Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-05-15 CVE-2018-1087 kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions.
local
low complexity
linux canonical debian redhat
7.8
2018-05-15 CVE-2018-1131 Deserialization of Untrusted Data vulnerability in multiple products
Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations.
network
low complexity
infinispan redhat CWE-502
8.8
2018-05-15 CVE-2018-11102 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libav 12.3
An issue was discovered in Libav 12.3.
network
low complexity
libav CWE-119
7.5
2018-05-15 CVE-2018-11100 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libming
The decompileSETTARGET function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.
network
low complexity
libming CWE-119
8.8
2018-05-15 CVE-2018-11098 Unrestricted Upload of File with Dangerous Type vulnerability in Frog CMS Project Frog CMS 0.9.5
An issue was discovered in Frog CMS 0.9.5.
network
low complexity
frog-cms-project CWE-434
7.2
2018-05-15 CVE-2018-11097 Missing Release of Resource after Effective Lifetime vulnerability in Cstring Project Cstring 20161109
An issue was discovered in cloudwu/cstring through 2016-11-09.
network
low complexity
cstring-project CWE-772
7.5
2018-05-15 CVE-2018-11095 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libming
The decompileJUMP function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact.
network
low complexity
libming CWE-119
8.8
2018-05-14 CVE-2017-14439 Improper Input Validation vulnerability in Moxa Edr-810 Firmware 4.1
Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317.
network
low complexity
moxa CWE-20
7.5
2018-05-14 CVE-2017-14438 Improper Input Validation vulnerability in Moxa Edr-810 Firmware 4.1
Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317.
network
low complexity
moxa CWE-20
7.5
2018-05-14 CVE-2017-14437 NULL Pointer Dereference vulnerability in Moxa Edr-810 Firmware 4.1
An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317.
network
low complexity
moxa CWE-476
7.5