Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2019-01-16 CVE-2019-2426 Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Networking).
network
high complexity
oracle netapp opensuse hp
3.7
2019-01-16 CVE-2019-2422 Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries).
network
high complexity
oracle canonical netapp redhat debian opensuse hp
3.1
2019-01-11 CVE-2018-16866 An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. 3.3
2019-01-11 CVE-2018-15466 Missing Authentication for Critical Function vulnerability in Cisco Policy Suite for Mobile 12.0.0
A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface.
network
high complexity
cisco CWE-306
3.7
2019-01-08 CVE-2018-1993 Information Exposure vulnerability in IBM Spectrum Scale
IBM Spectrum Scale (GPFS) 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 where the use of Local Read Only Cache (LROC) is enabled may caused read operation on a file to return data from a different file.
local
low complexity
ibm CWE-200
3.3
2018-12-23 CVE-2018-20405 Authorization Bypass Through User-Controlled Key vulnerability in Bigtreecms Bigtree 4.3
BigTree 4.3 allows full path disclosure via authenticated admin/news/ input that triggers a syntax error.
network
low complexity
bigtreecms CWE-639
2.7
2018-12-13 CVE-2018-1804 Session Fixation vulnerability in IBM Security Access Manager
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 does not set the secure attribute on authorization tokens or session cookies.
network
high complexity
ibm CWE-384
3.7
2018-12-12 CVE-2018-1484 Session Fixation vulnerability in IBM Bigfix Platform
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the secure attribute on authorization tokens or session cookies.
network
high complexity
ibm CWE-384
3.7
2018-12-12 CVE-2018-11464 Unspecified vulnerability in Siemens products
A vulnerability has been identified in SINUMERIK 828D V4.7 (All versions < V4.7 SP6 HF1), SINUMERIK 840D sl V4.7 (All versions < V4.7 SP6 HF5), SINUMERIK 840D sl V4.8 (All versions < V4.8 SP3).
network
high complexity
siemens
3.7
2018-12-11 CVE-2018-2497 Unspecified vulnerability in SAP Hana 1.0/2.0
The security audit log of SAP HANA, versions 1.0 and 2.0, does not log SELECT events if these events are part of a statement with the syntax CREATE TABLE <table_name> AS SELECT.
network
low complexity
sap
2.7