Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-03-22 CVE-2018-0542 Path Traversal vulnerability in Webproxy Project Webproxy 1.7.8
Directory traversal vulnerability in WebProxy version 1.7.8 allows an attacker to read arbitrary files via unspecified vectors.
network
low complexity
webproxy-project CWE-22
7.5
2018-03-22 CVE-2018-0540 Untrusted Search Path vulnerability in VIX Project VIX 2.21.148.0
Untrusted search path vulnerability in ViX version 2.21.148.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
vix-project CWE-426
7.8
2018-03-22 CVE-2018-1448 Unspecified vulnerability in IBM DB2
IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner.
local
low complexity
ibm
7.1
2018-03-22 CVE-2017-1677 Deserialization of Untrusted Data vulnerability in IBM DB2
IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execution depending on the classpath.
local
low complexity
ibm CWE-502
7.8
2018-03-22 CVE-2018-8909 Path Traversal vulnerability in Wire
The Wire application before 2018-03-07 for Android allows attackers to write to pathnames outside of the downloads directory via a ../ in a filename of a received file, related to AssetService.scala.
network
low complexity
wire CWE-22
7.5
2018-03-22 CVE-2018-8905 Out-of-bounds Write vulnerability in multiple products
In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF file, as demonstrated by tiff2ps.
network
low complexity
libtiff debian canonical redhat CWE-787
8.8
2018-03-22 CVE-2018-8904 Improper Input Validation vulnerability in Windows Optimization Master Project Windows Optimization Master 7.99.13.604
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002000.
7.8
2018-03-22 CVE-2018-8896 Improper Input Validation vulnerability in 2345 Security Guard Project 2345 Security Guard 3.6
In 2345 Security Guard 3.6, the driver file (2345DumpBlock.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222044.
local
low complexity
2345-security-guard-project CWE-20
7.8
2018-03-22 CVE-2018-8895 Improper Input Validation vulnerability in 2345 Security Guard Project 2345 Security Guard 3.6
In 2345 Security Guard 3.6, the driver file (2345DumpBlock.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222040.
local
low complexity
2345-security-guard-project CWE-20
7.8
2018-03-22 CVE-2018-8894 Improper Input Validation vulnerability in 2345 Security Guard Project 2345 Security Guard 3.6
In 2345 Security Guard 3.6, the driver file (2345BdPcSafe.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222108.
local
low complexity
2345-security-guard-project CWE-20
7.8