Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In November 2018
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper configuration of script may lead to unprivileged access.
CVSS Score
7.8
EPSS Score
0.0
Published
2018-11-27
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper configuration of daemons may lead to unprivileged access.
CVSS Score
7.8
EPSS Score
0.0
Published
2018-11-27
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper configuration of dev nodes may lead to potential security issue.
CVSS Score
7.8
EPSS Score
0.0
Published
2018-11-27
An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 all versions under web proxy's disclaimer response web pages, potentially causing sensitive data to be displayed in the HTTP response.
CVSS Score
7.5
EPSS Score
0.015
Published
2018-11-27
In Apache Hadoop 2.7.4 to 2.7.6, the security fix for CVE-2016-6811 is incomplete. A user who can escalate to yarn user can possibly run arbitrary commands as root user.
CVSS Score
8.8
EPSS Score
0.007
Published
2018-11-27
In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user.
CVSS Score
7.5
EPSS Score
0.006
Published
2018-11-27
In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to post-authentication command injection.
CVSS Score
7.5
EPSS Score
0.006
Published
2018-11-27
In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to several buffer overflows.
CVSS Score
8.1
EPSS Score
0.004
Published
2018-11-27
In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files containing sensitive information; notably, the SMM user account credentials and the system shadow file.
CVSS Score
8.1
EPSS Score
0.003
Published
2018-11-27
In System Management Module (SMM) versions prior to 1.06, an internal SMM function that retrieves configuration settings is prone to a buffer overflow.
CVSS Score
8.1
EPSS Score
0.005
Published
2018-11-27


Contact Us

Shodan ® - All rights reserved