CVE Feed

    Dashboard / CVE

    8.6
    High

    CVE-2018-18569

    Last Modified: 21 Nov 2024

    The Dundas BI server before 5.0.1.1010 is vulnerable to a Server-Side Request Forgery attack, allowing an attacker to forge arbitrary requests (with certain restrictions) that will be executed on behalf of the attacker, via the viewUrl parameter of the "export the dashboard as an image" feature. This could be leveraged to provide a proxy to attack other servers (internal or external) or to perform network scans of external or internal networks.

    Published: 11 Feb 2019
    4.3
    Medium

    CVE-2018-17542

    Last Modified: 21 Nov 2024

    SQL Injection exists in MailSherlock before 1.5.235 for OAKlouds allows an unauthenticated user to extract the subjects of the emails of other users within the enterprise via the select_mid parameter in an letgo.cgi request.

    Published: 11 Feb 2019
    —
    Unknown

    CVE-2018-16107

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 11 Feb 2019
    —
    Unknown

    CVE-2018-16108

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 11 Feb 2019
    —
    Unknown

    CVE-2018-16109

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 11 Feb 2019
    —
    Unknown

    CVE-2018-16111

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 11 Feb 2019
    —
    Unknown

    CVE-2018-16112

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 11 Feb 2019
    —
    Unknown

    CVE-2018-16113

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 11 Feb 2019
    —
    Unknown

    CVE-2018-16110

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 11 Feb 2019
    —
    Unknown

    CVE-2018-16099

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 11 Feb 2019
    —
    Unknown

    CVE-2018-16100

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 11 Feb 2019
    —
    Unknown

    CVE-2018-16101

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 11 Feb 2019
    —
    Unknown

    CVE-2018-16102

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 11 Feb 2019
    —
    Unknown

    CVE-2018-16103

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 11 Feb 2019
    —
    Unknown

    CVE-2018-16105

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 11 Feb 2019
    —
    Unknown

    CVE-2018-16106

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 11 Feb 2019
    —
    Unknown

    CVE-2018-16104

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 11 Feb 2019
    8.2
    High

    CVE-2019-8308

    Last Modified: 21 Nov 2024

    Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.

    Published: 11 Feb 2019
    6.5
    Medium

    CVE-2018-15586

    Last Modified: 21 Nov 2024

    Enigmail before 2.0.6 is prone to to OpenPGP signatures being spoofed for arbitrary messages using a PGP/INLINE signature wrapped within a specially crafted multipart HTML email.

    Published: 11 Feb 2019
    7.5
    High

    CVE-2018-15588

    Last Modified: 21 Nov 2024

    MailMate before 1.11.3 mishandles a suspicious HTML/MIME structure in a signed/encrypted email.

    Published: 11 Feb 2019
    5.7
    Medium

    CVE-2019-7730

    Last Modified: 21 Nov 2024

    MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=databases URI.

    Published: 11 Feb 2019
    9.8
    Critical

    CVE-2019-7731

    Last Modified: 21 Nov 2024

    MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup Database function with a .php filename for the backup's archive file.

    Published: 11 Feb 2019
    7.5
    High

    CVE-2019-7732

    Last Modified: 21 Nov 2024

    In Live555 0.95, a setup packet can cause a memory leak leading to DoS because, when there are multiple instances of a single field (username, realm, nonce, uri, or response), only the last instance can ever be freed.

    Published: 11 Feb 2019
    7.5
    High

    CVE-2019-7733

    Last Modified: 21 Nov 2024

    In Live555 0.95, there is a buffer overflow via a large integer in a Content-Length HTTP header because handleRequestBytes has an unrestricted memmove.

    Published: 11 Feb 2019
    9.8
    Critical

    CVE-2019-7736

    Last Modified: 21 Nov 2024

    D-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page. NOTE: this may overlap CVE-2019-13101.

    Published: 11 Feb 2019
    7.8
    High

    CVE-2018-11847

    Last Modified: 21 Nov 2024

    Malicious TA can tag QSEE kernel memory and map to EL0, there by corrupting the physical memory as well it can be used to corrupt the QSEE kernel and compromise the whole TEE in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables and Snapdragon Wired Infrastructure and Networking in versions IPQ8074, MDM9206, MDM9607, MDM9650, MDM9655, MSM8909W, MSM8996AU, QCA8081, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 650/52, SD 820, SD 820A, SD 835, SD 8CX, SDM439 and Snapdragon_High_Med_2016

    Published: 11 Feb 2019
    7.8
    High

    CVE-2018-11962

    Last Modified: 21 Nov 2024

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Use-after-free issue in heap while loading audio effects config in audio effects factory.

    Published: 11 Feb 2019
    5.5
    Medium

    CVE-2018-12006

    Last Modified: 21 Nov 2024

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Users with no extra privileges can potentially access leaked data due to uninitialized padding present in display function.

    Published: 11 Feb 2019
    5.5
    Medium

    CVE-2018-12011

    Last Modified: 21 Nov 2024

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Uninitialized data for socket address leads to information exposure.

    Published: 11 Feb 2019
    7.8
    High

    CVE-2018-12014

    Last Modified: 21 Nov 2024

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Null pointer dereference vulnerability may occur due to missing NULL assignment in NAT module of freed pointer.

    Published: 11 Feb 2019
    9.8
    Critical

    CVE-2018-12547

    Last Modified: 21 Nov 2024

    In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects existing APIs that called the functions to exceed the allocated buffer. This functions were not directly callable by non-native user code.

    Published: 11 Feb 2019
    7.8
    High

    CVE-2018-13889

    Last Modified: 21 Nov 2024

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Heap memory was accessed after it was freed

    Published: 11 Feb 2019
    7.8
    High

    CVE-2018-13893

    Last Modified: 21 Nov 2024

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Out of bound mask range access caused by using possible old value of msg mask table count while copying masks to userspace.

    Published: 11 Feb 2019
    7.8
    High

    CVE-2018-11888

    Last Modified: 21 Nov 2024

    Unauthorized access may be allowed by the SCP11 Crypto Services TA will processing commands from other TA in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile and Snapdragon Voice & Music in versions MDM9607, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 650/52, SD 820, SD 820A, SD 835, SD 8CX, SDM439, Snapdragon_High_Med_2016.

    Published: 11 Feb 2019
    7.8
    High

    CVE-2018-11855

    Last Modified: 21 Nov 2024

    If an end user makes use of SCP11 sample OCE code without modification it could lead to a buffer overflow when transmitting a CAPDU in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT and Snapdragon Mobile in versions MDM9607, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 636, SD 820, SD 820A, SD 835, SD 8CX, SDA660, SDM630, SDM660.

    Published: 11 Feb 2019
    7.8
    High

    CVE-2018-11899

    Last Modified: 21 Nov 2024

    While processing radio connection status change events, Radio index is not properly validated in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile and Snapdragon Voice & Music in versions MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24.

    Published: 11 Feb 2019
    7.8
    High

    CVE-2018-12010

    Last Modified: 21 Nov 2024

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Absence of length sanity check may lead to possible stack overflow resulting in memory corruption in trustzone region.

    Published: 11 Feb 2019
    9.8
    Critical

    CVE-2018-12549

    Last Modified: 21 Nov 2024

    In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when accelerating it.

    Published: 11 Feb 2019
    7.8
    High

    CVE-2018-13888

    Last Modified: 21 Nov 2024

    There is potential for memory corruption in the RIL daemon due to de reference of memory outside the allocated array length in RIL in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in versions MDM9206, MDM9607, MDM9635M, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM439, SDM630, SDM660, ZZ_QCS605.

    Published: 11 Feb 2019
    8.1
    High

    CVE-2019-7722

    Last Modified: 21 Nov 2024

    PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowing attackers tampering it (either by direct modification or MITM attacks when using remote rulesets) to perform information disclosure, denial of service, or request forgery attacks. (PMD 6.x is unaffected because of a 2017-09-15 change.)

    Published: 11 Feb 2019
    7.5
    High

    CVE-2019-6975

    Last Modified: 21 Nov 2024

    Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() function.

    Published: 11 Feb 2019
    5.5
    Medium

    CVE-2018-20587

    Last Modified: 21 Nov 2024

    Bitcoin Core 0.12.0 through 0.17.1 and Bitcoin Knots 0.12.0 through 0.17.x before 0.17.1.knots20181229 have Incorrect Access Control. Local users can exploit this to steal currency by binding the RPC IPv4 localhost port, and forwarding requests to the IPv6 localhost port.

    Published: 11 Feb 2019
    8.1
    High

    CVE-2019-7718

    Last Modified: 21 Nov 2024

    An issue was discovered in Metinfo 6.x. An attacker can leverage a race condition in the backend database backup function to execute arbitrary PHP code via admin/index.php?n=databack&c=index&a=dogetsql&tables=<?php and admin/databack/bakup_tables.php?2=file_put_contents URIs because app/system/databack/admin/index.class.php creates bakup_tables.php temporarily.

    Published: 11 Feb 2019
    9.8
    Critical

    CVE-2019-7719

    Last Modified: 21 Nov 2024

    Nibbleblog 4.0.5 allows eval injection by placing PHP code in the install.php username parameter and then making a content/private/shadow.php request.

    Published: 11 Feb 2019
    9.8
    Critical

    CVE-2019-7720

    Last Modified: 21 Nov 2024

    taocms through 2014-05-24 allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request.

    Published: 11 Feb 2019
    7.5
    High

    CVE-2019-7721

    Last Modified: 21 Nov 2024

    lib/NCCms.class.php in nc-cms 3.5 allows upload of .php files via the index.php?action=save name and editordata parameters.

    Published: 11 Feb 2019
    7.2
    High

    CVE-2018-20773

    Last Modified: 21 Nov 2024

    Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional <?php lines.

    Published: 11 Feb 2019
    5.4
    Medium

    CVE-2018-20774

    Last Modified: 21 Nov 2024

    Frog CMS 0.9.5 has XSS via the admin/?/layout/edit/1 Body field.

    Published: 11 Feb 2019
    7.2
    High

    CVE-2018-20775

    Last Modified: 21 Nov 2024

    admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file under the public/ URI.

    Published: 11 Feb 2019
    7.5
    High

    CVE-2018-20776

    Last Modified: 21 Nov 2024

    Frog CMS 0.9.5 provides a directory listing for a /public request.

    Published: 11 Feb 2019