Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-03-28 CVE-2018-0158 Memory Leak vulnerability in Cisco IOS and IOS XE
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition.
network
low complexity
cisco CWE-401
8.6
2018-03-28 CVE-2018-0157 Unspecified vulnerability in Cisco IOS XE
A vulnerability in the Zone-Based Firewall code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a device to reload.
network
low complexity
cisco
8.6
2018-03-28 CVE-2018-0156 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
7.5
2018-03-28 CVE-2018-0155 Improper Handling of Exceptional Conditions vulnerability in Cisco IOS and IOS XE
A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial of service (DoS) condition.
network
low complexity
cisco CWE-755
8.6
2018-03-28 CVE-2018-0154 Unspecified vulnerability in Cisco IOS
A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco
7.5
2018-03-28 CVE-2018-0152 Insufficient Session Expiration vulnerability in Cisco IOS XE 16.1.1
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to gain elevated privileges on an affected device.
network
low complexity
cisco CWE-613
8.8
2018-03-28 CVE-2018-8885 Race Condition vulnerability in Canonical Screen-Resolution-Extra and Ubuntu Linux
screenresolution-mechanism in screen-resolution-extra 0.17.2 does not properly use the PolicyKit D-Bus API, which allows local users to bypass intended access restrictions by leveraging a race condition via a setuid or pkexec process that is mishandled in a PolicyKitService._check_permission call.
local
high complexity
canonical CWE-362
7.0
2018-03-28 CVE-2018-8820 SQL Injection vulnerability in Square-9 Globalforms 6.2
An issue was discovered in Square 9 GlobalForms 6.2.x.
network
high complexity
square-9 CWE-89
7.5
2018-03-28 CVE-2018-1064 Resource Exhaustion vulnerability in multiple products
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
network
low complexity
debian redhat CWE-400
7.5
2018-03-28 CVE-2017-11509 SQL Injection vulnerability in multiple products
An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement.
network
low complexity
firebirdsql debian CWE-89
8.8