CVE Feed

    Dashboard / CVE

    8
    High

    CVE-2018-3963

    Last Modified: 21 Nov 2024

    An exploitable command injection vulnerability exists in the DHCP daemon configuration of the CUJO Smart Firewall. When adding a new static DHCP address, its corresponding hostname is inserted into the dhcpd.conf file without prior sanitization, allowing for arbitrary execution of system commands. To trigger this vulnerability, an attacker can send a DHCP request message and set up the corresponding static DHCP entry.

    Published: 21 Mar 2019
    7.5
    High

    CVE-2018-4030

    Last Modified: 21 Nov 2024

    An exploitable vulnerability exists the safe browsing function of the CUJO Smart Firewall, version 7003. The bug lies in the way the safe browsing function parses HTTP requests. The "Host" header is incorrectly extracted from captured HTTP requests, which would allow an attacker to visit any malicious websites and bypass the firewall. An attacker could send an HTTP request to exploit this vulnerability.

    Published: 21 Mar 2019
    7.5
    High

    CVE-2018-4011

    Last Modified: 21 Nov 2024

    An exploitable integer underflow vulnerability exists in the mdnscap binary of the CUJO Smart Firewall, version 7003. When parsing SRV records in an mDNS packet, the "RDLENGTH" value is handled incorrectly, leading to an out-of-bounds access that crashes the mdnscap process. An unauthenticated attacker can send an mDNS message to trigger this vulnerability.

    Published: 21 Mar 2019
    8.8
    High

    CVE-2019-6491

    Last Modified: 21 Nov 2024

    RISI Gestao de Horarios v3201.09.08 rev.23 allows SQL Injection.

    Published: 21 Mar 2019
    9.8
    Critical

    CVE-2018-3985

    Last Modified: 21 Nov 2024

    An exploitable double free vulnerability exists in the mdnscap binary of the CUJO Smart Firewall. When parsing mDNS packets, a memory space is freed twice if an invalid query name is encountered, leading to arbitrary code execution in the context of the mdnscap process. An unauthenticated attacker can send an mDNS message to trigger this vulnerability.

    Published: 21 Mar 2019
    7.8
    High

    CVE-2018-3969

    Last Modified: 21 Nov 2024

    An exploitable vulnerability exists in the verified boot protection of the CUJO Smart Firewall. It is possible to add arbitrary shell commands into the dhcpd.conf file, that persist across reboots and firmware updates, and thus allow for executing unverified commands. To trigger this vulnerability, a local attacker needs to be able to write into /config/dhcpd.conf.

    Published: 21 Mar 2019
    9.8
    Critical

    CVE-2018-4003

    Last Modified: 21 Nov 2024

    An exploitable heap overflow vulnerability exists in the mdnscap binary of the CUJO Smart Firewall running firmware 7003. The string lengths are handled incorrectly when parsing character strings in mDNS resource records, leading to arbitrary code execution in the context of the mdnscap process. An unauthenticated attacker can send an mDNS message to trigger this vulnerability.

    Published: 21 Mar 2019
    5.9
    Medium

    CVE-2018-16563

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.35), Firmware variant MODBUS TCP for EN100 Ethernet module (All versions), Firmware variant DNP3 TCP for EN100 Ethernet module (All versions), Firmware variant IEC104 for EN100 Ethernet module (All versions), Firmware variant Profinet IO for EN100 Ethernet module (All versions), SIPROTEC 5 relays with CPU variants CP300 and CP100 and the respective Ethernet communication modules (All versions < V7.82), SIPROTEC 5 relays with CPU variants CP200 and the respective Ethernet communication modules (All versions < V7.58). Specially crafted packets to port 102/tcp could cause a denial-of-service condition in the affected products. A manual restart is required to recover the EN100 module functionality of the affected devices. Successful exploitation requires an attacker with network access to send multiple packets to the affected products or modules. As a precondition the IEC 61850-MMS communication needs to be activated on the affected products or modules. No user interaction or privileges are required to exploit the vulnerability. The vulnerability could allow causing a Denial-of-Service condition of the network functionality of the device, compromising the availability of the system. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 21 Mar 2019
    5.5
    Medium

    CVE-2019-5011

    Last Modified: 21 Nov 2024

    An exploitable privilege escalation vulnerability exists in the helper service CleanMyMac X, version 4.20, due to improper updating. The application failed to remove the vulnerable components upon upgrading to the latest version, leaving the user open to attack. A user with local access can use this vulnerability to modify the file system as root. An attacker would need local access to the machine for a successful exploit.

    Published: 21 Mar 2019
    6.4
    Medium

    CVE-2018-1992

    Last Modified: 21 Nov 2024

    The IBM Power 9 OP910, OP920, and FW910 boot firmware's bootloader is responsible for loading and validating the initial boot firmware image that drives the rest of the system's hardware initialization. The bootloader firmware contains a buffer overflow vulnerability such that, if an attacker were able to replace the initial boot firmware image with a very carefully crafted and sufficiently large, malicious replacement, it could cause the bootloader, during the load of that image, to overwrite its own instruction memory and circumvent secure boot protections, install trojans, etc. IBM X-Force ID: 154345.

    Published: 21 Mar 2019
    5.9
    Medium

    CVE-2017-1713

    Last Modified: 21 Nov 2024

    IBM InfoSphere Streams 4.2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134632.

    Published: 21 Mar 2019
    9.8
    Critical

    CVE-2018-4059

    Last Modified: 21 Nov 2024

    An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticated telnet admin portal on the loopback interface. This can provide administrator access to the TURN server configuration, which can lead to additional attacks. An attacker who can get access to the telnet port can gain administrator access to the TURN server.

    Published: 21 Mar 2019
    7.7
    High

    CVE-2018-4058

    Last Modified: 21 Nov 2024

    An exploitable unsafe default configuration vulnerability exists in the TURN server functionality of coTURN prior to 4.5.0.9. By default, the TURN server allows relaying external traffic to the loopback interface of its own host. This can provide access to other private services running on that host, which can lead to further attacks. An attacker can set up a relay with a loopback address as the peer on an affected TURN server to trigger this vulnerability.

    Published: 21 Mar 2019
    7.5
    High

    CVE-2016-5800

    Last Modified: 21 Nov 2024

    A malicious attacker can trigger a remote buffer overflow in the Communication Server in Fatek Automation PM Designer V3 Version 2.1.2.2, and Automation FV Designer Version 1.2.8.0.

    Published: 21 Mar 2019
    6.1
    Medium

    CVE-2016-5819

    Last Modified: 21 Nov 2024

    Moxa G3100V2 Series, editions prior to Version 2.8, and OnCell G3111/G3151/G3211/G3251 Series, editions prior to Version 1.7 allows a reflected cross-site scripting attack which may allow an attacker to execute arbitrary script code in the user’s browser within the trust relationship between their browser and the server.

    Published: 21 Mar 2019
    5.5
    Medium

    CVE-2019-3838

    Last Modified: 21 Nov 2024

    It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

    Published: 21 Mar 2019
    5.5
    Medium

    CVE-2019-3835

    Last Modified: 21 Nov 2024

    It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

    Published: 21 Mar 2019
    9.8
    Critical

    CVE-2019-9898

    Last Modified: 21 Nov 2024

    Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.

    Published: 21 Mar 2019
    7.5
    High

    CVE-2019-9897

    Last Modified: 21 Nov 2024

    Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.

    Published: 21 Mar 2019
    7.8
    High

    CVE-2019-9896

    Last Modified: 21 Nov 2024

    In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directory as the executable.

    Published: 21 Mar 2019
    9.8
    Critical

    CVE-2019-9895

    Last Modified: 21 Nov 2024

    In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.

    Published: 21 Mar 2019
    7.5
    High

    CVE-2019-9894

    Last Modified: 21 Nov 2024

    A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.

    Published: 21 Mar 2019
    7.5
    High

    CVE-2019-17007

    Last Modified: 21 Nov 2024

    In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.

    Published: 21 Mar 2019
    7
    High

    CVE-2019-9755

    Last Modified: 21 Nov 2024

    An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where /bin/ntfs-3g is a setuid-root binary, this could lead to a local escalation of privileges.

    Published: 21 Mar 2019
    2.7
    Low

    CVE-2019-9889

    Last Modified: 21 Nov 2024

    In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results in a require call using a crafted type value, leading to Directory Traversal with File Inclusion. An attacker can leverage this vulnerability to execute code under the context of the web server.

    Published: 20 Mar 2019
    5.3
    Medium

    CVE-2017-2659

    Last Modified: 21 Nov 2024

    It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

    Published: 20 Mar 2019
    5.4
    Medium

    CVE-2018-17167

    Last Modified: 21 Nov 2024

    PrinterOn Enterprise 4.1.4 suffers from multiple authenticated stored XSS vulnerabilities via the (1) "Machine Host Name" or "Server Serial Number" field in the clustering configuration, (2) "name" field in the Edit Group configuration, (3) "Rule Name" field in the Access Control configuration, (4) "Service Name" in the Service Configuration, or (5) First Name or Last Name field in the Edit Account configuration.

    Published: 20 Mar 2019
    6.5
    Medium

    CVE-2019-7441

    Last Modified: 21 Nov 2024

    cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states it is true that the amount can be manipulated in the PayPal payment flow. However, the amount is validated against the WooCommerce order total before completing the order, and if it doesn’t match then the order will be left in an “On Hold” state

    Published: 20 Mar 2019
    6.5
    Medium

    CVE-2019-7440

    Last Modified: 21 Nov 2024

    JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to cgi-bin/qcmap_web_cgi).

    Published: 20 Mar 2019
    6.5
    Medium

    CVE-2019-7439

    Last Modified: 21 Nov 2024

    cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter.

    Published: 20 Mar 2019
    6.1
    Medium

    CVE-2019-7438

    Last Modified: 21 Nov 2024

    cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter.

    Published: 20 Mar 2019
    6.1
    Medium

    CVE-2019-7437

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected Cross-Site Scripting (XSS) via the Search field.

    Published: 20 Mar 2019
    6.5
    Medium

    CVE-2019-7436

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has directory traversal via a direct request for a listing of an uploads directory.

    Published: 20 Mar 2019
    5.3
    Medium

    CVE-2019-7435

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected HTML injection via the Search Form.

    Published: 20 Mar 2019
    6.5
    Medium

    CVE-2019-7434

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Rental Bike Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory.

    Published: 20 Mar 2019
    8.8
    High

    CVE-2019-7433

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Rental Bike Script 2.0.3 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.

    Published: 20 Mar 2019
    5.4
    Medium

    CVE-2019-7432

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Rental Bike Script 2.0.3 has HTML injection via the STREET field in the Profile Edit section.

    Published: 20 Mar 2019
    6.5
    Medium

    CVE-2019-7431

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Image Sharing Script 1.3.4 has directory traversal via a direct request for a listing of an uploads directory.

    Published: 20 Mar 2019
    5.3
    Medium

    CVE-2019-7430

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Image Sharing Script 1.3.4 has HTML injection via the Search Bar.

    Published: 20 Mar 2019
    6.5
    Medium

    CVE-2019-7429

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Property Rental Software 2.1.4 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2016/08 directory.

    Published: 20 Mar 2019
    8.8
    High

    CVE-2018-20648

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Car Rental Script 2.0.8 has Cross-Site Request Forgery (CSRF) via accountedit.php.

    Published: 20 Mar 2019
    6.5
    Medium

    CVE-2018-20647

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Car Rental Script 2.0.8 has directory traversal via a direct request for a listing of an image directory such as an images/ directory.

    Published: 20 Mar 2019
    6.5
    Medium

    CVE-2018-20646

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Basic B2B Script 2.0.9 has has directory traversal via a direct request for a listing of an image directory such as an uploads/ directory.

    Published: 20 Mar 2019
    5.4
    Medium

    CVE-2018-20645

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Basic B2B Script 2.0.9 has HTML injection via the First Name or Last Name field.

    Published: 20 Mar 2019
    8.8
    High

    CVE-2018-20644

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Basic B2B Script 2.0.9 has Cross-Site Request Forgery (CSRF) via the Edit profile feature.

    Published: 20 Mar 2019
    6.5
    Medium

    CVE-2018-20643

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.

    Published: 20 Mar 2019
    6.5
    Medium

    CVE-2018-20642

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 allows remote attackers to cause a denial of service (outage of profile editing) via crafted JavaScript code in the KeySkills field.

    Published: 20 Mar 2019
    8.8
    High

    CVE-2018-20641

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.

    Published: 20 Mar 2019
    5.4
    Medium

    CVE-2018-20640

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has stored Cross-Site Scripting (XSS) via the Full Name field.

    Published: 20 Mar 2019
    6.1
    Medium

    CVE-2018-20639

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has HTML injection via the Search Bar.

    Published: 20 Mar 2019