Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-06-05 CVE-2018-7884 Untrusted Search Path vulnerability in Displaylink Core Software Cleaner 8.2.1956
An issue was discovered in DisplayLink Core Software Cleaner Application 8.2.1956.
local
low complexity
displaylink CWE-426
7.8
2018-06-05 CVE-2018-10058 Out-of-bounds Write vulnerability in multiple products
The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers.
network
low complexity
cgminer-project bfgminer CWE-787
8.8
2018-06-05 CVE-2018-1000197 Incorrect Authorization vulnerability in Jenkins Black Duck HUB
An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users with Overall/Read permission to read and write the Black Duck Hub plugin configuration.
network
low complexity
jenkins CWE-863
8.1
2018-06-05 CVE-2018-1000194 Path Traversal vulnerability in multiple products
A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master security subsystem protection.
network
low complexity
jenkins oracle CWE-22
8.1
2018-06-05 CVE-2017-7635 Cross-Site Request Forgery (CSRF) vulnerability in Qnap NAS Proxy Server
QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections.
network
low complexity
qnap CWE-352
8.8
2018-06-05 CVE-2018-10601 Out-of-bounds Write vulnerability in Philips products
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow.
high complexity
philips CWE-787
8.2
2018-06-05 CVE-2018-10597 Out-of-bounds Write vulnerability in Philips products
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that allows an unauthenticated attacker to access memory ("write-what-where") from an attacker-chosen device address within the same subnet.
high complexity
philips CWE-787
8.3
2018-06-05 CVE-2018-1000189 Unspecified vulnerability in Jenkins Absint Astree
A command execution vulnerability exists in Jenkins Absint Astree Plugin 1.0.5 and older in AstreeBuilder.java that allows attackers with Overall/Read access to execute a command on the Jenkins master.
network
low complexity
jenkins
8.8
2018-06-05 CVE-2017-7654 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In Eclipse Mosquitto 1.4.15 and earlier, a Memory Leak vulnerability was found within the Mosquitto Broker.
network
low complexity
eclipse debian CWE-772
7.5
2018-06-05 CVE-2018-7943 Improper Authentication vulnerability in Huawei products
There is an authentication bypass vulnerability in some Huawei servers.
network
low complexity
huawei CWE-287
8.8