Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-07-27 CVE-2017-12151 Cryptographic Issues vulnerability in multiple products
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3.
network
high complexity
samba redhat debian hp CWE-310
7.4
2018-07-27 CVE-2018-14603 Cross-Site Request Forgery (CSRF) vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2.
network
low complexity
gitlab CWE-352
8.8
2018-07-27 CVE-2018-14602 Information Exposure vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2.
network
low complexity
gitlab CWE-200
7.5
2018-07-27 CVE-2018-14601 Unspecified vulnerability in Gitlab 11.1.0/11.1.1
An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.2.
network
low complexity
gitlab
7.5
2018-07-26 CVE-2018-14608 Missing Encryption of Sensitive Data vulnerability in Thomsonreuters Ultratax CS 2017
Thomson Reuters UltraTax CS 2017 on Windows has a password protection option; however, the level of protection might be inconsistent with some customers' expectations because the data is directly accessible in cleartext.
network
low complexity
thomsonreuters CWE-311
7.5
2018-07-26 CVE-2018-14607 Missing Encryption of Sensitive Data vulnerability in Thomsonreuters Ultratax CS 2017
Thomson Reuters UltraTax CS 2017 on Windows, in a client/server configuration, transfers customer records and bank account numbers in cleartext over SMBv2, which allows attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (MITM) attacks via unspecified vectors.
network
low complexity
thomsonreuters CWE-311
7.5
2018-07-26 CVE-2018-9068 Use of Hard-coded Credentials vulnerability in multiple products
The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected.
network
low complexity
lenovo ibm CWE-798
7.5
2018-07-26 CVE-2018-10879 A flaw was found in the Linux kernel's ext4 filesystem.
local
low complexity
canonical linux debian redhat
7.8
2018-07-26 CVE-2018-10878 A flaw was found in the Linux kernel's ext4 filesystem.
local
low complexity
canonical linux debian redhat
7.8
2018-07-26 CVE-2017-12150 It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled.
network
high complexity
samba redhat debian
7.4