Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-01-31 CVE-2017-1000411 Improper Resource Shutdown or Release vulnerability in Opendaylight and Openflow
OpenFlow Plugin and OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, Anil Vishnoi contain a flaw when multiple 'expired' flows take up the memory resource of CONFIG DATASTORE which leads to CONTROLLER shutdown.
network
low complexity
opendaylight CWE-404
7.5
2018-01-31 CVE-2018-6412 Information Exposure vulnerability in Linux Kernel
In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary information leakage for the FBIOPUTCMAP_SPARC and FBIOGETCMAP_SPARC commands.
network
low complexity
linux CWE-200
7.5
2018-01-30 CVE-2018-6408 Cross-Site Request Forgery (CSRF) vulnerability in Conceptronic Cipcamptiwl Firmware and Cipcamptiwl web Firmware
An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices.
network
low complexity
conceptronic CWE-352
8.8
2018-01-30 CVE-2018-6407 Improper Input Validation vulnerability in Conceptronic Cipcamptiwl Firmware and Cipcamptiwl web Firmware
An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices.
network
low complexity
conceptronic CWE-20
7.5
2018-01-30 CVE-2018-6406 Out-of-bounds Read vulnerability in Webmproject Libwebm
The function ParseVP9SuperFrameIndex in common/libwebm_util.cc in libwebm through 2018-01-30 does not validate the child_frame_length data obtained from a .webm file, which allows remote attackers to cause an information leak or a denial of service (heap-based buffer over-read and later out-of-bounds write), or possibly have unspecified other impact.
network
low complexity
webmproject CWE-125
8.8
2018-01-30 CVE-2018-6195 Unspecified vulnerability in Splashing Images Project Splashing Images 1.0/2.0/2.1
admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows authenticated (administrator, editor, or author) remote attackers to conduct PHP Object Injection attacks via crafted serialized data in the 'session' HTTP GET parameter to wp-admin/upload.php.
network
low complexity
splashing-images-project
7.2
2018-01-30 CVE-2018-5441 Improper Input Validation vulnerability in Phoenixcontact products
An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0.
local
low complexity
phoenixcontact CWE-20
7.8
2018-01-30 CVE-2017-1731 Unspecified vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could provide weaker than expected security when using the Administrative Console.
network
low complexity
ibm
8.8
2018-01-30 CVE-2014-4705 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei products
Multiple heap-based buffer overflows in the eSap software platform in Huawei Campus S9300, S7700, S9700, S5300, S5700, S6300, and S6700 series switches; AR150, AR160, AR200, AR1200, AR2200, AR3200, AR530, NetEngine16EX, SRG1300, SRG2300, and SRG3300 series routers; and WLAN AC6005, AC6605, and ACU2 access controllers allow remote attackers to cause a denial of service (device restart) via a crafted length field in a packet.
network
low complexity
huawei CWE-119
7.5
2018-01-30 CVE-2017-17969 Out-of-bounds Write vulnerability in multiple products
Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary code via a crafted ZIP archive.
local
low complexity
7-zip debian CWE-787
7.8