Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-03-05 CVE-2018-7713 Reachable Assertion vulnerability in Opencv 3.4.1
The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cause a denial of service (assertion failure) because (size.width <= (1<<20)) may be false.
network
low complexity
opencv CWE-617
7.5
2018-03-05 CVE-2018-7712 Reachable Assertion vulnerability in Opencv 3.4.1
The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cause a denial of service (assertion failure) because (size.height <= (1<<20)) may be false.
network
low complexity
opencv CWE-617
7.5
2018-03-05 CVE-2018-7711 Improper Verification of Cryptographic Signature vulnerability in multiple products
HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an attacker to get invalid signatures accepted as valid by forcing an error during validation.
network
high complexity
simplesamlphp debian CWE-347
8.1
2018-03-05 CVE-2017-18220 Use After Free vulnerability in Graphicsmagick 1.3.26
The ReadOneJNGImage and ReadJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 allow remote attackers to cause a denial of service (magick/blob.c CloseBlob use-after-free) or possibly have unspecified other impact via a crafted file, a related issue to CVE-2017-11403.
network
low complexity
graphicsmagick CWE-416
8.8
2018-03-05 CVE-2017-18218 Use After Free vulnerability in Linux Kernel
In drivers/net/ethernet/hisilicon/hns/hns_enet.c in the Linux kernel before 4.13, local users can cause a denial of service (use-after-free and BUG) or possibly have unspecified other impact by leveraging differences in skb handling between hns_nic_net_xmit_hw and hns_nic_net_xmit.
local
low complexity
linux CWE-416
7.8
2018-03-05 CVE-2018-7698 Insufficiently Protected Credentials vulnerability in D-Link Mydlink+ 3.8.5
An issue was discovered in D-Link mydlink+ 3.8.5 build 259 for DCS-933L 1.05.04 and DCS-934L 1.05.04 devices.
network
high complexity
d-link CWE-522
8.1
2018-03-05 CVE-2018-5453 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Moxa products
An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior.
network
low complexity
moxa CWE-119
7.5
2018-03-05 CVE-2017-7633 Information Exposure vulnerability in Qnap Qfinder PRO 6.1.0.0317
QNAP Qfinder Pro 6.1.0.0317 and earlier may expose sensitive information contained in NAS devices.
network
low complexity
qnap CWE-200
7.5
2018-03-05 CVE-2018-0491 Use After Free vulnerability in Torproject TOR
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10.
network
low complexity
torproject CWE-416
7.5
2018-03-05 CVE-2018-0490 NULL Pointer Dereference vulnerability in multiple products
An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10.
network
low complexity
torproject debian CWE-476
7.5