Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-01-25 CVE-2018-6207 Improper Input Validation vulnerability in Maxpcsecure Anti Virus 19.0.3.019
In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220019.
local
low complexity
maxpcsecure CWE-20
7.8
2018-01-25 CVE-2018-6206 Improper Input Validation vulnerability in Maxpcsecure Anti Virus 19.0.3.019
In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220011.
local
low complexity
maxpcsecure CWE-20
7.8
2018-01-25 CVE-2018-6205 Improper Input Validation vulnerability in Maxpcsecure Anti Virus 19.0.3.019
In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220009.
local
low complexity
maxpcsecure CWE-20
7.8
2018-01-25 CVE-2018-6204 Improper Input Validation vulnerability in Maxpcsecure Anti Virus 19.0.3.019
In Max Secure Anti Virus 19.0.3.019,, the driver file (SDActMon.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220019.
local
low complexity
maxpcsecure CWE-20
7.8
2018-01-25 CVE-2018-6203 Improper Input Validation vulnerability in Escanav Anti-Virus 14.0.1400.2029
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8300210C.
local
low complexity
escanav CWE-20
7.8
2018-01-25 CVE-2018-6202 Improper Input Validation vulnerability in Escanav Anti-Virus 14.0.1400.2029
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020F8.
local
low complexity
escanav CWE-20
7.8
2018-01-25 CVE-2018-6201 Improper Input Validation vulnerability in Escanav Anti-Virus 14.0.1400.2029
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020E0 or 0x830020E4.
local
low complexity
escanav CWE-20
7.8
2018-01-25 CVE-2018-6197 NULL Pointer Dereference vulnerability in multiple products
w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c.
network
low complexity
tats canonical CWE-476
7.5
2018-01-25 CVE-2018-6196 Infinite Loop vulnerability in multiple products
w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a negative indent value.
network
low complexity
tats canonical CWE-835
7.5
2018-01-24 CVE-2018-1048 Improper Encoding or Escaping of Output vulnerability in Redhat Jboss Enterprise Application Platform 7.1.0
It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
network
low complexity
redhat CWE-116
7.5