Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-03-22 CVE-2018-5503 Improper Input Validation vulnerability in F5 Big-Ip Policy Enforcement Manager
On F5 BIG-IP versions 13.0.0 - 13.1.0.3 or 12.0.0 - 12.1.3.1, TMM may restart when processing a specifically crafted page through a virtual server with an associated PEM policy that has content insertion as an action.
network
low complexity
f5 CWE-20
7.5
2018-03-22 CVE-2018-5502 Improper Certificate Validation vulnerability in F5 products
On F5 BIG-IP versions 13.0.0 - 13.1.0.3, attackers may be able to disrupt services on the BIG-IP system with maliciously crafted client certificate.
network
low complexity
f5 CWE-295
7.5
2018-03-22 CVE-2018-5731 Improper Input Validation vulnerability in Heimdalsecurity Heimdal 2.2.190
An issue was discovered in Heimdal PRO 2.2.190.
local
high complexity
heimdalsecurity CWE-20
7.0
2018-03-22 CVE-2018-5349 Incorrect Permission Assignment for Critical Resource vulnerability in Heimdalsecurity Heimdal 2.2.190
A vulnerability has been found in Heimdal PRO v2.2.190, but it is most likely also present in Heimdal FREE and Heimdal CORP.
local
low complexity
heimdalsecurity CWE-732
7.8
2018-03-22 CVE-2017-16772 Improper Input Validation vulnerability in Synology Photo Station
Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote authenticated users to execute arbitrary codes via the prog_id parameter.
network
low complexity
synology CWE-20
8.8
2018-03-22 CVE-2017-0935 Improper Privilege Management vulnerability in UI Edgeos 1.9.1/1.9.1.1
Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the file system leading to sensitive information being exposed.
network
low complexity
ui CWE-269
8.8
2018-03-22 CVE-2017-0934 Improper Privilege Management vulnerability in Ubnt Edgeos
Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of protection of the file system leading to sensitive information being exposed.
network
low complexity
ubnt CWE-269
8.8
2018-03-22 CVE-2017-0933 Cross-Site Request Forgery (CSRF) vulnerability in Ubnt Edgeos
Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability.
network
low complexity
ubnt CWE-352
8.0
2018-03-22 CVE-2017-0932 Improper Privilege Management vulnerability in Ubnt Edgeos
Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the lack of validation on the input of the Feature functionality.
network
low complexity
ubnt CWE-269
8.8
2018-03-22 CVE-2018-0552 Untrusted Search Path vulnerability in Securebrain Phishwall Client 5.1.26
Untrusted search path vulnerability in The installer of PhishWall Client Firefox and Chrome edition for Windows Ver.
local
low complexity
securebrain CWE-426
7.8