Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-04-10 CVE-2018-9918 Uncontrolled Recursion vulnerability in multiple products
libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to cause a denial of service (stack exhaustion), related to the QPDFObjectHandle and QPDF_Dictionary classes, because nesting in direct objects is not restricted.
local
low complexity
qpdf-project canonical CWE-674
7.8
2018-04-10 CVE-2018-9037 Unrestricted Upload of File with Dangerous Type vulnerability in Monstra 3.0.4
Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain .php files.
network
low complexity
monstra CWE-434
8.8
2018-04-10 CVE-2018-2413 Missing Authorization vulnerability in SAP Disclosure Management 10.1
SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
network
low complexity
sap CWE-862
8.8
2018-04-10 CVE-2018-2412 Missing Authorization vulnerability in SAP Disclosure Management 10.1
SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
network
low complexity
sap CWE-862
8.8
2018-04-10 CVE-2018-2409 Session Fixation vulnerability in SAP Cloud Platform 2.0
Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector).
network
low complexity
sap CWE-384
8.8
2018-04-10 CVE-2018-2408 Session Fixation vulnerability in SAP Businessobjects
Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad.
network
low complexity
sap CWE-384
7.3
2018-04-10 CVE-2015-0172 Information Exposure vulnerability in IBM Security Siteprotector System 3.0/3.1.0.0/3.1.1.0
IBM Security SiteProtector System 3.0, 3.1.0 and 3.1.1 allows remote attackers to bypass intended security restrictions and consequently execute unspecified commands and obtain sensitive information via unknown vectors.
network
low complexity
ibm CWE-200
7.5
2018-04-10 CVE-2014-3999 Improper Authentication vulnerability in Horde Ldap
The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user DN.
network
high complexity
horde CWE-287
8.1
2018-04-10 CVE-2014-1946 Permissions, Privileges, and Access Controls vulnerability in Opendocman
OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to themselves via a crafted request to signup.php.
network
low complexity
opendocman CWE-264
8.8
2018-04-10 CVE-2014-0158 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in the JPEG2000 image tile decoder in OpenJPEG before 1.5.2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file because of incorrect j2k_decode, j2k_read_eoc, and tcd_decode_tile interaction, a related issue to CVE-2013-6045.
network
low complexity
uclouvain opensuse CWE-119
8.8