Total
9170 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-6773 | 1 Jiangmin | 1 Antivirus | 2018-02-22 | 6.1 MEDIUM | 7.8 HIGH |
In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A008084. | |||||
CVE-2018-6769 | 1 Jiangmin | 1 Antivirus | 2018-02-22 | 6.1 MEDIUM | 7.8 HIGH |
In Jiangmin Antivirus 16.0.0.100, the driver file (KrnlCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x99008020. | |||||
CVE-2018-6768 | 1 Jiangmin | 1 Antivirus | 2018-02-22 | 6.1 MEDIUM | 7.8 HIGH |
In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A008090. | |||||
CVE-2018-6770 | 1 Jiangmin | 1 Antivirus | 2018-02-22 | 6.1 MEDIUM | 7.8 HIGH |
In Jiangmin Antivirus 16.0.0.100, the driver file (KrnlCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x99008210. | |||||
CVE-2018-6771 | 1 Jiangmin | 1 Antivirus | 2018-02-22 | 6.1 MEDIUM | 7.8 HIGH |
In Jiangmin Antivirus 16.0.0.100, the driver file (KrnlCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x99008224. | |||||
CVE-2018-6633 | 1 Micropoint | 1 Proactive Defense | 2018-02-22 | 6.1 MEDIUM | 7.8 HIGH |
In Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110005.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x80000038. | |||||
CVE-2018-6524 | 1 Inca | 1 Nprotect Avs | 2018-02-21 | 6.1 MEDIUM | 7.8 HIGH |
In nProtect AVS V4.0 before 4.0.0.39, the driver file (TKFsAv.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220c20. | |||||
CVE-2018-6523 | 1 Inca | 1 Nprotect Avs | 2018-02-21 | 6.1 MEDIUM | 7.8 HIGH |
In nProtect AVS V4.0 before 4.0.0.39, the driver file (TKFsAv.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x22045c. | |||||
CVE-2018-6525 | 1 Inca | 1 Nprotect Avs | 2018-02-21 | 6.1 MEDIUM | 7.8 HIGH |
In nProtect AVS V4.0 before 4.0.0.39, the driver file (TKFsAv.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220458. | |||||
CVE-2018-6522 | 1 Inca | 1 Nprotect Avs | 2018-02-21 | 6.1 MEDIUM | 7.8 HIGH |
In nProtect AVS V4.0 before 4.0.0.39, the driver file (TKRgFtXp.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220408. | |||||
CVE-2017-2750 | 1 Hp | 346 A2w75a, A2w75a Firmware, A2w76a and 343 more | 2018-02-21 | 7.5 HIGH | 9.8 CRITICAL |
Insufficient Solution DLL Signature Validation allows potential execution of arbitrary code in HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP OfficeJet Enterprise printers before 2308937_578479, 2405087_018548, and other firmware versions. | |||||
CVE-2017-18077 | 1 Brace Expansion Project | 1 Brace Expansion | 2018-02-15 | 5.0 MEDIUM | 7.5 HIGH |
index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expression Denial of Service (ReDoS) attacks, as demonstrated by an expand argument containing many comma characters. | |||||
CVE-2016-0300 | 1 Ibm | 1 Tririga Application Platform | 2018-02-14 | 5.5 MEDIUM | 5.4 MEDIUM |
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 might allow remote attackers to access arbitrary JSP pages via vectors related to improper input validation. IBM X-Force ID: 111412. | |||||
CVE-2018-6471 | 1 Superantispyware | 1 Superantispyware | 2018-02-13 | 6.1 MEDIUM | 7.8 HIGH |
In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C402078. | |||||
CVE-2018-6472 | 1 Superantispyware | 1 Superantispyware | 2018-02-13 | 6.1 MEDIUM | 7.8 HIGH |
In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40204c. | |||||
CVE-2018-6476 | 1 Superantispyware | 1 Superantispyware | 2018-02-13 | 10.0 HIGH | 9.8 CRITICAL |
In SUPERAntiSpyware Professional Trial 6.0.1254, the SASKUTIL.SYS driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating input values from IOCtl 0x9C402114 or 0x9C402124 or 0x9C40207c. | |||||
CVE-2018-6474 | 1 Superantispyware | 1 Superantispyware | 2018-02-13 | 6.1 MEDIUM | 7.8 HIGH |
In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C402148. | |||||
CVE-2018-6473 | 1 Superantispyware | 1 Superantispyware | 2018-02-13 | 6.1 MEDIUM | 7.8 HIGH |
In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C402080. | |||||
CVE-2017-12632 | 1 Apache | 1 Nifi | 2018-02-13 | 5.0 MEDIUM | 7.5 HIGH |
A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and compare to a controlled whitelist was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x release should upgrade to the appropriate release. | |||||
CVE-2016-10710 | 1 Biscom | 1 Secure File Transfer | 2018-02-13 | 6.5 MEDIUM | 8.1 HIGH |
Biscom Secure File Transfer (SFT) 5.0.1000 through 5.0.1048 does not validate the dataFieldId value, and uses sequential numbers, which allows remote authenticated users to overwrite or read files via crafted requests. Version 5.0.1050 contains the fix. |