Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-02-14 CVE-2017-5970 NULL Pointer Dereference vulnerability in Linux Kernel
The ipv4_pktinfo_prepare function in net/ipv4/ip_sockglue.c in the Linux kernel through 4.9.9 allows attackers to cause a denial of service (system crash) via (1) an application that makes crafted system calls or possibly (2) IPv4 traffic with invalid IP options.
network
low complexity
linux CWE-476
7.5
2017-02-13 CVE-2017-5149 NULL Pointer Dereference vulnerability in Abbott Merlin@Home Firmware 8.0
An issue was discovered in St.
network
high complexity
abbott CWE-476
8.9
2017-02-13 CVE-2016-8358 Origin Validation Error vulnerability in Smiths-Medical Cadd-Solis Medication Safety Software
An issue was discovered in Smiths-Medical CADD-Solis Medication Safety Software, Version 1.0; 2.0; 3.0; and 3.1.
network
high complexity
smiths-medical CWE-346
8.5
2017-02-13 CVE-2017-5169 Cross-Site Request Forgery (CSRF) vulnerability in Hanwha-Security Smart Security Manager 1.5
An issue was discovered in Hanwha Techwin Smart Security Manager Versions 1.5 and prior.
network
high complexity
hanwha-security CWE-352
7.5
2017-02-13 CVE-2017-5168 Path Traversal vulnerability in Hanwha-Security Smart Security Manager 1.5
An issue was discovered in Hanwha Techwin Smart Security Manager Versions 1.5 and prior.
network
high complexity
hanwha-security CWE-22
7.5
2017-02-13 CVE-2017-5167 Use of Hard-coded Credentials vulnerability in Binom3 Universal Multifunctional Electric Power Quality Meter Firmware
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter.
network
low complexity
binom3 CWE-798
8.6
2017-02-13 CVE-2017-5165 Cross-Site Request Forgery (CSRF) vulnerability in Binom3 Universal Multifunctional Electric Power Quality Meter Firmware
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter.
network
low complexity
binom3 CWE-352
7.6
2017-02-13 CVE-2017-5161 Uncontrolled Search Path Element vulnerability in Sielcosistemi Winlog Lite and Winlog PRO
An issue was discovered in Sielco Sistemi Winlog Lite SCADA Software, versions prior to Version 3.02.01, and Winlog Pro SCADA Software, versions prior to Version 3.02.01.
local
high complexity
sielcosistemi CWE-427
7.2
2017-02-13 CVE-2017-5155 Insecure Default Initialization of Resource vulnerability in Schneider-Electric Wonderware Historian 2014R2Sp1P01
An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier.
network
low complexity
schneider-electric CWE-1188
7.3
2017-02-13 CVE-2017-5153 Information Exposure Through Log Files vulnerability in Osisoft PI Coresight and PI web API
An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 integrated install kit.
local
low complexity
osisoft CWE-532
7.8