CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2018-2031

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 22 Jan 2019
    9.8
    Critical

    CVE-2018-6444

    Last Modified: 21 Nov 2024

    A Vulnerability in Brocade Network Advisor versions before 14.1.0 could allow a remote unauthenticated attacker to execute arbitray code. The vulnerability could also be exploited to execute arbitrary OS Commands.

    Published: 22 Jan 2019
    7.5
    High

    CVE-2018-6445

    Last Modified: 21 Nov 2024

    A Vulnerability in Brocade Network Advisor versions before 14.0.3 could allow a remote unauthenticated attacker to export the current user database which includes the encrypted (not hashed) password of the systems. The attacker could gain access to the Brocade Network Advisor System after extracting/decrypting the passwords.

    Published: 22 Jan 2019
    8.1
    High

    CVE-2018-6443

    Last Modified: 21 Nov 2024

    A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications. A remote unauthenticated user who has access to Network Advisor client libraries and able to decrypt the Jboss credentials could gain access to the Jboss web console.

    Published: 22 Jan 2019
    8.8
    High

    CVE-2019-6509

    Last Modified: 21 Nov 2024

    An issue was discovered in creditease-sec insight through 2018-09-11. depart_delete in srcpm/app/admin/views.py allows CSRF.

    Published: 22 Jan 2019
    8.8
    High

    CVE-2019-6508

    Last Modified: 21 Nov 2024

    An issue was discovered in creditease-sec insight through 2018-09-11. role_perm_delete in srcpm/app/admin/views.py allows CSRF.

    Published: 22 Jan 2019
    8.8
    High

    CVE-2019-6507

    Last Modified: 21 Nov 2024

    An issue was discovered in creditease-sec insight through 2018-09-11. login_user_delete in srcpm/app/admin/views.py allows CSRF.

    Published: 22 Jan 2019
    8.8
    High

    CVE-2019-6510

    Last Modified: 21 Nov 2024

    An issue was discovered in creditease-sec insight through 2018-09-11. user_delete in srcpm/app/admin/views.py allows CSRF.

    Published: 22 Jan 2019
    6.5
    Medium

    CVE-2017-6923

    Last Modified: 21 Nov 2024

    In Drupal 8.x prior to 8.3.7 When creating a view, you can optionally use Ajax to update the displayed data via filter parameters. The views subsystem/module did not restrict access to the Ajax endpoint to only views configured to use Ajax. This is mitigated if you have access restrictions on the view. It is best practice to always include some form of access restrictions on all views, even if you are using another module to display them.

    Published: 22 Jan 2019
    9.8
    Critical

    CVE-2018-19635

    Last Modified: 21 Nov 2024

    CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to escalate privileges in the user interface.

    Published: 22 Jan 2019
    9.8
    Critical

    CVE-2019-6339

    Last Modified: 21 Nov 2024

    In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration.

    Published: 22 Jan 2019
    6.5
    Medium

    CVE-2017-6922

    Last Modified: 21 Nov 2024

    In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded them, rather than all anonymous users. Drupal core did not previously provide this protection, allowing an access bypass vulnerability to occur. This issue is mitigated by the fact that in order to be affected, the site must allow anonymous users to upload files into a private file system.

    Published: 22 Jan 2019
    7.5
    High

    CVE-2018-19634

    Last Modified: 21 Nov 2024

    CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to access survey information.

    Published: 22 Jan 2019
    8
    High

    CVE-2019-6338

    Last Modified: 21 Nov 2024

    In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Drupal configurations. Refer to CVE-2018-1000888 for details

    Published: 22 Jan 2019
    9.8
    Critical

    CVE-2019-6503

    Last Modified: 21 Nov 2024

    There is a deserialization vulnerability in Chatopera cosin v3.10.0. An attacker can execute commands during server-side deserialization by uploading maliciously constructed files. This is related to the TemplateController.java impsave method and the MainUtils toObject method.

    Published: 22 Jan 2019
    4.3
    Medium

    CVE-2018-13374

    Last Modified: 24 Oct 2025

    A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

    Published: 22 Jan 2019
    7.5
    High

    CVE-2019-0190

    Last Modified: 21 Nov 2024

    A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts.

    Published: 22 Jan 2019
    7.5
    High

    CVE-2018-17199

    Last Modified: 21 Nov 2024

    In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.

    Published: 22 Jan 2019
    8.8
    High

    CVE-2020-1716

    Last Modified: 21 Nov 2024

    A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force Ceph deployments, and gain administrator access to Ceph clusters via the Ceph dashboard to initiate read, write, and delete Ceph clusters and also modify Ceph cluster configurations. Versions before ceph-ansible 6.0.0alpha1 are affected.

    Published: 22 Jan 2019
    6.5
    Medium

    CVE-2018-18508

    Last Modified: 21 Nov 2024

    In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.

    Published: 22 Jan 2019
    5.5
    Medium

    CVE-2018-20449

    Last Modified: 21 Nov 2024

    The hidma_chan_stats function in drivers/dma/qcom/hidma_dbg.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading "callback=" lines in a debugfs file.

    Published: 22 Jan 2019
    5.3
    Medium

    CVE-2018-17189

    Last Modified: 21 Nov 2024

    In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.

    Published: 22 Jan 2019
    8.1
    High

    CVE-2019-6499

    Last Modified: 21 Nov 2024

    Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint database account (in viewpoint-portal\conf\server.xml) that could potentially be exploited by malicious users to compromise the affected system.

    Published: 21 Jan 2019
    7.5
    High

    CVE-2019-6500

    Last Modified: 21 Nov 2024

    In Axway File Transfer Direct 2.7.1, an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request with %2e instead of '.' characters, as demonstrated by an initial /h2hdocumentation//%2e%2e/ substring.

    Published: 21 Jan 2019
    8.8
    High

    CVE-2019-6498

    Last Modified: 21 Nov 2024

    GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused.

    Published: 21 Jan 2019
    7.5
    High

    CVE-2019-3817

    Last Modified: 21 Nov 2024

    A use-after-free flaw has been discovered in libcomps before version 0.1.10 in the way ObjMRTrees are merged. An attacker, who is able to make an application read a crafted comps XML file, may be able to crash the application or execute malicious code.

    Published: 21 Jan 2019
    9.8
    Critical

    CVE-2019-9169

    Last Modified: 21 Nov 2024

    In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.

    Published: 20 Jan 2019
    7.5
    High

    CVE-2019-6502

    Last Modified: 21 Nov 2024

    sc_context_create in ctx.c in libopensc in OpenSC 0.19.0 has a memory leak, as demonstrated by a call from eidenv.

    Published: 20 Jan 2019
    7.5
    High

    CVE-2018-20796

    Last Modified: 21 Nov 2024

    In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.

    Published: 20 Jan 2019
    6.5
    Medium

    CVE-2019-1000019

    Last Modified: 21 Nov 2024

    libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_format_7zip.c, header_bytes() that can result in a crash (denial of service). This attack appears to be exploitable via the victim opening a specially crafted 7zip file.

    Published: 20 Jan 2019
    6.5
    Medium

    CVE-2019-1000020

    Last Modified: 21 Nov 2024

    libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ISO9660 parser, archive_read_support_format_iso9660.c, read_CE()/parse_rockridge() that can result in DoS by infinite loop. This attack appears to be exploitable via the victim opening a specially crafted ISO9660 file.

    Published: 20 Jan 2019
    5.9
    Medium

    CVE-2018-18908

    Last Modified: 21 Nov 2024

    The Sky Go Desktop application 1.0.19-1 through 1.0.23-1 for Windows performs several requests over cleartext HTTP. This makes the data submitted in these requests prone to Man in The Middle (MiTM) attacks, whereby an attacker would be able to obtain the data sent in these requests. Some of the requests contain potentially sensitive information that could be useful to an attacker, such as the victim's Sky username.

    Published: 19 Jan 2019
    8.8
    High

    CVE-2019-6496

    Last Modified: 21 Nov 2024

    The ThreadX-based firmware on Marvell Avastar Wi-Fi devices, models 88W8787, 88W8797, 88W8801, 88W8897, and 88W8997, allows remote attackers to execute arbitrary code or cause a denial of service (block pool overflow) via malformed Wi-Fi packets during identification of available Wi-Fi networks. Exploitation of the Wi-Fi device can lead to exploitation of the host application processor in some cases, but this depends on several factors including host OS hardening and the availability of DMA.

    Published: 19 Jan 2019
    9.8
    Critical

    CVE-2019-6497

    Last Modified: 21 Nov 2024

    Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter.

    Published: 19 Jan 2019
    5.5
    Medium

    CVE-2019-18885

    Last Modified: 21 Nov 2024

    fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents NULL pointer dereference via a crafted btrfs image because fs_devices->devices is mishandled within find_device, aka CID-09ba3bc9dd15.

    Published: 19 Jan 2019
    8.8
    High

    CVE-2018-5881

    Last Modified: 21 Nov 2024

    Improper validation of buffer length checks in the lwm2m device management protocol can leads to a buffer overflow in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 636, SD 835, SDA660, SDM630, SDM660

    Published: 18 Jan 2019
    9.8
    Critical

    CVE-2018-5915

    Last Modified: 21 Nov 2024

    Exception in Modem IP stack while processing IPv6 packet in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX20, SXR1130

    Published: 18 Jan 2019
    9.8
    Critical

    CVE-2017-18160

    Last Modified: 21 Nov 2024

    AGPS session failure in GNSS module due to cyphersuites are hardcoded and needed manual update everytime in snapdragon mobile and snapdragon wear in versions MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 835, SD 845, SD 850

    Published: 18 Jan 2019
    7.8
    High

    CVE-2017-18331

    Last Modified: 21 Nov 2024

    Improper access control on secure display buffers in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 820, SD 820A, SD 835, SDA660

    Published: 18 Jan 2019
    5.5
    Medium

    CVE-2017-18332

    Last Modified: 21 Nov 2024

    Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX20, SXR1130

    Published: 18 Jan 2019
    7.8
    High

    CVE-2017-8276

    Last Modified: 21 Nov 2024

    Improper authorization involving a fuse in TrustZone in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SDA660, SDM439, SDM630, SDM660, SDX24, Snapdragon_High_Med_2016.

    Published: 18 Jan 2019
    8.8
    High

    CVE-2018-11279

    Last Modified: 21 Nov 2024

    Lack of check of input size can make device memory get corrupted because of buffer overflow in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 810, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDM439, SDM630, SDM660, SDX20, Snapdragon_High_Med_2016, SXR1130

    Published: 18 Jan 2019
    9.3
    Critical

    CVE-2018-11284

    Last Modified: 21 Nov 2024

    Spoofed SMS can be used to send a large number of messages to the device which will in turn initiate a flood of registration updates with the server in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 625, SD 636, SDA660, SDM630, SDM660, SDX20

    Published: 18 Jan 2019
    7.8
    High

    CVE-2018-11288

    Last Modified: 21 Nov 2024

    Possible undefined behavior due to lack of size check in function for parameter segment_idx can lead to a read outside of the intended region in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDX24, SXR1130

    Published: 18 Jan 2019
    8.8
    High

    CVE-2018-11993

    Last Modified: 21 Nov 2024

    Improper check while accessing the local memory stack on MQTT connection request can lead to buffer overflow in snapdragon wear in versions MDM9206, MDM9607

    Published: 18 Jan 2019
    7.5
    High

    CVE-2018-11998

    Last Modified: 21 Nov 2024

    While processing a packet decode request in MQTT, Race condition can occur leading to an out-of-bounds access in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, SD 210/SD 212/SD 205, SD 427, SD 435, SD 450, SD 625, SD 636, SD 835, SDA660, SDM630, SDM660, Snapdragon_High_Med_2016

    Published: 18 Jan 2019
    5.5
    Medium

    CVE-2018-11999

    Last Modified: 21 Nov 2024

    Improper input validation in trustzone can lead to denial of service in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 636, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDM630, SDM660, SDX24

    Published: 18 Jan 2019
    7.4
    High

    CVE-2018-15784

    Last Modified: 21 Nov 2024

    Dell Networking OS10 versions prior to 10.4.3.0 contain a vulnerability in the Phone Home feature which does not properly validate the server's certificate authority during TLS handshake. Use of an invalid or malicious certificate could potentially allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.

    Published: 18 Jan 2019
    5.5
    Medium

    CVE-2018-3595

    Last Modified: 21 Nov 2024

    Anti-rollback can be bypassed in replay scenario during app loading due to improper error handling of RPMB writes in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX24, SXR1130

    Published: 18 Jan 2019
    7.8
    High

    CVE-2018-5867

    Last Modified: 21 Nov 2024

    Lack of checking input size can lead to buffer overflow In WideVine in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDM439, SDM630, SDM660, SDX24, Snapdragon_High_Med_2016, SXR1130

    Published: 18 Jan 2019