Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-01-31 CVE-2018-6472 Improper Input Validation vulnerability in Superantispyware 6.0.1254
In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40204c.
local
low complexity
superantispyware CWE-20
7.8
2018-01-31 CVE-2018-6471 Improper Input Validation vulnerability in Superantispyware 6.0.1254
In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C402078.
local
low complexity
superantispyware CWE-20
7.8
2018-01-31 CVE-2018-6462 Out-of-bounds Write vulnerability in Tracker-Software Pdf-Xchange Viewer and Viewer AX SDK
Tracker PDF-XChange Viewer and Viewer AX SDK before 2.5.322.8 mishandle conversion from YCC to RGB colour spaces by calculating on the basis of 1 bpc instead of 8 bpc, which might allow remote attackers to execute arbitrary code via a crafted PDF document.
local
low complexity
tracker-software CWE-787
7.8
2018-01-31 CVE-2018-5996 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code, allows remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.
local
low complexity
7-zip debian CWE-119
7.8
2018-01-31 CVE-2014-1632 Permission Issues vulnerability in Eventum Project Eventum
htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the hostname parameter.
network
high complexity
eventum-project CWE-275
8.1
2018-01-31 CVE-2014-1631 Permission Issues vulnerability in Eventum Project Eventum
Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
network
low complexity
eventum-project CWE-275
7.5
2018-01-31 CVE-2018-6460 Information Exposure vulnerability in Anchorfree Hotspot Shield
Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895.
network
low complexity
anchorfree CWE-200
7.5
2018-01-31 CVE-2018-6384 Unquoted Search Path or Element vulnerability in Nsclient Nsclient++
Unquoted Windows search path vulnerability in NSClient++ before 0.4.1.73 allows non-privileged local users to execute arbitrary code with elevated privileges on the system via a malicious program.exe executable in the %SYSTEMDRIVE% folder.
local
low complexity
nsclient CWE-428
7.8
2018-01-31 CVE-2017-8916 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Cisecurity Cis-Cat PRO Dashboard
In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access.
local
low complexity
cisecurity CWE-640
7.8
2018-01-31 CVE-2018-1000001 Out-of-bounds Write vulnerability in multiple products
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.
local
low complexity
gnu canonical redhat CWE-787
7.8