Total
9398 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-17952 | 1 Php Multivendor Ecommerce Project | 1 Php Multivendor Ecommerce | 2018-04-13 | 5.0 MEDIUM | 8.6 HIGH |
PHP Scripts Mall PHP Multivendor Ecommerce has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address. | |||||
CVE-2017-15667 | 1 Flexense | 1 Sysgauge | 2018-04-13 | 5.0 MEDIUM | 7.5 HIGH |
In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9221. | |||||
CVE-2018-8711 | 1 Woocommerce-filter | 1 Woocommerce Products Filter | 2018-04-12 | 7.5 HIGH | 9.8 CRITICAL |
A local file inclusion issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The vulnerability is due to the lack of args/input validation on render_html before allowing it to be called by extract(), a PHP built-in function. Because of this, the supplied args/input can be used to overwrite the $pagepath variable, which then could lead to a local file inclusion attack. | |||||
CVE-2018-8904 | 1 Windows Optimization Master Project | 1 Windows Optimization Master | 2018-04-12 | 6.1 MEDIUM | 7.8 HIGH |
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002000. | |||||
CVE-2018-8050 | 1 Afflib Project | 1 Afflib | 2018-04-12 | 4.3 MEDIUM | 6.5 MEDIUM |
The af_get_page() function in lib/afflib_pages.cpp in AFFLIB (aka AFFLIBv3) through 3.7.16 allows remote attackers to cause a denial of service (segmentation fault) via a corrupt AFF image that triggers an unexpected pagesize value. | |||||
CVE-2018-8876 | 1 2345 Security Guard Project | 1 2345 Security Guard | 2018-04-12 | 6.1 MEDIUM | 7.8 HIGH |
In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222098. | |||||
CVE-2018-8873 | 1 2345 Security Guard Project | 1 2345 Security Guard | 2018-04-12 | 6.1 MEDIUM | 7.8 HIGH |
In 2345 Security Guard 3.6, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222040. | |||||
CVE-2018-8874 | 1 2345 Security Guard Project | 1 2345 Security Guard | 2018-04-12 | 6.1 MEDIUM | 7.8 HIGH |
In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222054. | |||||
CVE-2018-8875 | 1 2345 Security Guard Project | 1 2345 Security Guard | 2018-04-12 | 6.1 MEDIUM | 7.8 HIGH |
In 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x0022209c. | |||||
CVE-2018-8896 | 1 2345 Security Guard Project | 1 2345 Security Guard | 2018-04-12 | 6.1 MEDIUM | 7.8 HIGH |
In 2345 Security Guard 3.6, the driver file (2345DumpBlock.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222044. | |||||
CVE-2018-8895 | 1 2345 Security Guard Project | 1 2345 Security Guard | 2018-04-12 | 6.1 MEDIUM | 7.8 HIGH |
In 2345 Security Guard 3.6, the driver file (2345DumpBlock.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222040. | |||||
CVE-2018-8894 | 1 2345 Security Guard Project | 1 2345 Security Guard | 2018-04-12 | 6.1 MEDIUM | 7.8 HIGH |
In 2345 Security Guard 3.6, the driver file (2345BdPcSafe.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222108. | |||||
CVE-2018-8765 | 1 2345 Security Guard Project | 1 2345 Security Guard | 2018-04-12 | 6.1 MEDIUM | 7.8 HIGH |
In 2345 Security Guard 3.6, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222018. | |||||
CVE-2017-6464 | 1 Ntp | 1 Ntp | 2018-04-12 | 4.0 MEDIUM | 6.5 MEDIUM |
NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malformed mode configuration directive. | |||||
CVE-2018-6298 | 1 Hanwha-security | 4 Snh-v6410pn, Snh-v6410pn Firmware, Snh-v6410pnw and 1 more | 2018-04-09 | 10.0 HIGH | 9.8 CRITICAL |
Remote code execution in Hanwha Techwin Smartcams | |||||
CVE-2017-17862 | 2 Debian, Linux | 2 Debian Linux, Linux Kernel | 2018-04-07 | 4.9 MEDIUM | 5.5 MEDIUM |
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 ignores unreachable code, even though it would still be processed by JIT compilers. This behavior, also considered an improper branch-pruning logic issue, could possibly be used by local users for denial of service. | |||||
CVE-2018-1000081 | 1 Ajenti | 1 Ajenti | 2018-04-06 | 5.0 MEDIUM | 7.5 HIGH |
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter .. | |||||
CVE-2017-18064 | 1 Google | 1 Android | 2018-04-06 | 7.2 HIGH | 7.8 HIGH |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for p2p_noa_info in wma_send_bcn_buf_ll() which is received from firmware leads to potential buffer overflow. | |||||
CVE-2017-18067 | 1 Google | 1 Android | 2018-04-06 | 10.0 HIGH | 9.8 CRITICAL |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation while processing an encrypted authentication management frame in lim_send_auth_mgmt_frame() leads to buffer overflow. | |||||
CVE-2017-18063 | 1 Google | 1 Android | 2018-04-06 | 7.2 HIGH | 7.8 HIGH |
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for nlo_event in wma_nlo_match_evt_handler(), which is received from firmware, leads to potential out of bound memory access. |