Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-03-27 CVE-2018-9044 Improper Input Validation vulnerability in Iobit Advanced Systemcare Ultimate 11.0.1.58
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060cc.
local
low complexity
iobit CWE-20
7.8
2018-03-27 CVE-2018-9043 Improper Input Validation vulnerability in Iobit Advanced Systemcare Ultimate 11.0.1.58
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060d0.
local
low complexity
iobit CWE-20
7.8
2018-03-27 CVE-2018-9042 Improper Input Validation vulnerability in Iobit Advanced Systemcare Ultimate 11.0.1.58
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402000.
local
low complexity
iobit CWE-20
7.8
2018-03-27 CVE-2018-9041 Improper Input Validation vulnerability in Iobit Advanced Systemcare Ultimate 11.0.1.58
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402004.
local
low complexity
iobit CWE-20
7.8
2018-03-27 CVE-2018-9040 Improper Input Validation vulnerability in Iobit Advanced Systemcare Ultimate 11.0.1.58
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060c4.
local
low complexity
iobit CWE-20
7.8
2018-03-26 CVE-2018-8802 SQL Injection vulnerability in Unisys Clearpath Eportal Manager and Eportal-2200
SQL injection vulnerability in the management interface in ePortal Manager allows remote attackers to execute arbitrary SQL commands via unspecified parameters.
network
high complexity
unisys CWE-89
8.1
2018-03-26 CVE-2018-7658 Improper Input Validation vulnerability in Softros Network Time System 2.3.4
NTSServerSvc.exe in the server in Softros Network Time System 2.3.4 allows remote attackers to cause a denial of service (daemon crash) by sending exactly 11 bytes.
network
low complexity
softros CWE-20
7.5
2018-03-26 CVE-2017-12410 Race Condition vulnerability in Kaseya Virtual System Administrator
It is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition when Kaseya Virtual System Administrator agent 9.3.0.11 and earlier tries to execute its binaries from working and/or temporary folders.
local
high complexity
kaseya CWE-362
7.4
2018-03-26 CVE-2017-18249 Race Condition vulnerability in multiple products
The add_free_nid function in fs/f2fs/node.c in the Linux kernel before 4.12 does not properly track an allocated nid, which allows local users to cause a denial of service (race condition) or possibly have unspecified other impact via concurrent threads.
local
high complexity
linux debian CWE-362
7.0
2018-03-26 CVE-2018-7673 Unspecified vulnerability in Netiq Identity Manager 4.5
The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack.
network
low complexity
netiq
7.5