Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-09-09 CVE-2017-8040 XXE vulnerability in VMWare Single Sign-On for Pivotal Cloud Foundry
In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XXE (XML External Entity) attack was discovered in the Single Sign-On service dashboard.
network
low complexity
vmware CWE-611
6.5
2017-09-09 CVE-2017-5147 Uncontrolled Search Path Element vulnerability in Azeotech Daqfactory
An Uncontrolled Search Path Element issue was discovered in AzeoTech DAQFactory versions prior to 17.1.
local
low complexity
azeotech CWE-427
5.3
2017-09-09 CVE-2017-14223 Resource Exhaustion vulnerability in multiple products
In libavformat/asfdec_f.c in FFmpeg 3.3.3, a DoS in asf_build_simple_index() due to lack of an EOF (End of File) check might cause huge CPU consumption.
network
low complexity
ffmpeg debian CWE-400
6.5
2017-09-09 CVE-2017-14222 Excessive Iteration vulnerability in Ffmpeg 3.3.3
In libavformat/mov.c in FFmpeg 3.3.3, a DoS in read_tfra() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption.
network
low complexity
ffmpeg CWE-834
6.5
2017-09-08 CVE-2017-0793 Information Exposure vulnerability in Google Android
A information disclosure vulnerability in the N/A memory subsystem.
local
low complexity
google CWE-200
5.5
2017-09-08 CVE-2017-0792 Information Exposure vulnerability in Google Android 7.1.2
A information disclosure vulnerability in the Broadcom wi-fi driver.
low complexity
google CWE-200
6.5
2017-09-08 CVE-2017-0780 Unspecified vulnerability in Google Android
A denial of service vulnerability in the Android runtime (android messenger).
local
low complexity
google
5.5
2017-09-08 CVE-2017-0779 Information Exposure vulnerability in Google Android
A information disclosure vulnerability in the Android media framework (audioflinger).
local
low complexity
google CWE-200
5.5
2017-09-08 CVE-2017-0777 Information Exposure vulnerability in Google Android
A information disclosure vulnerability in the Android media framework (n/a).
local
low complexity
google CWE-200
5.5
2017-09-08 CVE-2017-0776 Information Exposure vulnerability in Google Android
A information disclosure vulnerability in the Android media framework (n/a).
local
low complexity
google CWE-200
5.5