Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-09-12 CVE-2017-1085 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Freebsd
In FreeBSD before 11.2-RELEASE, an application which calls setrlimit() to increase RLIMIT_STACK may turn a read-only memory region below the stack into a read-write region.
local
low complexity
freebsd CWE-119
7.8
2018-09-12 CVE-2017-1084 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Freebsd
In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections afforded by the guard-page.
network
low complexity
freebsd CWE-119
7.5
2018-09-12 CVE-2017-1083 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Freebsd
In FreeBSD before 11.2-RELEASE, a stack guard-page is available but is disabled by default.
network
low complexity
freebsd CWE-119
7.5
2018-09-12 CVE-2017-1082 Improper Input Validation vulnerability in Freebsd
In FreeBSD 11.x before 11.1-RELEASE and 10.x before 10.4-RELEASE, the qsort algorithm has a deterministic recursion pattern.
network
low complexity
freebsd CWE-20
7.5
2018-09-12 CVE-2018-13807 Improper Input Validation vulnerability in Siemens products
A vulnerability has been identified in SCALANCE X300 (All versions < V4.0.0), SCALANCE X408 (All versions < V4.0.0), SCALANCE X414 (All versions).
network
low complexity
siemens CWE-20
8.6
2018-09-12 CVE-2018-13806 Uncontrolled Search Path Element vulnerability in Siemens TD Keypad Designer
A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions).
local
low complexity
siemens CWE-427
7.8
2018-09-12 CVE-2018-16951 Cross-Site Request Forgery (CSRF) vulnerability in Xunfeng Project Xunfeng 0.2.0
xunfeng 0.2.0 allows command execution via CSRF because masscan.py mishandles backquote characters, a related issue to CVE-2018-16832.
network
low complexity
xunfeng-project CWE-352
8.0
2018-09-12 CVE-2018-16949 Resource Exhaustion vulnerability in multiple products
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2.
network
low complexity
openafs debian CWE-400
7.5
2018-09-12 CVE-2018-16948 Information Exposure vulnerability in multiple products
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2.
network
low complexity
openafs debian CWE-200
7.5
2018-09-12 CVE-2018-16946 Files or Directories Accessible to External Parties vulnerability in LG products
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control.
network
low complexity
lg CWE-552
7.5