Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-08-20 CVE-2018-14079 Information Exposure vulnerability in Wi2Be Smart HP WMT R1.2.20201400922
Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to obtain sensitive information via /Status/SystemStatusRpm.esp.
network
low complexity
wi2be CWE-200
7.5
2018-08-20 CVE-2018-14077 Unspecified vulnerability in Wi2Be Smart HP WMT R1.2.20201400922
Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to backup the device configuration via a direct request to /Maintenance/configfile.cfg.
network
low complexity
wi2be
7.5
2018-08-20 CVE-2018-1000224 Missing Initialization of Resource vulnerability in Godotengine Godot
Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6.
network
low complexity
godotengine CWE-909
7.5
2018-08-20 CVE-2018-1000223 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Surina Soundtouch
soundtouch version up to and including 2.0.0 contains a Buffer Overflow vulnerability in SoundStretch/WavFile.cpp:WavInFile::readHeaderBlock() that can result in arbitrary code execution.
network
low complexity
surina CWE-119
8.8
2018-08-20 CVE-2018-1000222 Double Free vulnerability in multiple products
Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution .
network
low complexity
libgd canonical debian CWE-415
8.8
2018-08-20 CVE-2018-1000216 Double Free vulnerability in Cjson Project Cjson
Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE.
network
low complexity
cjson-project CWE-415
8.8
2018-08-20 CVE-2018-1000215 Missing Release of Resource after Effective Lifetime vulnerability in Cjson Project Cjson
Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service (DoS).
network
low complexity
cjson-project CWE-772
7.5
2018-08-20 CVE-2018-1000657 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Rust-Lang Rust
Rust Programming Language Rust standard library version Commit bfa0e1f58acf1c28d500c34ed258f09ae021893e and later; stable release 1.3.0 and later contains a Buffer Overflow vulnerability in std::collections::vec_deque::VecDeque::reserve() function that can result in Arbitrary code execution, but no proof-of-concept exploit is currently published..
local
low complexity
rust-lang CWE-119
7.8
2018-08-20 CVE-2018-1000656 Improper Input Validation vulnerability in multiple products
The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of service.
network
low complexity
palletsprojects netapp CWE-20
7.5
2018-08-20 CVE-2018-1000650 SQL Injection vulnerability in Librehealth EHR 2.0.0
LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions that can result in Ability to perform malicious database queries.
network
low complexity
librehealth CWE-89
8.8