Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-09-20 CVE-2018-15832 Improper Input Validation vulnerability in Ubisoft Uplay 63.0.5699.0
upc.exe in Ubisoft Uplay Desktop Client versions 63.0.5699.0 allows remote attackers to execute arbitrary code.
network
low complexity
ubisoft CWE-20
8.8
2018-09-20 CVE-2018-6505 Unspecified vulnerability in HP Arcsight Management Center 2.0/2.9.1
A potential Unauthenticated File Download vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81.
network
low complexity
hp
7.5
2018-09-20 CVE-2018-6504 Cross-Site Request Forgery (CSRF) vulnerability in Microfocus Arcsight Management Center
A potential Cross-Site Request Forgery (CSRF) vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81.
network
low complexity
microfocus CWE-352
8.8
2018-09-20 CVE-2018-14827 Resource Exhaustion vulnerability in Rockwellautomation Rslinx
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior.
network
low complexity
rockwellautomation CWE-400
7.5
2018-09-20 CVE-2018-14821 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Rockwellautomation Rslinx
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior.
network
low complexity
rockwellautomation CWE-119
7.5
2018-09-20 CVE-2018-14796 Missing Authentication for Critical Function vulnerability in Tec4Data Smartcooler Firmware
Tec4Data SmartCooler, all versions prior to firmware 180806, the device responds to a remote unauthenticated reboot command that may be used to perform a denial of service attack.
network
low complexity
tec4data CWE-306
7.5
2018-09-20 CVE-2018-6500 Path Traversal vulnerability in HP Arcsight Management Center 2.0/2.9.1
A potential Directory Traversal Security vulnerability has been identified in ArcSight Management Center (ArcMC) in all versions prior to 2.81.
network
low complexity
hp CWE-22
7.5
2018-09-20 CVE-2018-3865 Classic Buffer Overflow vulnerability in Samsung Sth-Eth-250 Firmware 0.20.17
An exploitable buffer overflow vulnerability exists in the Samsung WifiScan handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17.
network
low complexity
samsung CWE-120
8.8
2018-09-20 CVE-2018-3864 Classic Buffer Overflow vulnerability in Samsung Sth-Eth-250 Firmware 0.20.17
An exploitable buffer overflow vulnerability exists in the Samsung WifiScan handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17.
network
low complexity
samsung CWE-120
8.8
2018-09-20 CVE-2018-1674 SQL Injection vulnerability in IBM products
IBM Business Process Manager 8.5 through 8.6 and 18.0.0.0 through 18.0.0.1 are vulnerable to SQL injection.
network
low complexity
ibm CWE-89
8.8