Vulnerabilities > Microsoft > Windows

DATE CVE VULNERABILITY TITLE RISK
2018-06-11 CVE-2016-5294 Improper Input Validation vulnerability in Mozilla Firefox, Firefox ESR and Thunderbird
The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process.
local
low complexity
mozilla microsoft CWE-20
2.1
2018-06-11 CVE-2016-5293 Improper Input Validation vulnerability in multiple products
When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local file.
local
low complexity
mozilla microsoft debian CWE-20
2.1
2018-06-11 CVE-2018-6515 Improper Input Validation vulnerability in Puppet
Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted configuration file an attacker could get pxp-agent to load arbitrary code with privilege escalation.
6.8
2018-06-11 CVE-2018-6514 Untrusted Search Path vulnerability in Puppet
In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a DLL preloading attack, which could lead to a privilege escalation.
6.8
2018-06-08 CVE-2018-4246 Incorrect Type Conversion or Cast vulnerability in Apple products
An issue was discovered in certain Apple products.
6.8
2018-06-08 CVE-2018-4232 Unspecified vulnerability in Apple products
An issue was discovered in certain Apple products.
4.3
2018-06-08 CVE-2018-4226 Information Exposure vulnerability in Apple products
An issue was discovered in certain Apple products.
local
low complexity
apple microsoft CWE-200
2.1
2018-06-08 CVE-2018-4225 Improper Input Validation vulnerability in Apple products
An issue was discovered in certain Apple products.
local
low complexity
apple microsoft CWE-20
2.1
2018-06-08 CVE-2018-4224 Information Exposure vulnerability in Apple products
An issue was discovered in certain Apple products.
local
low complexity
apple microsoft CWE-200
2.1
2018-06-08 CVE-2018-4222 Out-of-bounds Read vulnerability in Apple products
An issue was discovered in certain Apple products.
6.8