Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-01-27 CVE-2018-6358 Out-of-bounds Write vulnerability in multiple products
The printDefineFont2 function (util/listfdb.c) in libming through 0.4.8 is vulnerable to a heap-based buffer overflow, which may allow attackers to cause a denial of service or unspecified other impact via a crafted FDB file.
network
low complexity
libming debian CWE-787
8.8
2018-01-27 CVE-2018-6357 Cross-site Scripting vulnerability in Acurax Social Media Widget
The acx_asmw_saveorder_callback function in function.php in the acurax-social-media-widget plugin before 3.2.6 for WordPress has CSRF via the recordsArray parameter to wp-admin/admin-ajax.php, with resultant social_widget_icon_array_order XSS.
network
low complexity
acurax CWE-79
8.8
2018-01-27 CVE-2018-6353 OS Command Injection vulnerability in Electrum
The Python console in Electrum through 2.9.4 and 3.x through 3.0.5 supports arbitrary Python code without considering (1) social-engineering attacks in which a user pastes code that they do not understand and (2) code pasted by a physically proximate attacker at an unattended workstation, which makes it easier for attackers to steal Bitcoin via hook code that runs at a later time when the wallet password has been entered, a different vulnerability than CVE-2018-1000022.
local
low complexity
electrum CWE-78
7.8
2018-01-27 CVE-2017-18077 Improper Input Validation vulnerability in Brace Expansion Project Brace Expansion
index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expression Denial of Service (ReDoS) attacks, as demonstrated by an expand argument containing many comma characters.
network
low complexity
brace-expansion-project CWE-20
7.5
2018-01-26 CVE-2016-2983 Improper Input Validation vulnerability in IBM Tealeaf Customer Experience 8.7/8.8/9.0.2
IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker under unusual circumstances to read operational data or TLS session state for any active sessions, cause denial of service, or bypass security.
network
high complexity
ibm CWE-20
8.1
2018-01-26 CVE-2018-6015 Information Exposure vulnerability in Icegram Email Subscribers & Newsletters
An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress.
network
low complexity
icegram CWE-200
7.5
2018-01-26 CVE-2017-14523 Injection vulnerability in Wondercms 2.3.1
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack.
network
low complexity
wondercms CWE-74
7.5
2018-01-26 CVE-2017-14521 Unrestricted Upload of File with Dangerous Type vulnerability in Wondercms 2.3.0/2.3.1
In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.
network
low complexity
wondercms CWE-434
8.8
2018-01-26 CVE-2017-12380 NULL Pointer Dereference vulnerability in multiple products
ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
debian clamav CWE-476
7.5
2018-01-26 CVE-2017-12376 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially execute arbitrary code on an affected device.
local
low complexity
debian clamav CWE-119
7.8