Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-06-21 CVE-2017-9778 Allocation of Resources Without Limits or Throttling vulnerability in GNU GDB
GNU Debugger (GDB) 8.0 and earlier fails to detect a negative length field in a DWARF section.
local
low complexity
gnu CWE-770
5.5
2017-06-21 CVE-2017-9130 Out-of-bounds Read vulnerability in Freeware Advanced Audio Coder Project Freeware Advanced Audio Coder 1.28
The faacEncOpen function in libfaac/frame.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted wav file.
5.5
2017-06-21 CVE-2017-9129 Resource Exhaustion vulnerability in Audiocoding Freeware Advanced Audio Coder 1.28
The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (large loop) via a crafted wav file.
local
low complexity
audiocoding CWE-400
5.5
2017-06-20 CVE-2017-3744 Information Exposure Through Log Files vulnerability in multiple products
In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running.
network
low complexity
lenovo ibm CWE-532
6.5
2017-06-20 CVE-2017-3215 Insufficient Session Expiration vulnerability in Milwaukee One-Key
The Milwaukee ONE-KEY Android mobile application uses bearer tokens with an expiration of one year.
network
low complexity
milwaukee CWE-613
5.3
2017-06-19 CVE-2017-9762 Use After Free vulnerability in Radare Radare2 1.5.0
The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted binary file.
local
low complexity
radare CWE-416
5.5
2017-06-19 CVE-2017-9761 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Radare Radare2 1.5.0
The find_eoq function in libr/core/cmd.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
local
low complexity
radare CWE-119
5.5
2017-06-19 CVE-2017-1000377 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Linux Kernel
An issue was discovered in the size of the default stack guard page on PAX Linux (originally from GRSecurity but shipped by other Linux vendors), specifically the default stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects PAX Linux Kernel versions as of June 19, 2017 (specific version information is not available at this time).
local
low complexity
linux CWE-119
5.9
2017-06-19 CVE-2017-1000373 Resource Exhaustion vulnerability in Openbsd
The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times.
network
low complexity
openbsd CWE-400
6.5
2017-06-19 CVE-2017-1000369 Improper Resource Shutdown or Release vulnerability in multiple products
Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution.
local
low complexity
exim debian CWE-404
4.0