Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-04-18 CVE-2014-10044 Improper Validation of Array Index vulnerability in Qualcomm products
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, SD 210/SD 212/SD 205, SD 400, SD 617, SD 800, and SD 820, in the time daemon, unauthorized users can potentially modify system time and cause an array index to be out-of-bound.
network
low complexity
qualcomm CWE-129
7.5
2018-04-18 CVE-2014-10043 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qualcomm products
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, and SD 800, while reading PlayReady rights string information from command buffer (which is sent from non-secure side), if length of rights string is very large, a buffer over read occurs, exposing TZ App memory to non-secure side.
network
low complexity
qualcomm CWE-119
7.5
2018-04-18 CVE-2018-5342 Incorrect Permission Assignment for Critical Resource vulnerability in Zohocorp Manageengine Desktop Central 10.0.124/10.0.184
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a superuser account.
network
low complexity
zohocorp CWE-732
7.2
2018-04-18 CVE-2018-5340 Unspecified vulnerability in Zohocorp Manageengine Desktop Central 10.0.124/10.0.184
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an account with permission to write to the filesystem via SQL queries).
network
low complexity
zohocorp
7.2
2018-04-18 CVE-2018-8736 Unspecified vulnerability in Nagios XI
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escalating to root.
network
low complexity
nagios
8.8
2018-04-18 CVE-2018-8735 OS Command Injection vulnerability in Nagios XI
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command injection.
network
low complexity
nagios CWE-78
8.8
2018-04-18 CVE-2018-10193 Resource Exhaustion vulnerability in Logmein Lastpass
LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser hang) via an HTML document because the resource consumption of onloadwff.js grows with the number of INPUT elements.
network
low complexity
logmein CWE-400
7.5
2018-04-17 CVE-2018-6798 Out-of-bounds Read vulnerability in multiple products
An issue was discovered in Perl 5.22 through 5.26.
network
low complexity
debian perl canonical redhat CWE-125
7.5
2018-04-17 CVE-2018-10190 Improper Privilege Management vulnerability in Londontrustmedia Private Internet Access 77
A vulnerability in London Trust Media Private Internet Access (PIA) VPN Client v77 for Windows could allow an unauthenticated, local attacker to run executable files with elevated privileges.
local
low complexity
londontrustmedia CWE-269
7.8
2018-04-17 CVE-2018-10189 Information Exposure vulnerability in Mautic
An issue was discovered in Mautic 1.x and 2.x before 2.13.0.
network
low complexity
mautic CWE-200
7.5