Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-12-07 CVE-2017-17449 Information Exposure vulnerability in Linux Kernel
The __netlink_deliver_tap_skb function in net/netlink/af_netlink.c in the Linux kernel through 4.14.4, when CONFIG_NLMON is enabled, does not restrict observations of Netlink messages to a single net namespace, which allows local users to obtain sensitive information by leveraging the CAP_NET_ADMIN capability to sniff an nlmon interface for all Netlink activity on the system.
local
high complexity
linux CWE-200
4.7
2017-12-06 CVE-2017-17446 Incorrect Conversion between Numeric Types vulnerability in Game-Music-Emu Project Game-Music-Emu 0.6.1
The Mem_File_Reader::read_avail function in Data_Reader.cpp in the Game_Music_Emu library (aka game-music-emu) 0.6.1 does not ensure a non-negative size, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
network
low complexity
game-music-emu-project CWE-681
6.5
2017-12-06 CVE-2017-17440 NULL Pointer Dereference vulnerability in GNU Libextractor 1.6
GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Module) file, as demonstrated by the EXTRACTOR_xm_extract_method function in plugins/xm_extractor.c.
network
low complexity
gnu CWE-476
6.5
2017-12-06 CVE-2017-13148 Improper Input Validation vulnerability in Google Android
A denial of service vulnerability in the Android media framework (libmpeg2).
network
low complexity
google CWE-20
6.5
2017-12-06 CVE-2017-0880 Unspecified vulnerability in Google Android
A denial of service vulnerability in the Android media framework (libskia).
network
low complexity
google
6.5
2017-12-06 CVE-2017-0874 Improper Input Validation vulnerability in Google Android
A denial of service vulnerability in the Android media framework (libavc).
network
low complexity
google CWE-20
6.5
2017-12-06 CVE-2017-0873 Improper Input Validation vulnerability in Google Android
A denial of service vulnerability in the Android media framework (libmpeg2).
network
low complexity
google CWE-20
6.5
2017-12-06 CVE-2017-17383 Cross-site Scripting vulnerability in Jenkins
Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
network
high complexity
jenkins CWE-79
4.7
2017-12-05 CVE-2017-14018 Improper Authentication vulnerability in Ethicon Endo-Surgery Generator Gen11 Firmware
An improper authentication issue was discovered in Johnson & Johnson Ethicon Endo-Surgery Generator Gen11, all versions released before November 29, 2017.
high complexity
ethicon CWE-287
4.8
2017-12-05 CVE-2017-4920 Resource Exhaustion vulnerability in VMWare Nsx-V Edge
The implementation of the OSPF protocol in VMware NSX-V Edge 6.2.x prior to 6.2.8 and NSX-V Edge 6.3.x prior to 6.3.3 doesn't correctly handle the link-state advertisement (LSA).
network
high complexity
vmware CWE-400
5.9