2017-7927 Use of Hard-coded Credentials vulnerability in Dahuasecurity products
A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices.
network
low complexity
dahuasecurity CWE-798
7.3