Vulnerabilities > Microsoft > Windows

DATE CVE VULNERABILITY TITLE RISK
2018-03-22 CVE-2017-1677 Deserialization of Untrusted Data vulnerability in IBM DB2
IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execution depending on the classpath.
local
low complexity
ibm linux microsoft CWE-502
4.6
2018-03-22 CVE-2017-1571 Use of a Broken or Risky Cryptographic Algorithm vulnerability in IBM DB2
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
local
low complexity
ibm linux microsoft CWE-327
2.1
2018-03-20 CVE-2018-3626 Information Exposure vulnerability in Intel SGX SDK
Edger8r tool in the Intel SGX SDK before version 2.1.2 (Linux) and 1.9.6 (Windows) may generate code that is susceptible to a side channel potentially allowing a local user to access unauthorized information.
1.9
2018-03-04 CVE-2018-7449 Improper Input Validation vulnerability in Segger Embos/Ip FTP Server 3.22
SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an invalid LIST, STOR, or RETR command.
network
low complexity
segger microsoft CWE-20
5.0
2018-02-18 CVE-2018-7212 Path Traversal vulnerability in Sinatrarb Sinatra 2.0.0/2.0.1
An issue was discovered in rack-protection/lib/rack/protection/path_traversal.rb in Sinatra 2.x before 2.0.1 on Windows.
network
low complexity
sinatrarb microsoft CWE-22
5.0
2018-02-15 CVE-2017-12553 Unspecified vulnerability in HP System Management Homepage
A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
local
high complexity
hp linux microsoft
5.5
2018-02-15 CVE-2017-12552 Unspecified vulnerability in HP System Management Homepage
A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
local
high complexity
hp linux microsoft
5.5
2018-02-15 CVE-2017-12551 Unspecified vulnerability in HP System Management Homepage
A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
local
high complexity
hp linux microsoft
5.5
2018-02-15 CVE-2017-12550 Unspecified vulnerability in HP System Management Homepage
A local security misconfiguration vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
local
high complexity
hp linux microsoft
5.5
2018-02-15 CVE-2017-12549 Improper Authentication vulnerability in HP System Management Homepage
A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
local
high complexity
hp linux microsoft CWE-287
5.5