Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-04-06 CVE-2018-7506 Information Exposure vulnerability in Moxa Mxview
The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information.
network
low complexity
moxa CWE-200
7.5
2018-04-06 CVE-2018-1272 Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests.
network
high complexity
vmware oracle
7.5
2018-04-06 CVE-2018-1000156 Improper Input Validation vulnerability in multiple products
GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution.
local
low complexity
gnu canonical debian redhat CWE-20
7.8
2018-04-05 CVE-2017-12090 Resource Exhaustion vulnerability in Rockwellautomation Micrologix 1400 B Firmware
An exploitable denial of service vulnerability exists in the processing of snmp-set commands of the Allen Bradley Micrologix 1400 Series B FRN 21.2 and below.
network
low complexity
rockwellautomation CWE-400
7.5
2018-04-05 CVE-2017-12089 Unspecified vulnerability in Rockwellautomation Micrologix 1400 B Firmware
An exploitable denial of service vulnerability exists in the program download functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before.
network
low complexity
rockwellautomation
7.5
2018-04-05 CVE-2017-12088 Improper Input Validation vulnerability in Rockwellautomation Micrologix 1400 B Firmware
An exploitable denial of service vulnerability exists in the Ethernet functionality of the Allen Bradley Micrologix 1400 Series B FRN 21.2 and below.
network
low complexity
rockwellautomation CWE-20
7.5
2018-04-05 CVE-2017-2861 Out-of-bounds Read vulnerability in Natus Xltek Neuroworks 8
An exploitable Denial of Service vulnerability exists in the use of a return value in the NewProducerStream command in Natus Xltek NeuroWorks 8.
network
low complexity
natus CWE-125
7.5
2018-04-05 CVE-2017-0431 Unspecified vulnerability in Google Android
An elevation of privilege vulnerability in Qualcomm closed source components.
local
low complexity
google
7.8
2018-04-05 CVE-2016-8482 Permissions, Privileges, and Access Controls vulnerability in Google Android
An elevation of privilege vulnerability in the NVIDIA GPU driver.
local
low complexity
google CWE-264
7.8
2018-04-05 CVE-2015-9016 Race Condition vulnerability in Google Android
In blk_mq_tag_to_rq in blk-mq.c in the upstream kernel, there is a possible use after free due to a race condition when a request has been previously freed by blk_mq_complete_request.
local
high complexity
google CWE-362
7.0