Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-02-22 CVE-2018-7317 Information Exposure vulnerability in Christianwebministries Proclaim 9.1.1
Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/.
network
low complexity
christianwebministries CWE-200
7.5
2018-02-22 CVE-2018-7299 Unspecified vulnerability in Eq-3 Homematic Central Control Unit Ccu2 Firmware 2.29.22
Remote Code Execution in the addon installation process in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows authenticated attackers to create or overwrite arbitrary files or install malicious software on the device.
low complexity
eq-3
8.0
2018-02-22 CVE-2018-7298 Cleartext Transmission of Sensitive Information vulnerability in Eq-3 Homematic Central Control Unit Ccu2 Firmware 2.29.22
In /usr/local/etc/config/addons/mh/loopupd.sh on eQ-3 AG HomeMatic CCU2 2.29.22 devices, software update packages are downloaded via the HTTP protocol, which does not provide any cryptographic protection of the downloaded contents.
network
high complexity
eq-3 CWE-319
8.1
2018-02-22 CVE-2018-1417 Incorrect Permission Assignment for Critical Resource vulnerability in IBM Java SDK
Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code running under a security manager to elevate its privileges.
network
high complexity
ibm CWE-732
8.1
2018-02-22 CVE-2018-1414 SQL Injection vulnerability in IBM products
IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
8.8
2018-02-22 CVE-2018-7408 Incorrect Permission Assignment for Critical Resource vulnerability in Npmjs NPM 5.7.0
An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgrade -g npm" command, and also announced in the vendor's blog without mention of pre-release status).
local
low complexity
npmjs CWE-732
7.8
2018-02-22 CVE-2017-5251 Missing Encryption of Sensitive Data vulnerability in Insteon HUB Firmware
In version 1012 and prior of Insteon's Insteon Hub, the radio transmissions used for communication between the hub and connected devices are not encrypted.
network
high complexity
insteon CWE-311
8.1
2018-02-22 CVE-2018-7285 NULL Pointer Dereference vulnerability in Digium Asterisk
A NULL pointer access issue was discovered in Asterisk 15.x through 15.2.1.
network
low complexity
digium CWE-476
7.5
2018-02-22 CVE-2018-7284 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2.
network
low complexity
digium debian CWE-119
7.5
2018-02-22 CVE-2018-0204 Weak Password Requirements vulnerability in Cisco Prime Collaboration Provisioning 12.1
A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for individual users.
network
low complexity
cisco CWE-521
7.5