Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-09-08 CVE-2018-16715 Incorrect Permission Assignment for Critical Resource vulnerability in Absolute Ctes Windows Agent 1.0.0.1479
An issue was discovered in Absolute Software CTES Windows Agent through 1.0.0.1479.
network
low complexity
absolute CWE-732
8.8
2018-09-07 CVE-2018-16454 Improper Input Validation vulnerability in Currency Converter Script Project Currency Converter Script 2.0.5
PHP Scripts Mall Currency Converter Script 2.0.5 allows remote attackers to cause a denial of service (web-interface change) via an inverted comma.
network
low complexity
currency-converter-script-project CWE-20
7.5
2018-09-07 CVE-2018-15552 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Theethereumlottery the Ethereum Lottery
The "PayWinner" function of a simplelottery smart contract implementation for The Ethereum Lottery, an Ethereum gambling game, generates a random value with publicly readable variable "maxTickets" (which is private, yet predictable and readable by the eth.getStorageAt function).
network
low complexity
theethereumlottery CWE-338
7.5
2018-09-07 CVE-2018-15483 Improper Input Validation vulnerability in Kone Group Controller Firmware
An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5.
network
low complexity
kone CWE-20
7.5
2018-09-07 CVE-2018-12897 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Solarwinds Dameware Mini Remote Control
SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.
local
low complexity
solarwinds CWE-119
7.8
2018-09-07 CVE-2017-17691 Insufficiently Protected Credentials vulnerability in Contronics Homeputer CL Studio FUR Homematic
Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances, which allows remote attackers to obtain sensitive information via a man in the middle attack.
network
high complexity
contronics CWE-522
8.1
2018-09-07 CVE-2018-16667 Out-of-bounds Read vulnerability in Contiki-Ng Contiki-Ng.
An issue was discovered in Contiki-NG through 4.1.
local
high complexity
contiki-ng CWE-125
7.0
2018-09-07 CVE-2018-16666 Out-of-bounds Write vulnerability in Contiki-Ng Contiki-Ng.
An issue was discovered in Contiki-NG through 4.1.
local
low complexity
contiki-ng CWE-787
7.8
2018-09-07 CVE-2018-16664 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Contiki-Ng Contiki-Ng.
An issue was discovered in Contiki-NG through 4.1.
local
high complexity
contiki-ng CWE-119
7.0
2018-09-07 CVE-2018-16663 Out-of-bounds Write vulnerability in Contiki-Ng Contiki-Ng.
An issue was discovered in Contiki-NG through 4.1.
local
low complexity
contiki-ng CWE-787
7.8