Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-04-19 CVE-2018-2750 Unspecified vulnerability in Oracle Enterprise Manager Base Platform 12.1.0.5
Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Products Suite (subcomponent: UI Framework).
network
low complexity
oracle
7.1
2018-04-19 CVE-2018-2746 Unspecified vulnerability in Oracle products
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module).
network
low complexity
oracle
7.1
2018-04-19 CVE-2018-2742 Unspecified vulnerability in Oracle Enterprise Manager OPS Center 12.2.2/12.3.3
Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Products Suite (subcomponent: Framework).
network
low complexity
oracle
7.3
2018-04-19 CVE-2018-2718 Unspecified vulnerability in Oracle Solaris 10.0/11.3
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RPC).
network
low complexity
oracle
7.5
2018-04-19 CVE-2018-1167 OS Command Injection vulnerability in Spotify 1.0.69.336
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player 1.0.69.336.
network
low complexity
spotify CWE-78
8.8
2018-04-18 CVE-2018-10204 Incorrect Permission Assignment for Critical Resource vulnerability in Purevpn 6.0.1
PureVPN 6.0.1 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "sevpnclient" service.
network
low complexity
purevpn CWE-732
8.8
2018-04-18 CVE-2018-10194 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.
local
low complexity
artifex canonical debian redhat CWE-119
7.8
2018-04-18 CVE-2018-7762 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Schneider-Electric products
A vulnerability exists in the web services to process SOAP requests in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200 which could allow result in a buffer overflow.
network
low complexity
schneider-electric CWE-119
7.5
2018-04-18 CVE-2018-7759 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Schneider-Electric products
A buffer overflow vulnerability exists in Schneider Electric's Modicon M340, Modicon Premium, Modicon Quantum PLC, BMXNOR0200.
network
low complexity
schneider-electric CWE-119
7.5
2018-04-18 CVE-2018-7240 Out-of-bounds Write vulnerability in Schneider-Electric products
A vulnerability exists in Schneider Electric's Modicon Quantum in all versions of the communication modules which could allow arbitrary code execution.
network
low complexity
schneider-electric CWE-787
8.8