Vulnerabilities > Microsoft > Windows > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-06-11 CVE-2016-9079 Use After Free vulnerability in multiple products
A use-after-free vulnerability in SVG Animation has been discovered.
network
low complexity
debian redhat mozilla microsoft torproject CWE-416
5.0
2018-06-11 CVE-2016-9072 7PK - Security Features vulnerability in Mozilla Firefox
When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabled by default.
network
low complexity
mozilla microsoft CWE-254
5.0
2018-06-11 CVE-2016-5295 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox
This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke the Mozilla Updater to run malicious local files.
local
low complexity
mozilla microsoft CWE-264
4.6
2018-06-11 CVE-2018-6515 Improper Input Validation vulnerability in Puppet
Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted configuration file an attacker could get pxp-agent to load arbitrary code with privilege escalation.
6.8
2018-06-11 CVE-2018-6514 Untrusted Search Path vulnerability in Puppet
In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a DLL preloading attack, which could lead to a privilege escalation.
6.8
2018-06-08 CVE-2018-4246 Incorrect Type Conversion or Cast vulnerability in Apple products
An issue was discovered in certain Apple products.
6.8
2018-06-08 CVE-2018-4232 Unspecified vulnerability in Apple products
An issue was discovered in certain Apple products.
4.3
2018-06-08 CVE-2018-4222 Out-of-bounds Read vulnerability in Apple products
An issue was discovered in certain Apple products.
6.8
2018-06-08 CVE-2018-4218 Use After Free vulnerability in Apple products
An issue was discovered in certain Apple products.
6.8
2018-06-08 CVE-2018-4214 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple products
An issue was discovered in certain Apple products.
6.8