Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-06-22 CVE-2018-12648 NULL Pointer Dereference vulnerability in Exempi Project Exempi 2.4.5
The WEBP::GetLE32 function in XMPFiles/source/FormatSupport/WEBP_Support.hpp in Exempi 2.4.5 has a NULL pointer dereference.
network
low complexity
exempi-project CWE-476
7.5
2018-06-22 CVE-2017-7466 Improper Input Validation vulnerability in Redhat Ansible
Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems.
network
low complexity
redhat CWE-20
8.0
2018-06-22 CVE-2018-12642 Incorrect Permission Assignment for Critical Resource vulnerability in Froxlor
Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.
network
low complexity
froxlor CWE-732
7.5
2018-06-22 CVE-2018-12635 Improper Input Validation vulnerability in Circontrol Scada 4.2.4
CirCarLife Scada v4.2.4 allows unauthorized upgrades via requests to the html/upgrade.html and services/system/firmware.upgrade URIs.
network
low complexity
circontrol CWE-20
7.5
2018-06-21 CVE-2018-12631 Path Traversal vulnerability in Redatam
Redatam7 (formerly Redatam WebServer) allows remote attackers to read arbitrary files via /redbin/rpwebutilities.exe/text?LFN=../ directory traversal.
network
low complexity
redatam CWE-22
7.5
2018-06-21 CVE-2018-12613 Improper Authentication vulnerability in PHPmyadmin 4.8.0/4.8.0.1/4.8.1
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server.
network
low complexity
phpmyadmin CWE-287
8.8
2018-06-21 CVE-2018-7683 Information Exposure Through Log Files vulnerability in Microfocus Solutions Business Manager
Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log files.
network
low complexity
microfocus CWE-532
7.5
2018-06-21 CVE-2018-12617 Integer Overflow or Wraparound vulnerability in multiple products
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger a segmentation fault when trying to allocate a large memory chunk.
network
low complexity
qemu canonical debian CWE-190
7.5
2018-06-21 CVE-2017-2672 Improper Privilege Management vulnerability in multiple products
A flaw was found in foreman before version 1.15 in the logging of adding and registering images.
network
low complexity
theforeman redhat CWE-269
8.8
2018-06-21 CVE-2017-2669 Improper Input Validation vulnerability in multiple products
Dovecot before version 2.2.29 is vulnerable to a denial of service.
network
low complexity
dovecot debian CWE-20
7.5