Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-01-29 CVE-2017-18079 NULL Pointer Dereference vulnerability in multiple products
drivers/input/serio/i8042.c in the Linux kernel before 4.12.4 allows attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact because the port->exists value can change after it is validated.
local
low complexity
linux canonical CWE-476
7.8
2018-01-29 CVE-2017-18078 Link Following vulnerability in multiple products
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.
local
low complexity
systemd-project debian opensuse CWE-59
7.8
2018-01-28 CVE-2018-6360 Improper Input Validation vulnerability in multiple products
mpv through 0.28.0 allows remote attackers to execute arbitrary code via a crafted web site, because it reads HTML documents containing VIDEO elements, and accepts arbitrary URLs in a src attribute without a protocol whitelist in player/lua/ytdl_hook.lua.
network
low complexity
mpv debian CWE-20
8.8
2018-01-27 CVE-2018-6359 Use After Free vulnerability in multiple products
The decompileIF function (util/decompile.c) in libming through 0.4.8 is vulnerable to a use-after-free, which may allow attackers to cause a denial of service or unspecified other impact via a crafted SWF file.
network
low complexity
libming debian CWE-416
8.8
2018-01-27 CVE-2018-6358 Out-of-bounds Write vulnerability in multiple products
The printDefineFont2 function (util/listfdb.c) in libming through 0.4.8 is vulnerable to a heap-based buffer overflow, which may allow attackers to cause a denial of service or unspecified other impact via a crafted FDB file.
network
low complexity
libming debian CWE-787
8.8
2018-01-27 CVE-2018-6357 Cross-site Scripting vulnerability in Acurax Social Media Widget
The acx_asmw_saveorder_callback function in function.php in the acurax-social-media-widget plugin before 3.2.6 for WordPress has CSRF via the recordsArray parameter to wp-admin/admin-ajax.php, with resultant social_widget_icon_array_order XSS.
network
low complexity
acurax CWE-79
8.8
2018-01-27 CVE-2018-6353 OS Command Injection vulnerability in Electrum
The Python console in Electrum through 2.9.4 and 3.x through 3.0.5 supports arbitrary Python code without considering (1) social-engineering attacks in which a user pastes code that they do not understand and (2) code pasted by a physically proximate attacker at an unattended workstation, which makes it easier for attackers to steal Bitcoin via hook code that runs at a later time when the wallet password has been entered, a different vulnerability than CVE-2018-1000022.
local
low complexity
electrum CWE-78
7.8
2018-01-27 CVE-2017-18077 Improper Input Validation vulnerability in Brace Expansion Project Brace Expansion
index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expression Denial of Service (ReDoS) attacks, as demonstrated by an expand argument containing many comma characters.
network
low complexity
brace-expansion-project CWE-20
7.5
2018-01-26 CVE-2016-2983 Improper Input Validation vulnerability in IBM Tealeaf Customer Experience 8.7/8.8/9.0.2
IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker under unusual circumstances to read operational data or TLS session state for any active sessions, cause denial of service, or bypass security.
network
high complexity
ibm CWE-20
8.1
2018-01-26 CVE-2018-6015 Information Exposure vulnerability in Icegram Email Subscribers & Newsletters
An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress.
network
low complexity
icegram CWE-200
7.5