Vulnerabilities > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-06-06 | CVE-2018-1456 | XXE vulnerability in IBM products IBM Rhapsody DM 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. | 7.1 |
2018-06-06 | CVE-2018-11813 | Excessive Iteration vulnerability in IJG Libjpeg 9C libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF. | 7.5 |
2018-06-05 | CVE-2018-7884 | Untrusted Search Path vulnerability in Displaylink Core Software Cleaner 8.2.1956 An issue was discovered in DisplayLink Core Software Cleaner Application 8.2.1956. | 7.8 |
2018-06-05 | CVE-2018-10058 | Out-of-bounds Write vulnerability in multiple products The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers. | 8.8 |
2018-06-05 | CVE-2018-1000197 | Incorrect Authorization vulnerability in Jenkins Black Duck HUB An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users with Overall/Read permission to read and write the Black Duck Hub plugin configuration. | 8.1 |
2018-06-05 | CVE-2018-1000194 | Path Traversal vulnerability in multiple products A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master security subsystem protection. | 8.1 |
2018-06-05 | CVE-2017-7635 | Cross-Site Request Forgery (CSRF) vulnerability in Qnap NAS Proxy Server QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections. | 8.8 |
2018-06-05 | CVE-2018-10601 | Out-of-bounds Write vulnerability in Philips products IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow. | 8.2 |
2018-06-05 | CVE-2018-10597 | Out-of-bounds Write vulnerability in Philips products IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that allows an unauthenticated attacker to access memory ("write-what-where") from an attacker-chosen device address within the same subnet. | 8.3 |
2018-06-05 | CVE-2018-1000189 | Unspecified vulnerability in Jenkins Absint Astree A command execution vulnerability exists in Jenkins Absint Astree Plugin 1.0.5 and older in AstreeBuilder.java that allows attackers with Overall/Read access to execute a command on the Jenkins master. | 8.8 |