Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-03-05 CVE-2018-7698 Insufficiently Protected Credentials vulnerability in D-Link Mydlink+ 3.8.5
An issue was discovered in D-Link mydlink+ 3.8.5 build 259 for DCS-933L 1.05.04 and DCS-934L 1.05.04 devices.
network
high complexity
d-link CWE-522
8.1
2018-03-05 CVE-2018-5453 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Moxa products
An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior.
network
low complexity
moxa CWE-119
7.5
2018-03-05 CVE-2017-7633 Information Exposure vulnerability in Qnap Qfinder PRO 6.1.0.0317
QNAP Qfinder Pro 6.1.0.0317 and earlier may expose sensitive information contained in NAS devices.
network
low complexity
qnap CWE-200
7.5
2018-03-05 CVE-2018-0491 Use After Free vulnerability in Torproject TOR
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10.
network
low complexity
torproject CWE-416
7.5
2018-03-05 CVE-2018-0490 NULL Pointer Dereference vulnerability in multiple products
An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10.
network
low complexity
torproject debian CWE-476
7.5
2018-03-05 CVE-2018-7644 Improper Verification of Cryptographic Signature vulnerability in Simplesamlphp
The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp before 1.15.3 incorrectly verifies signatures on SAML assertions, allowing a remote attacker to construct a crafted SAML assertion on behalf of an Identity Provider that would pass as cryptographically valid, thereby allowing them to impersonate a user from that Identity Provider, aka a key confusion issue.
network
low complexity
simplesamlphp CWE-347
7.5
2018-03-05 CVE-2018-1316 Path Traversal vulnerability in Apache ODE
The ODE process deployment web service was sensible to deployment messages with forged names.
network
low complexity
apache CWE-22
7.5
2018-03-05 CVE-2018-1000115 Resource Exhaustion vulnerability in multiple products
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources).
network
low complexity
memcached canonical debian redhat CWE-400
7.5
2018-03-05 CVE-2018-7668 Information Exposure vulnerability in Testlink
TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownload.php.
network
low complexity
testlink CWE-200
7.5
2018-03-04 CVE-2017-18214 Resource Exhaustion vulnerability in multiple products
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.
network
low complexity
momentjs tenable CWE-400
7.5