Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-09-19 CVE-2018-3831 Information Exposure vulnerability in Elastic Elasticsearch
Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API.
network
low complexity
elastic CWE-200
8.8
2018-09-19 CVE-2018-3828 Information Exposure Through Log Files vulnerability in Elastic Cloud Enterprise
Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability.
network
high complexity
elastic CWE-532
7.5
2018-09-19 CVE-2018-3827 Information Exposure Through Log Files vulnerability in Elastic Azure Repository
A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin.
network
high complexity
elastic CWE-532
8.1
2018-09-19 CVE-2017-2876 Classic Buffer Overflow vulnerability in Foscam C1 Firmware 2.52.2.43
An exploitable buffer overflow vulnerability exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43.
network
low complexity
foscam CWE-120
7.5
2018-09-19 CVE-2017-2873 OS Command Injection vulnerability in Foscam C1 Firmware 2.52.2.43
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43.
network
low complexity
foscam CWE-78
7.2
2018-09-19 CVE-2018-17208 OS Command Injection vulnerability in Linksys Velop Firmware 1.1.2.187020
Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cgi-bin/zbtest2.cgi (scripts that can be discovered with binwalk on the firmware, but are not visible in the web interface).
network
low complexity
linksys CWE-78
8.8
2018-09-19 CVE-2018-17205 Reachable Assertion vulnerability in multiple products
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c.
network
low complexity
openvswitch redhat canonical CWE-617
7.5
2018-09-19 CVE-2017-2878 Classic Buffer Overflow vulnerability in Foscam C1 Firmware 2.52.2.43
An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43.
network
low complexity
foscam CWE-120
7.5
2018-09-19 CVE-2017-2855 Classic Buffer Overflow vulnerability in Foscam C1 Firmware 2.52.2.43
An exploitable buffer overflow vulnerability exists in the DDNS client used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43.
network
high complexity
foscam CWE-120
8.1
2018-09-19 CVE-2018-17183 Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code.
local
low complexity
debian canonical artifex redhat
7.8