CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-20812

    Last Modified: 21 Nov 2024

    An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R1 and below. This is applicable only to dual-stack (IPv4/IPv6) endpoints.

    Published: 16 Mar 2019
    9.8
    Critical

    CVE-2018-20813

    Last Modified: 21 Nov 2024

    An input validation issue has been found with login_meeting.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2.

    Published: 16 Mar 2019
    7.5
    High

    CVE-2018-20809

    Last Modified: 21 Nov 2024

    A crafted message can cause the web server to crash with Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R5 and Pulse Policy Secure 5.4RX before 5.4R5. This is not applicable to PCS 8.1RX.

    Published: 16 Mar 2019
    9.8
    Critical

    CVE-2018-20810

    Last Modified: 21 Nov 2024

    Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices.

    Published: 16 Mar 2019
    5.3
    Medium

    CVE-2018-20811

    Last Modified: 21 Nov 2024

    A hidden RPC service issue was found with Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2 and 8.1RX before 8.1R12.

    Published: 16 Mar 2019
    6.1
    Medium

    CVE-2018-20814

    Last Modified: 21 Nov 2024

    An XSS issue was found with Psaldownload.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.3R2 before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX or PPS 5.2RX.

    Published: 16 Mar 2019
    9.1
    Critical

    CVE-2019-11034

    Last Modified: 21 Nov 2024

    When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.

    Published: 16 Mar 2019
    6.5
    Medium

    CVE-2019-9904

    Last Modified: 21 Nov 2024

    An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursive agclose calls in lib\cgraph\graph.c in libcgraph.a, related to agfstsubg in lib\cgraph\subg.c.

    Published: 16 Mar 2019
    6.1
    Medium

    CVE-2019-9844

    Last Modified: 21 Nov 2024

    simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.

    Published: 15 Mar 2019
    6.1
    Medium

    CVE-2018-20806

    Last Modified: 21 Nov 2024

    Phamm (aka PHP LDAP Virtual Hosting Manager) 0.6.8 allows XSS via the login page (the /public/main.php action parameter).

    Published: 15 Mar 2019
    7.5
    High

    CVE-2019-9843

    Last Modified: 21 Nov 2024

    In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolveExternalEntities setting. For example, this allows disclosure of file contents to a MITM attacker if a victim performs a spotlessApply operation on an untrusted XML file.

    Published: 15 Mar 2019
    6.1
    Medium

    CVE-2019-9837

    Last Modified: 21 Nov 2024

    Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open redirect via the redirect_uri field in an OAuth authorization request (that results in an error response) with the 'openid' scope and a prompt=none value. This allows phishing attacks against the authorization flow.

    Published: 15 Mar 2019
    8.8
    High

    CVE-2018-14745

    Last Modified: 21 Nov 2024

    Buffer overflow in prot_get_ring_space in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to overwrite kernel memory due to improper validation of the ring buffer read pointer. The Samsung ID is SVE-2018-12029.

    Published: 15 Mar 2019
    7.5
    High

    CVE-2018-15508

    Last Modified: 21 Nov 2024

    Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control allowing a remote attackers to cause a denial of service via opening a connection on port 8083 to a device running the Five9 SoftPhone(issue 1 of 2).

    Published: 15 Mar 2019
    6.7
    Medium

    CVE-2019-6149

    Last Modified: 21 Nov 2024

    An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 that could allow a malicious user with local access to execute code with administrative privileges.

    Published: 15 Mar 2019
    9.8
    Critical

    CVE-2018-15509

    Last Modified: 21 Nov 2024

    Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control (issue 2 of 2).

    Published: 15 Mar 2019
    5.3
    Medium

    CVE-2019-5616

    Last Modified: 21 Nov 2024

    CircuitWerkes Sicon-8, a hardware device used for managing electrical devices, ships with a web-based front-end controller and implements an authentication mechanism in JavaScript that is run in the context of a user's web browser.

    Published: 15 Mar 2019
    7.5
    High

    CVE-2018-17882

    Last Modified: 21 Nov 2024

    An Integer overflow vulnerability exists in the batchTransfer function of a smart contract implementation for CryptoBotsBattle (CBTB), an Ethereum token. This vulnerability could be used by an attacker to create an arbitrary amount of tokens for any user.

    Published: 15 Mar 2019
    7.5
    High

    CVE-2018-18205

    Last Modified: 21 Nov 2024

    Topvision CC8800 CMTS C-E devices allow remote attackers to obtain sensitive information via a direct request for /WebContent/startup.tar.gz with userName=admin in a cookie.

    Published: 15 Mar 2019
    2.2
    Low

    CVE-2018-17955

    Last Modified: 21 Nov 2024

    In yast2-multipath before version 4.1.1 a static temporary filename allows local attackers to overwrite files on systems without symlink protection

    Published: 15 Mar 2019
    7.8
    High

    CVE-2018-17956

    Last Modified: 21 Nov 2024

    In yast2-samba-provision up to and including version 1.0.1 the password for samba shares was provided on the command line to tools used by yast2-samba-provision, allowing local attackers to read them in the process list

    Published: 15 Mar 2019
    6.5
    Medium

    CVE-2018-20106

    Last Modified: 21 Nov 2024

    In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as root. This requires tricking root to enter such a password in yast.

    Published: 15 Mar 2019
    9.6
    Critical

    CVE-2019-9835

    Last Modified: 21 Nov 2024

    The receiver (aka bridge) component of Fujitsu Wireless Keyboard Set LX901 GK900 devices allows Keystroke Injection. This occurs because it accepts unencrypted 2.4 GHz packets, even though all legitimate communication uses AES encryption.

    Published: 15 Mar 2019
    7.5
    High

    CVE-2019-9832

    Last Modified: 21 Nov 2024

    The AirDrop application through 2.0 for Android allows remote attackers to cause a denial of service via a client that makes many socket connections through a configured port.

    Published: 15 Mar 2019
    6.1
    Medium

    CVE-2019-9834

    Last Modified: 21 Nov 2024

    The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injection. Successful exploitation will allow attacker-supplied HTML to run in the context of the affected browser, potentially allowing the attacker to steal authentication credentials or to control how the site is rendered to the user. NOTE: the vendor disputes the risk because there is a clear warning next to the button for importing a snapshot

    Published: 15 Mar 2019
    7.5
    High

    CVE-2019-9831

    Last Modified: 21 Nov 2024

    The AirMore application through 1.6.1 for Android allows remote attackers to cause a denial of service (system hang) via many simultaneous /?Key=PhoneRequestAuthorization requests.

    Published: 15 Mar 2019
    7.5
    High

    CVE-2019-9833

    Last Modified: 21 Nov 2024

    The Screen Stream application through 3.0.15 for Android allows remote attackers to cause a denial of service via many simultaneous /start-stop requests.

    Published: 15 Mar 2019
    7.5
    High

    CVE-2018-19393

    Last Modified: 21 Nov 2024

    Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configuration file. This was exploitable via multiple attack vectors depending on the device's configuration. Further analysis also indicated this vulnerability could be leveraged to achieve a Denial of Service (DoS) condition, where the device would require a factory reset to return to normal operation.

    Published: 15 Mar 2019
    4.8
    Medium

    CVE-2018-19394

    Last Modified: 21 Nov 2024

    Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file.

    Published: 15 Mar 2019
    6.1
    Medium

    CVE-2018-19391

    Last Modified: 21 Nov 2024

    Cobham Satcom Sailor 250 and 500 devices before 1.25 contained persistent XSS, which could be exploited by an unauthenticated threat actor via the /index.lua?pageID=Phone%20book name field.

    Published: 15 Mar 2019
    9.8
    Critical

    CVE-2018-19392

    Last Modified: 21 Nov 2024

    Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability. This could allow modification of any user account's password (including the default "admin" account), without prior knowledge of their password. All that is required is knowledge of the username and attack vector (/index.lua?pageID=Administration usernameAdmChange, passwordAdmChange1, and passwordAdmChange2 fields).

    Published: 15 Mar 2019
    7
    High

    CVE-2018-18253

    Last Modified: 21 Nov 2024

    An issue was discovered in CapMon Access Manager 5.4.1.1005. CALRunElevated.exe attempts to enforce access control by adding an unprivileged user to the local Administrators group for a very short time to execute a single command. However, the user is left in that group if the command crashes, and there is also a race condition in all cases.

    Published: 15 Mar 2019
    7.8
    High

    CVE-2018-18255

    Last Modified: 21 Nov 2024

    An issue was discovered in CapMon Access Manager 5.4.1.1005. The client applications of AccessManagerCoreService.exe communicate with this server through named pipes. A user can initiate communication with the server by creating a named pipe and sending commands to achieve elevated privileges.

    Published: 15 Mar 2019
    7.8
    High

    CVE-2018-18256

    Last Modified: 21 Nov 2024

    An issue was discovered in CapMon Access Manager 5.4.1.1005. A regular user can obtain local administrator privileges if they run any whitelisted application through the Custom App Launcher.

    Published: 15 Mar 2019
    7.8
    High

    CVE-2018-18254

    Last Modified: 21 Nov 2024

    An issue was discovered in CapMon Access Manager 5.4.1.1005. An unprivileged user can read the cal_whitelist table in the Custom App Launcher (CAL) database, and potentially gain privileges by placing a Trojan horse program at an app pathname.

    Published: 15 Mar 2019
    7.8
    High

    CVE-2018-18252

    Last Modified: 21 Nov 2024

    An issue was discovered in CapMon Access Manager 5.4.1.1005. CALRunElevated.exe provides "NT AUTHORITY\SYSTEM" access to unprivileged users via the --system option.

    Published: 15 Mar 2019
    8.8
    High

    CVE-2019-9829

    Last Modified: 21 Nov 2024

    Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action. This occurs because template rendering uses an include operation on a cache file, which bypasses the prohibition of .php files as templates.

    Published: 15 Mar 2019
    6.5
    Medium

    CVE-2019-9903

    Last Modified: 21 Nov 2024

    PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.

    Published: 15 Mar 2019
    8.8
    High

    CVE-2019-4034

    Last Modified: 21 Nov 2024

    IBM Content Navigator 3.0CD is could allow an attacker to execute arbitrary code on a user's workstation. When editing an executable file in ICN with Edit service, it will be executed on the user's workstation. IBM X-Force ID: 156000.

    Published: 14 Mar 2019
    5.4
    Medium

    CVE-2018-1984

    Last Modified: 21 Nov 2024

    IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 154137.

    Published: 14 Mar 2019
    5.4
    Medium

    CVE-2018-1983

    Last Modified: 21 Nov 2024

    IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 154136.

    Published: 14 Mar 2019
    5.4
    Medium

    CVE-2018-1982

    Last Modified: 21 Nov 2024

    IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 154135.

    Published: 14 Mar 2019
    5.4
    Medium

    CVE-2018-1952

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153495.

    Published: 14 Mar 2019
    4.3
    Medium

    CVE-2018-1929

    Last Modified: 21 Nov 2024

    IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 could allow a malicious user to be allowed to view any view if he knows the URL link of a the view, and access information that should not be able to see. IBM X-Force ID: 153120.

    Published: 14 Mar 2019
    5.4
    Medium

    CVE-2018-1916

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152740.

    Published: 14 Mar 2019
    5.4
    Medium

    CVE-2018-1914

    Last Modified: 21 Nov 2024

    IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152738.

    Published: 14 Mar 2019
    5.4
    Medium

    CVE-2018-1910

    Last Modified: 21 Nov 2024

    IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152734.

    Published: 14 Mar 2019
    5.4
    Medium

    CVE-2018-1908

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation with Automation Anywhere 11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152671.

    Published: 14 Mar 2019
    5.4
    Medium

    CVE-2018-1763

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148617.

    Published: 14 Mar 2019
    5.4
    Medium

    CVE-2018-1823

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 150426.

    Published: 14 Mar 2019