Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2017-11-22 CVE-2017-2705 Unspecified vulnerability in Huawei P9 Firmware
Huawei P9 smartphones with software versions earlier before EVA-AL10C00B365, versions earlier before EVA-AL00C00B365, versions earlier before EVA-CL00C92B365, versions earlier before EVA-DL00C17B365, versions earlier before EVA-TL00C01B365 have a phone activation bypass vulnerability.
low complexity
huawei
2.4
2017-11-22 CVE-2017-2701 Insufficient Verification of Data Authenticity vulnerability in Huawei Mate 9 Firmware Mhaal00Ac00B125
Mate 9 with software MHA-AL00AC00B125 has a denial of service (DoS) vulnerability.
local
low complexity
huawei CWE-345
3.3
2017-11-22 CVE-2017-2694 Permission Issues vulnerability in Huawei Vmall
The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call.
local
low complexity
huawei CWE-275
3.3
2017-11-22 CVE-2017-15528 Improper Certificate Validation vulnerability in Norton Install Norton Security
Prior to v 7.6, the Install Norton Security (INS) product can be susceptible to a certificate spoofing vulnerability, which is a type of attack whereby a maliciously procured certificate binds the public key of an attacker to the domain name of the target.
network
high complexity
norton CWE-295
3.7
2017-11-16 CVE-2017-1088 Information Exposure vulnerability in Freebsd
In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p4, 11.0-RELEASE-p15, 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24, the kernel does not properly clear the memory of the kld_file_stat structure before filling the data.
local
low complexity
freebsd CWE-200
3.3
2017-11-16 CVE-2017-1086 Information Exposure vulnerability in Freebsd
In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p4, 11.0-RELEASE-p15, 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24, not all information in the struct ptrace_lwpinfo is relevant for the state of any thread, and the kernel does not fill the irrelevant bytes or short strings.
local
low complexity
freebsd CWE-200
3.3
2017-11-15 CVE-2017-11874 Unspecified vulnerability in Microsoft Chakracore and Edge
Microsoft Edge in Microsoft Windows 10 1703, 1709, Windows Server, version 1709, and ChakraCore allows an attacker to bypass Control Flow Guard (CFG) to run arbitrary code on a target system, due to how Microsoft Edge handles accessing memory in code compiled by the Edge Just-In-Time (JIT) compiler, aka "Microsoft Edge Security Feature Bypass Vulnerability".
network
high complexity
microsoft
3.1
2017-11-15 CVE-2017-11850 Information Exposure vulnerability in Microsoft products
Microsoft Graphics Component in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to log on to an affected system and run a specially crafted application due to improper handling of objects in memory, aka "Microsoft Graphics Component Information Disclosure Vulnerability".
local
high complexity
microsoft CWE-200
2.5
2017-11-15 CVE-2017-11833 Information Exposure vulnerability in Microsoft Edge
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to determine the origin of all webpages in the affected browser, due to how Microsoft Edge handles cross-origin requests, aka "Microsoft Edge Information Disclosure Vulnerability".
network
high complexity
microsoft CWE-200
3.1
2017-11-15 CVE-2017-11791 Information Exposure vulnerability in Microsoft Chakracore, Edge and Internet Explorer
ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability".
network
high complexity
microsoft CWE-200
3.1