Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-10-03 CVE-2014-0043 Information Exposure vulnerability in Apache Wicket 1.5.10/6.13.0
In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library with a known security vulnerability is in use.
network
low complexity
apache CWE-200
5.3
2017-10-02 CVE-2017-14974 NULL Pointer Dereference vulnerability in GNU Binutils 2.29
The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandle the failure of a certain canonicalization step, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to elf32-i386.c and elf64-x86-64.c.
local
low complexity
gnu CWE-476
5.5
2017-10-02 CVE-2017-14970 Missing Release of Resource after Effective Lifetime vulnerability in Openvswitch
In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages.
network
high complexity
openvswitch CWE-772
5.9
2017-10-02 CVE-2017-14957 Cross-site Scripting vulnerability in Blogotext Project Blogotext
Stored XSS vulnerability via a comment in inc/conv.php in BlogoText before 3.7.6 allows an unauthenticated attacker to inject JavaScript.
network
low complexity
blogotext-project CWE-79
6.1
2017-10-02 CVE-2017-14955 Race Condition vulnerability in Checkmk
Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.
network
high complexity
checkmk CWE-362
5.9
2017-10-02 CVE-2017-14954 Information Exposure vulnerability in Linux Kernel
The waitid implementation in kernel/exit.c in the Linux kernel through 4.13.4 accesses rusage data structures in unintended cases, which allows local users to obtain sensitive information, and bypass the KASLR protection mechanism, via a crafted system call.
local
low complexity
linux CWE-200
5.5
2017-10-02 CVE-2017-14941 Information Exposure vulnerability in Jaspersoft Jasperreports 4.7.0
Jaspersoft JasperReports 4.7 suffers from a saved credential disclosure vulnerability, which allows a remote authenticated user to retrieve stored Data Source passwords by accessing flow.html and reading the HTML source code of the page reached in an Edit action for a Data Source connector.
network
low complexity
jaspersoft CWE-200
6.5
2017-09-30 CVE-2017-9794 Information Exposure vulnerability in Apache Geode
When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh command line utility to execute queries.
network
low complexity
apache CWE-200
4.3
2017-09-30 CVE-2017-14940 NULL Pointer Dereference vulnerability in GNU Binutils 2.29
scan_unit_for_symbols in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file.
local
low complexity
gnu CWE-476
5.5
2017-09-30 CVE-2017-14939 Out-of-bounds Read vulnerability in GNU Binutils 2.29
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles a length calculation, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to read_1_byte.
local
low complexity
gnu CWE-125
5.5