Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-02-13 CVE-2016-4547 Improper Input Validation vulnerability in Samsung Mobile
Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) via a crafted system call to TvoutService_C.
network
low complexity
samsung CWE-20
7.5
2017-02-13 CVE-2016-3995 Information Exposure vulnerability in Cryptopp Crypto++
The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.6.4 may be optimized out by the compiler, which allows attackers to conduct timing attacks.
network
low complexity
cryptopp CWE-200
7.5
2017-02-13 CVE-2016-3616 NULL Pointer Dereference vulnerability in multiple products
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.
network
low complexity
libjpeg-turbo redhat debian canonical CWE-476
8.8
2017-02-13 CVE-2016-2568 Improper Encoding or Escaping of Output vulnerability in multiple products
pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
local
high complexity
freedesktop redhat CWE-116
7.8
2017-02-13 CVE-2016-10026 Improper Access Control vulnerability in Ikiwiki 3.20161219
ikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git and recentchanges plugins and the CGI interface enabled, which allows remote attackers to revert certain changes by leveraging permissions to change the page before the revision was made.
network
low complexity
ikiwiki CWE-284
7.5
2017-02-13 CVE-2016-8495 Information Exposure vulnerability in Fortinet Fortimanager Firmware
An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 allows remote attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack via the Fortisandbox devices probing feature.
network
high complexity
fortinet CWE-200
7.4
2017-02-12 CVE-2017-3302 Use After Free vulnerability in multiple products
Crash in libmysqlclient.so in Oracle MySQL before 5.6.21 and 5.7.x before 5.7.5 and MariaDB through 5.5.54, 10.0.x through 10.0.29, 10.1.x through 10.1.21, and 10.2.x through 10.2.3.
network
low complexity
oracle mariadb debian redhat CWE-416
7.5
2017-02-10 CVE-2016-8713 Out-of-bounds Write vulnerability in Gonitro Nitro PDF PRO 10.5.5.9
A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10.5.9.9.
local
low complexity
gonitro CWE-787
7.8
2017-02-10 CVE-2016-8711 Unspecified vulnerability in Gonitro Nitro PDF PRO 10.5.5.9/10.5.9.9
A potential remote code execution vulnerability exists in the PDF parsing functionality of Nitro Pro 10.
local
low complexity
gonitro
7.8
2017-02-10 CVE-2016-8709 Out-of-bounds Write vulnerability in Gonitro Nitro PDF PRO 10.5.5.9/10.5.9.9
A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10.
local
low complexity
gonitro CWE-787
7.8