Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-08-31 CVE-2018-16276 Out-of-bounds Write vulnerability in multiple products
An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7.
local
low complexity
linux debian canonical CWE-787
7.8
2018-08-31 CVE-2018-7685 Improper Verification of Cryptographic Signature vulnerability in Opensuse Libzypp
The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RPM warning and allow installation, a problem caused by malicious warnings only displayed during download.
local
low complexity
opensuse CWE-347
7.8
2018-08-31 CVE-2018-16275 Improper Neutralization of Formula Elements in a CSV File vulnerability in Opswat Metadefender
OPSWAT MetaDefender before v4.11.2 allows CSV injection.
local
low complexity
opswat CWE-1236
7.8
2018-08-30 CVE-2018-16238 Improper Input Validation vulnerability in Damicms 6.0.1
An issue was discovered in damiCMS V6.0.1.
network
low complexity
damicms CWE-20
7.2
2018-08-30 CVE-2018-16231 Improper Input Validation vulnerability in Michael-Roth-Software Pftp 8.4F
Michael Roth Software Personal FTP Server (PFTP) through 8.4f allows remote attackers to cause a denial of service (daemon crash) via an unspecified sequence of FTP commands.
network
low complexity
michael-roth-software CWE-20
7.5
2018-08-30 CVE-2018-15363 Out-of-bounds Read vulnerability in Trendmicro products
An Out-of-Bounds Read Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations.
local
low complexity
trendmicro CWE-125
7.8
2018-08-30 CVE-2018-10514 Improper Privilege Management vulnerability in Trendmicro products
A Missing Impersonation Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations.
local
low complexity
trendmicro CWE-269
7.8
2018-08-30 CVE-2018-10513 Deserialization of Untrusted Data vulnerability in Trendmicro products
A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations.
local
low complexity
trendmicro CWE-502
7.8
2018-08-30 CVE-2018-15745 Path Traversal vulnerability in Argussurveillance DVR 4.0.0.0
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter.
network
low complexity
argussurveillance CWE-22
7.5
2018-08-30 CVE-2018-15480 Unspecified vulnerability in Mystrom products
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73.
network
low complexity
mystrom
8.8