CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-4285

    Last Modified: 21 Nov 2024

    A type confusion issue was addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.

    Published: 3 Apr 2019
    8.8
    High

    CVE-2018-4261

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, Safari 11.1.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.

    Published: 3 Apr 2019
    9.8
    Critical

    CVE-2018-4268

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.

    Published: 3 Apr 2019
    8.6
    High

    CVE-2018-4275

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 11.4.1.

    Published: 3 Apr 2019
    8.6
    High

    CVE-2018-4269

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2, iTunes 12.8 for Windows, iCloud for Windows 7.6.

    Published: 3 Apr 2019
    7.5
    High

    CVE-2018-4276

    Last Modified: 21 Nov 2024

    A null pointer dereference was addressed with improved validation. This issue affected versions prior to macOS High Sierra 10.13.6.

    Published: 3 Apr 2019
    5.5
    Medium

    CVE-2018-4282

    Last Modified: 21 Nov 2024

    An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, tvOS 11.4.1, watchOS 4.3.2.

    Published: 3 Apr 2019
    8.8
    High

    CVE-2018-4145

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.3, tvOS 11.3, watchOS 4.3, Safari 11.1, iTunes 12.7.4 for Windows, iCloud for Windows 7.4.

    Published: 3 Apr 2019
    5.9
    Medium

    CVE-2018-4153

    Last Modified: 21 Nov 2024

    An injection issue was addressed with improved validation. This issue affected versions prior to macOS Mojave 10.14.

    Published: 3 Apr 2019
    5.5
    Medium

    CVE-2018-4178

    Last Modified: 21 Nov 2024

    A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved permission validation. This issue affected versions prior to macOS High Sierra 10.13.4.

    Published: 3 Apr 2019
    8.8
    High

    CVE-2018-4191

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

    Published: 3 Apr 2019
    6.5
    Medium

    CVE-2018-4195

    Last Modified: 21 Nov 2024

    An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 12.

    Published: 3 Apr 2019
    5.5
    Medium

    CVE-2018-4216

    Last Modified: 21 Nov 2024

    A logic issue existed in the handling of call URLs. This issue was addressed with improved state management. This issue affected versions prior to iOS 11.4.1.

    Published: 3 Apr 2019
    7.5
    High

    CVE-2018-4248

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS 11.4.1, watchOS 4.3.2.

    Published: 3 Apr 2019
    6.5
    Medium

    CVE-2018-4260

    Last Modified: 21 Nov 2024

    An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to iOS 11.4.1, Safari 11.1.2.

    Published: 3 Apr 2019
    7
    High

    CVE-2017-7151

    Last Modified: 21 Nov 2024

    A race condition was addressed with additional validation. This issue affected versions prior to iOS 11.2, macOS High Sierra 10.13.2, tvOS 11.2, watchOS 4.2, iTunes 12.7.2 for Windows, macOS High Sierra 10.13.4.

    Published: 3 Apr 2019
    8.8
    High

    CVE-2018-4197

    Last Modified: 21 Nov 2024

    A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

    Published: 3 Apr 2019
    7.8
    High

    CVE-2018-4126

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7.

    Published: 3 Apr 2019
    7.5
    High

    CVE-2018-4203

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

    Published: 3 Apr 2019
    —
    Unknown

    CVE-2019-10268

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 3 Apr 2019
    5.5
    Medium

    CVE-2019-10723

    Last Modified: 21 Nov 2024

    An issue was discovered in PoDoFo 0.9.6. The PdfPagesTreeCache class in doc/PdfPagesTreeCache.cpp has an attempted excessive memory allocation because nInitialSize is not validated.

    Published: 3 Apr 2019
    7.5
    High

    CVE-2019-5423

    Last Modified: 21 Nov 2024

    Path traversal vulnerability in http-live-simulator npm package version 1.0.5 allows arbitrary path to be accessed on the file system by a remote attacker.

    Published: 3 Apr 2019
    6.1
    Medium

    CVE-2019-5422

    Last Modified: 21 Nov 2024

    XSS in buttle npm package version 0.2.0 causes execution of attacker-provided code in the victim's browser when an attacker creates an arbitrary file on the server.

    Published: 3 Apr 2019
    9.8
    Critical

    CVE-2019-5421

    Last Modified: 21 Nov 2024

    Plataformatec Devise version 4.5.0 and earlier, using the lockable module contains a CWE-367 vulnerability in The `Devise::Models::Lockable` class, more specifically at the `#increment_failed_attempts` method. File location: lib/devise/models/lockable.rb that can result in Multiple concurrent requests can prevent an attacker from being blocked on brute force attacks. This attack appear to be exploitable via Network connectivity - brute force attacks. This vulnerability appears to have been fixed in 4.6.0 and later.

    Published: 3 Apr 2019
    4.8
    Medium

    CVE-2019-10261

    Last Modified: 21 Nov 2024

    CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fields via a "DNS Functions" "Edit Nameservers IPs" action.

    Published: 3 Apr 2019
    7.8
    High

    CVE-2019-4014

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 155892.

    Published: 3 Apr 2019
    8.4
    High

    CVE-2018-1936

    Last Modified: 21 Nov 2024

    IBM DB2 9.7, 10.1, 10.5, and 11.1 libdb2e.so.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 153316.

    Published: 3 Apr 2019
    5.4
    Medium

    CVE-2018-1913

    Last Modified: 21 Nov 2024

    IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152737.

    Published: 3 Apr 2019
    4.8
    Medium

    CVE-2018-1731

    Last Modified: 21 Nov 2024

    IBM DOORS Next Generation (DNG/RRC) 5.0 through 5.0.3 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147710.

    Published: 3 Apr 2019
    8.8
    High

    CVE-2019-10673

    Last Modified: 21 Nov 2024

    A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress allows attackers to become admin and subsequently extract sensitive information and execute arbitrary code. This occurs because the attacker can change the e-mail address in the administrator profile, and then the attacker is able to reset the administrator password using the WordPress "password forget" form.

    Published: 3 Apr 2019
    2.5
    Low

    CVE-2019-11191

    Last Modified: 21 Nov 2024

    The Linux kernel through 5.0.7, when CONFIG_IA32_AOUT is enabled and ia32_aout is loaded, allows local users to bypass ASLR on setuid a.out programs (if any exist) because install_exec_creds() is called too late in load_aout_binary() in fs/binfmt_aout.c, and thus the ptrace_may_access() check has a race condition when reading /proc/pid/stat. NOTE: the software maintainer disputes that this is a vulnerability because ASLR for a.out format executables has never been supported

    Published: 3 Apr 2019
    9.8
    Critical

    CVE-2018-4259

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.

    Published: 3 Apr 2019
    9.8
    Critical

    CVE-2018-4286

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.

    Published: 3 Apr 2019
    9.8
    Critical

    CVE-2018-4287

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.

    Published: 3 Apr 2019
    9.8
    Critical

    CVE-2018-4288

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.

    Published: 3 Apr 2019
    9.8
    Critical

    CVE-2018-4291

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to macOS High Sierra 10.13.6.

    Published: 3 Apr 2019
    8.8
    High

    CVE-2018-4407

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

    Published: 3 Apr 2019
    6.5
    Medium

    CVE-2019-10871

    Last Modified: 21 Nov 2024

    An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.

    Published: 3 Apr 2019
    7.1
    High

    CVE-2019-12779

    Last Modified: 21 Nov 2024

    libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

    Published: 3 Apr 2019
    6.1
    Medium

    CVE-2019-3837

    Last Modified: 21 Nov 2024

    It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unprivileged multi-threaded userspace application calling recvmsg() for the same network socket in parallel executed on ioatdma-enabled hardware with net_dma enabled can leak the memory, crash the host leading to a denial-of-service or cause a random memory corruption.

    Published: 3 Apr 2019
    5.4
    Medium

    CVE-2019-3886

    Last Modified: 21 Nov 2024

    An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.

    Published: 3 Apr 2019
    9.8
    Critical

    CVE-2019-5953

    Last Modified: 21 Nov 2024

    Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified vectors.

    Published: 3 Apr 2019
    5.9
    Medium

    CVE-2018-4300

    Last Modified: 21 Nov 2024

    The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.

    Published: 3 Apr 2019
    8.8
    High

    CVE-2019-10872

    Last Modified: 21 Nov 2024

    An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.

    Published: 3 Apr 2019
    4.7
    Medium

    CVE-2019-11190

    Last Modified: 21 Nov 2024

    The Linux kernel before 4.8 allows local users to bypass ASLR on setuid programs (such as /bin/su) because install_exec_creds() is called too late in load_elf_binary() in fs/binfmt_elf.c, and thus the ptrace_may_access() check has a race condition when reading /proc/pid/stat.

    Published: 3 Apr 2019
    6.1
    Medium

    CVE-2018-18035

    Last Modified: 21 Nov 2024

    A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.

    Published: 2 Apr 2019
    9.8
    Critical

    CVE-2019-6506

    Last Modified: 21 Nov 2024

    SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection.

    Published: 2 Apr 2019
    9.8
    Critical

    CVE-2017-6047

    Last Modified: 21 Nov 2024

    Detcon Sitewatch Gateway, all versions without cellular, Passwords are presented in plaintext in a file that is accessible without authentication.

    Published: 2 Apr 2019
    7.5
    High

    CVE-2017-6049

    Last Modified: 21 Nov 2024

    Detcon Sitewatch Gateway, all versions without cellular, an attacker can edit settings on the device using a specially crafted URL.

    Published: 2 Apr 2019
    —
    Unknown

    CVE-2017-2676

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 2 Apr 2019