Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-07-13 CVE-2018-1000206 Cross-Site Request Forgery (CSRF) vulnerability in Jfrog Artifactory
JFrog Artifactory version since 5.11 contains a Cross ite Request Forgery (CSRF) vulnerability in UI rest endpoints that can result in Classic CSRF attack allowing an attacker to perform actions as logged in user.
network
low complexity
jfrog CWE-352
8.8
2018-07-13 CVE-2018-7535 Incorrect Default Permissions vulnerability in Totalav 4.1.7/4.6.19
An issue was discovered in TotalAV v4.1.7.
local
low complexity
totalav CWE-276
7.8
2018-07-13 CVE-2018-1245 Incorrect Authorization vulnerability in EMC RSA Identity Governance and Lifecycle 7.0.1/7.0.2/7.1.0
RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability within the workflow architect component (ACM).
network
low complexity
emc CWE-863
8.8
2018-07-13 CVE-2018-10018 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Gdata-Software Total Security 25.4.0.3
The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a long IsBlackListed argument.
network
low complexity
gdata-software CWE-119
8.8
2018-07-13 CVE-2018-9067 Unspecified vulnerability in Lenovo Help
The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, if exploited, could have led to exposure of approximately 400 email addresses and 8,500 IMEI.
network
low complexity
lenovo
7.5
2018-07-13 CVE-2018-14051 Infinite Loop vulnerability in Libwav Project Libwav
The function wav_read in libwav.c in libwav through 2017-04-20 has an infinite loop.
network
low complexity
libwav-project CWE-835
7.5
2018-07-13 CVE-2018-14046 Out-of-bounds Read vulnerability in Exiv2 0.26
Exiv2 0.26 has a heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp.
network
low complexity
exiv2 CWE-125
8.8
2018-07-13 CVE-2018-14045 Reachable Assertion vulnerability in Surina Soundtouch 2.0.0
The FIRFilter::evaluateFilterMulti function in FIRFilter.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch.
network
low complexity
surina CWE-617
7.5
2018-07-13 CVE-2018-14044 Reachable Assertion vulnerability in Surina Soundtouch 2.0.0
The RateTransposer::setChannels function in RateTransposer.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch.
network
low complexity
surina CWE-617
7.5
2018-07-13 CVE-2018-6969 Out-of-bounds Read vulnerability in VMWare Tools
VMware Tools (10.x and prior before 10.3.0) contains an out-of-bounds read vulnerability in HGFS.
local
high complexity
vmware CWE-125
7.0