CVE-2017-5544 (fengine_s5800_firmware)

CVE-2017-5544 (fengine_s5800_firmware)

An issue was discovered on FiberHome Fengine S5800 switches V210R240. An unauthorized attacker can access the device’s SSH service, using a password cracking tool to establish SSH connections quickly. This will trigger an increase in the SSH login timeout (each of the login attempts will occupy a connection slot for a longer time). Once this occurs, legitimate login attempts via SSH/telnet will be refused, resulting in a denial of service; you must restart the device.

Source: CVE-2017-5544 (fengine_s5800_firmware)

CVE-2017-5556 (foxit_reader, phantompdf)

CVE-2017-5556 (foxit_reader, phantompdf)

The ConvertToPDF plugin in Foxit Reader before 8.2 and PhantomPDF before 8.2 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

Source: CVE-2017-5556 (foxit_reader, phantompdf)

CVE-2017-5554 (oxygenos)

CVE-2017-5554 (oxygenos)

An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2. The attacker can reboot the device into the fastboot mode, which could be done without any authentication. A physical attacker can press the "Volume Up" button during device boot, where an attacker with ADB access can issue the adb reboot bootloader command. Then, the attacker can put the platform’s SELinux in permissive mode, which severely weakens it, by issuing: fastboot oem selinux permissive.

Source: CVE-2017-5554 (oxygenos)

CVE-2016-8213 (documentum_administrator, documentum_capital_projects, documentum_taskspace, documentum_webtop)

CVE-2016-8213 (documentum_administrator, documentum_capital_projects, documentum_taskspace, documentum_webtop)

EMC Documentum WebTop Version 6.8, prior to P18 and Version 6.8.1, prior to P06; and EMC Documentum TaskSpace version 6.7SP3, prior to P02; and EMC Documentum Capital Projects Version 1.9, prior to P30 and Version 1.10, prior to P17; and EMC Documentum Administrator Version 7.0, Version 7.1, and Version 7.2 prior to P18 contain a Stored Cross-Site Scripting Vulnerability that could potentially be exploited by malicious users to compromise the affected system.

Source: CVE-2016-8213 (documentum_administrator, documentum_capital_projects, documentum_taskspace, documentum_webtop)