Total
9398 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-6474 | 1 Superantispyware | 1 Superantispyware | 2018-02-13 | 6.1 MEDIUM | 7.8 HIGH |
In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C402148. | |||||
CVE-2018-6476 | 1 Superantispyware | 1 Superantispyware | 2018-02-13 | 10.0 HIGH | 9.8 CRITICAL |
In SUPERAntiSpyware Professional Trial 6.0.1254, the SASKUTIL.SYS driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating input values from IOCtl 0x9C402114 or 0x9C402124 or 0x9C40207c. | |||||
CVE-2018-6473 | 1 Superantispyware | 1 Superantispyware | 2018-02-13 | 6.1 MEDIUM | 7.8 HIGH |
In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C402080. | |||||
CVE-2018-6472 | 1 Superantispyware | 1 Superantispyware | 2018-02-13 | 6.1 MEDIUM | 7.8 HIGH |
In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40204c. | |||||
CVE-2017-12632 | 1 Apache | 1 Nifi | 2018-02-13 | 5.0 MEDIUM | 7.5 HIGH |
A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and compare to a controlled whitelist was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x release should upgrade to the appropriate release. | |||||
CVE-2016-10710 | 1 Biscom | 1 Secure File Transfer | 2018-02-13 | 6.5 MEDIUM | 8.1 HIGH |
Biscom Secure File Transfer (SFT) 5.0.1000 through 5.0.1048 does not validate the dataFieldId value, and uses sequential numbers, which allows remote authenticated users to overwrite or read files via crafted requests. Version 5.0.1050 contains the fix. | |||||
CVE-2018-6217 | 1 Kingsoftstore | 1 Kingsoft Wps Office | 2018-02-12 | 4.3 MEDIUM | 5.5 MEDIUM |
The WStr::_alloc_iostr_data() function in kso.dll in Kingsoft WPS Office 10.1.0.7106 and 10.2.0.5978 allows remote attackers to cause a denial of service (application crash) via a crafted (a) web page, (b) office document, or (c) .rtf file. | |||||
CVE-2017-15697 | 1 Apache | 1 Nifi | 2018-02-12 | 7.5 HIGH | 9.8 CRITICAL |
A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fix to properly handle these headers was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x release should upgrade to the appropriate release. | |||||
CVE-2018-6203 | 1 Escanav | 1 Anti-virus | 2018-02-08 | 6.1 MEDIUM | 7.8 HIGH |
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8300210C. | |||||
CVE-2018-6202 | 1 Escanav | 1 Anti-virus | 2018-02-08 | 6.1 MEDIUM | 7.8 HIGH |
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020F8. | |||||
CVE-2018-6201 | 1 Escanav | 1 Anti-virus | 2018-02-08 | 6.1 MEDIUM | 7.8 HIGH |
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020E0 or 0x830020E4. | |||||
CVE-2017-1000402 | 1 Jenkins | 1 Swarm | 2018-02-08 | 4.3 MEDIUM | 5.9 MEDIUM |
Jenkins Swarm Plugin Client 3.4 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. | |||||
CVE-2017-1000397 | 1 Jenkins | 1 Maven | 2018-02-08 | 4.3 MEDIUM | 5.9 MEDIUM |
Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on commons-httpclient. | |||||
CVE-2018-6206 | 1 Maxpcsecure | 1 Anti Virus | 2018-02-07 | 6.1 MEDIUM | 7.8 HIGH |
In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220011. | |||||
CVE-2018-6205 | 1 Maxpcsecure | 1 Anti Virus | 2018-02-07 | 6.1 MEDIUM | 7.8 HIGH |
In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220009. | |||||
CVE-2018-6208 | 1 Maxpcsecure | 1 Anti Virus | 2018-02-07 | 6.1 MEDIUM | 7.8 HIGH |
In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x22000d. | |||||
CVE-2018-6207 | 1 Maxpcsecure | 1 Anti Virus | 2018-02-07 | 6.1 MEDIUM | 7.8 HIGH |
In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220019. | |||||
CVE-2018-6209 | 1 Maxpcsecure | 1 Anti Virus | 2018-02-07 | 6.1 MEDIUM | 7.8 HIGH |
In Max Secure Anti Virus 19.0.3.019,, the driver file (MaxCryptMon.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220019. | |||||
CVE-2018-6204 | 1 Maxpcsecure | 1 Anti Virus | 2018-02-07 | 6.1 MEDIUM | 7.8 HIGH |
In Max Secure Anti Virus 19.0.3.019,, the driver file (SDActMon.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220019. | |||||
CVE-2016-2983 | 1 Ibm | 1 Tealeaf Customer Experience | 2018-02-07 | 6.8 MEDIUM | 8.1 HIGH |
IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker under unusual circumstances to read operational data or TLS session state for any active sessions, cause denial of service, or bypass security. IBM X-Force ID: 113999. |