Vulnerabilities > Microsoft > Windows

DATE CVE VULNERABILITY TITLE RISK
2019-01-09 CVE-2018-16171 Path Traversal vulnerability in Cybozu Remote Service Manager
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code file on the server via unspecified vectors.
6.8
2019-01-09 CVE-2018-16170 Path Traversal vulnerability in Cybozu Remote Service Manager
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors.
network
low complexity
cybozu microsoft CWE-22
6.5
2019-01-03 CVE-2019-5007 NULL Pointer Dereference vulnerability in Foxitsoftware Foxit Reader and Phantompdf
An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows.
5.8
2019-01-03 CVE-2019-5006 NULL Pointer Dereference vulnerability in Foxitsoftware Foxit Reader and Phantompdf
An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows.
4.3
2019-01-03 CVE-2019-5005 Out-of-bounds Write vulnerability in Foxitsoftware Foxit Reader and Phantompdf
An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows.
4.3
2019-01-02 CVE-2018-5197 Improper Input Validation vulnerability in Tobesoft Xplatform 9.2/9.2.1/9.2.2
A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow attacker to perform a command injection attack.
6.8
2018-12-21 CVE-2018-18332 Incorrect Permission Assignment for Critical Resource vulnerability in Trendmicro Officescan XG
A Trend Micro OfficeScan XG weak file permissions vulnerability may allow an attacker to potentially manipulate permissions on some key files to modify other files and folders on vulnerable installations.
network
low complexity
trendmicro microsoft CWE-732
5.0
2018-12-21 CVE-2018-18331 Incorrect Permission Assignment for Critical Resource vulnerability in Trendmicro Officescan XG
A Trend Micro OfficeScan XG weak file permissions vulnerability on a particular folder for a particular group may allow an attacker to alter the files, which could lead to other exploits on vulnerable installations.
network
low complexity
trendmicro microsoft CWE-732
5.0
2018-12-14 CVE-2018-1977 Improper Input Validation vulnerability in IBM DB2 11.1
IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) contains a denial of service vulnerability.
network
low complexity
ibm linux microsoft CWE-20
4.0
2018-12-03 CVE-2018-7115 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HP Intelligent Management Center
HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote buffer overflow in dbman.exe opcode 10001 on Windows.
network
low complexity
hp microsoft CWE-119
5.0