Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-04-04 CVE-2018-1082 Improper Authentication vulnerability in Moodle
A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4.
network
high complexity
moodle CWE-287
8.1
2018-04-04 CVE-2018-9275 Information Exposure vulnerability in Yubico PAM
In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device) and/or DoS (reaching the maximum number of file descriptors).
network
low complexity
yubico CWE-200
8.2
2018-04-04 CVE-2018-1447 Use of Password Hash With Insufficient Computational Effort vulnerability in IBM products
The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords.
network
high complexity
ibm CWE-916
8.1
2018-04-04 CVE-2018-1421 XXE vulnerability in IBM Datapower Gateway
IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
7.1
2018-04-04 CVE-2017-6424 Unspecified vulnerability in Google Android
An elevation of privilege vulnerability in the Qualcomm WiFi driver.
local
high complexity
google
7.0
2018-04-04 CVE-2017-6423 Unspecified vulnerability in Google Android
An elevation of privilege vulnerability in the Qualcomm kyro L2 driver.
local
high complexity
google
7.0
2018-04-04 CVE-2016-8486 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in Qualcomm closed source components.
network
low complexity
google CWE-200
7.5
2018-04-04 CVE-2016-8485 Information Exposure vulnerability in Google Android
An information disclosure vulnerability in Qualcomm closed source components.
network
low complexity
google CWE-200
7.5
2018-04-04 CVE-2016-10235 Improper Input Validation vulnerability in Google Android
A denial of service vulnerability in the Qualcomm WiFi driver.
network
low complexity
google CWE-20
7.5
2018-04-04 CVE-2016-10232 Permissions, Privileges, and Access Controls vulnerability in Google Android
An elevation of privilege vulnerability in the Qualcomm video driver.
local
low complexity
google CWE-264
7.8