Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-01-18 CVE-2016-6823 Integer Overflow or Wraparound vulnerability in Imagemagick
Integer overflow in the BMP coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (crash) via crafted height and width values, which triggers an out-of-bounds write.
network
low complexity
imagemagick CWE-190
7.5
2017-01-18 CVE-2016-6527 Permissions, Privileges, and Access Controls vulnerability in Samsung Mobile 5.0/5.1/6.0
The SmartCall Activity component in Telecom application on Samsung Note device L(5.0/5.1) and M(6.0) allows attackers to cause a denial of service (crash and reboot) or possibly gain privileges via a malformed serializable object.
local
low complexity
samsung CWE-264
7.8
2017-01-18 CVE-2016-6526 Permissions, Privileges, and Access Controls vulnerability in Samsung Mobile 5.0/5.1/6.0
The SpamCall Activity component in Telecom application on Samsung Note device L(5.0/5.1) and M(6.0) allows attackers to cause a denial of service (crash and reboot) or possibly gain privileges via a malformed serializable object.
local
low complexity
samsung CWE-264
7.8
2017-01-18 CVE-2016-2233 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Hexchat Project Hexchat 2.10.2
Stack-based buffer overflow in the inbound_cap_ls function in common/inbound.c in HexChat 2.10.2 allows remote IRC servers to cause a denial of service (crash) via a large number of options in a CAP LS message.
network
low complexity
hexchat-project CWE-119
7.5
2017-01-18 CVE-2016-2087 Path Traversal vulnerability in Hexchat Project Hexchat 2.11.0
Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a ..
network
high complexity
hexchat-project CWE-22
7.4
2017-01-18 CVE-2014-9910 Permissions, Privileges, and Access Controls vulnerability in Google Android
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
local
high complexity
google CWE-264
7.0
2017-01-18 CVE-2014-9909 Permissions, Privileges, and Access Controls vulnerability in Google Android
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel.
local
high complexity
google CWE-264
7.0
2017-01-17 CVE-2017-5521 Unspecified vulnerability in Netgear products
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices.
network
high complexity
netgear
8.1
2017-01-17 CVE-2017-5520 Unrestricted Upload of File with Dangerous Type vulnerability in Metalgenix Genixcms
The media rename feature in GeniXCMS through 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to rename and execute files with the `.php6`, `.php7` and `.phtml` extensions.
network
low complexity
metalgenix CWE-434
8.8
2017-01-17 CVE-2017-5518 Server-Side Request Forgery (SSRF) vulnerability in Metalgenix Genixcms
The media-file upload feature in GeniXCMS through 0.0.8 allows remote attackers to conduct SSRF attacks via a URL, as demonstrated by a URL with an intranet IP address.
network
low complexity
metalgenix CWE-918
7.4