Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-07-12 CVE-2017-18155 Improper Input Validation vulnerability in Qualcomm products
While playing HEVC content using HD DMB in Snapdragon Automobile and Snapdragon Mobile in version MSM8996AU, SD 450, SD 625, SD 820, SD 820A, SD 835, an uninitialized variable can be used leading to a kernel fault.
local
low complexity
qualcomm CWE-20
7.8
2018-07-12 CVE-2018-13997 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Codeplea Genann 20180708
Genann through 2018-07-08 has a SEGV in genann_run in genann.c.
network
low complexity
codeplea CWE-119
7.5
2018-07-12 CVE-2018-10895 Cross-Site Request Forgery (CSRF) vulnerability in Qutebrowser
qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs.
network
low complexity
qutebrowser CWE-352
8.8
2018-07-11 CVE-2018-11049 Uncontrolled Search Path Element vulnerability in multiple products
RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability.
local
low complexity
emc rsa CWE-427
7.3
2018-07-11 CVE-2018-0032 Improper Input Validation vulnerability in Juniper Junos
The receipt of a crafted BGP UPDATE can lead to a routing process daemon (RPD) crash and restart.
network
low complexity
juniper CWE-20
7.5
2018-07-11 CVE-2018-0030 Resource Exhaustion vulnerability in Juniper Junos
Receipt of a specific MPLS packet may cause MPC7/8/9, PTX-FPC3 (FPC-P1, FPC-P2) line cards or PTX1K to crash and restart.
network
low complexity
juniper CWE-400
7.5
2018-07-11 CVE-2018-0026 Unspecified vulnerability in Juniper Junos 15.1/15.1X8
After Junos OS device reboot or upgrade, the stateless firewall filter configuration may not take effect.
network
low complexity
juniper
7.5
2018-07-11 CVE-2018-0025 Unspecified vulnerability in Juniper Junos 12.1X46/12.3X48/15.1X49
When an SRX Series device is configured to use HTTP/HTTPS pass-through authentication services, a client sending authentication credentials in the initial HTTP/HTTPS session is at risk that these credentials may be captured during follow-on HTTP/HTTPS requests by a malicious actor through a man-in-the-middle attack or by authentic servers subverted by malicious actors.
network
high complexity
juniper
8.1
2018-07-11 CVE-2018-0024 Improper Privilege Management vulnerability in Juniper Junos
An Improper Privilege Management vulnerability in a shell session of Juniper Networks Junos OS allows an authenticated unprivileged attacker to gain full control of the system.
local
low complexity
juniper CWE-269
7.8
2018-07-11 CVE-2018-3936 Out-of-bounds Write vulnerability in Antennahouse Office Server Document Converter 6.1
In Antenna House Office Server Document Converter version V6.1 Pro MR2 for Linux64 (6,1,2018,0312), a crafted Microsoft Word (DOC) document can lead to an out-of-bounds write, resulting in remote code execution.
local
low complexity
antennahouse CWE-787
7.8