Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2018-03-09 CVE-2017-17330 Missing Release of Resource after Effective Lifetime vulnerability in Huawei Ar3200 Firmware and Ngfw Module Firmware
Huawei AR3200 V200R005C32; V200R006C10; V200R006C11; V200R007C00; V200R007C01; V200R007C02; V200R008C00; V200R008C10; V200R008C20; V200R008C30; NGFW Module V500R001C00; V500R001C20; V500R002C00 have a memory leak vulnerability.
local
low complexity
huawei CWE-772
3.3
2018-03-09 CVE-2017-17329 Missing Release of Resource after Effective Lifetime vulnerability in Huawei Viewpoint 8660 Firmware V100R008C03
Huawei ViewPoint 8660 V100R008C03 have a memory leak vulnerability.
local
low complexity
huawei CWE-772
3.3
2018-03-09 CVE-2017-17325 Unspecified vulnerability in Huawei Hicinema 8.0.3.308/8.0.4.300
Huawei video applications HiCinema with software of 8.0.3.308; 8.0.4.300 have a permission control vulnerability.
network
high complexity
huawei
3.7
2018-03-09 CVE-2017-17321 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei Ensp Firmware
Huawei eNSP software with software of versions earlier than V100R002C00B510 has a buffer overflow vulnerability.
local
low complexity
huawei CWE-119
3.3
2018-03-09 CVE-2017-17280 Information Exposure vulnerability in Huawei Lon-Al00B Firmware Lonal00Bc00
NFC (Near Field Communication) module in Huawei mobile phones with software LON-AL00BC00 has an information leak vulnerability.
low complexity
huawei CWE-200
3.5
2018-03-09 CVE-2017-17149 Unspecified vulnerability in Huawei Hiwallet 5.0.3.100/8.0.0.301
Huawei HiWallet App with the versions before 8.0.4 has an arbitrary lock pattern change vulnerability.
low complexity
huawei
3.9
2018-03-08 CVE-2018-0218 XXE vulnerability in Cisco Secure Access Control Server Solution Engine 5.8(0.8)
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system.
local
low complexity
cisco CWE-611
3.3
2018-03-08 CVE-2018-0207 XXE vulnerability in Cisco Secure Access Control Server Solution Engine 5.8(0.8)
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system.
local
low complexity
cisco CWE-611
3.3
2018-03-06 CVE-2018-5730 LDAP Injection vulnerability in multiple products
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.
network
low complexity
mit fedoraproject debian redhat CWE-90
3.8
2018-03-05 CVE-2017-8164 Improper Input Validation vulnerability in Huawei products
Some Huawei smart phones with software EVA-L09C34B142; EVA-L09C40B196; EVA-L09C432B210; EVA-L09C440B138; EVA-L09C464B150; EVA-L09C530B127; EVA-L09C55B190; EVA-L09C576B150; EVA-L09C635B221; EVA-L09C636B193; EVA-L09C675B130; EVA-L09C688B143; EVA-L09C703B160; EVA-L09C706B145; EVA-L09GBRC555B171; EVA-L09IRLC368B160; EVA-L19C10B190; EVA-L19C185B220; EVA-L19C20B160; EVA-L19C432B210; EVA-L19C636B190; EVA-L29C20B160; EVA-L29C636B191; EVA-TL00C01B198; VIE-L09C02B131; VIE-L09C109B181; VIE-L09C113B170; VIE-L09C150B170; VIE-L09C25B120; VIE-L09C40B181; VIE-L09C432B181; VIE-L09C55B170; VIE-L09C605B131; VIE-L09ITAC555B130; VIE-L29C10B170; VIE-L29C185B181; VIE-L29C605B131; VIE-L29C636B202 have a denial of service (DoS) vulnerability.
local
low complexity
huawei CWE-20
3.3