Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-07-06 CVE-2018-13406 Integer Overflow or Wraparound vulnerability in multiple products
An integer overflow in the uvesafb_setcmap function in drivers/video/fbdev/uvesafb.c in the Linux kernel before 4.17.4 could result in local attackers being able to crash the kernel or potentially elevate privileges because kmalloc_array is not used.
local
low complexity
linux canonical debian CWE-190
7.8
2018-07-06 CVE-2018-13405 Improper Privilege Management vulnerability in multiple products
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group.
7.8
2018-07-06 CVE-2018-13110 Incorrect Permission Assignment for Critical Resource vulnerability in Adbglobal products
All ADB broadband gateways / routers based on the Epicentro platform are affected by a privilege escalation vulnerability where attackers can gain access to the command line interface (CLI) if previously disabled by the ISP, escalate their privileges, and perform further attacks.
network
high complexity
adbglobal CWE-732
7.5
2018-07-06 CVE-2018-13109 Incorrect Authorization vulnerability in Adbglobal products
All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able to access and manipulate settings within the web interface that are forbidden to end users (e.g., by the ISP).
network
low complexity
adbglobal CWE-863
7.5
2018-07-06 CVE-2018-13108 Unspecified vulnerability in Adbglobal products
All ADB broadband gateways / routers based on the Epicentro platform are affected by a local root jailbreak vulnerability where attackers are able to gain root access on the device, and extract further information such as sensitive configuration data of the ISP (e.g., VoIP credentials) or attack the internal network of the ISP.
local
low complexity
adbglobal
7.8
2018-07-06 CVE-2017-2665 Insufficiently Protected Credentials vulnerability in multiple products
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user.
local
high complexity
mongodb redhat CWE-522
7.0
2018-07-06 CVE-2018-8929 Channel and Path Errors vulnerability in Synology SSL VPN Client
Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted payload.
network
high complexity
synology CWE-417
8.1
2018-07-06 CVE-2018-13348 Improper Input Validation vulnerability in Mercurial
The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data, but actually are not, aka OVE-20180430-0001.
network
low complexity
mercurial CWE-20
7.5
2018-07-06 CVE-2018-13346 Improper Input Validation vulnerability in Mercurial
The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of the original data, aka OVE-20180430-0004.
network
low complexity
mercurial CWE-20
7.5
2018-07-05 CVE-2018-13340 Cross-Site Request Forgery (CSRF) vulnerability in Gleeztech Gleez CMS 1.2.0
Gleez CMS 1.2.0 has CSRF, as demonstrated by a /page/add request.
network
low complexity
gleeztech CWE-352
8.8