CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-4277

    Last Modified: 21 Nov 2024

    In iOS before 11.4.1, watchOS before 4.3.2, tvOS before 11.4.1, Safari before 11.1.1, macOS High Sierra before 10.13.6, a spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation.

    Published: 11 Jan 2019
    4.3
    Medium

    CVE-2018-4278

    Last Modified: 21 Nov 2024

    In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tracking.

    Published: 11 Jan 2019
    9.8
    Critical

    CVE-2018-4281

    Last Modified: 21 Nov 2024

    In SwiftNIO before 1.8.0, a buffer overflow was addressed with improved size validation.

    Published: 11 Jan 2019
    9.8
    Critical

    CVE-2018-4298

    Last Modified: 21 Nov 2024

    In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a permissions issue existed in Remote Management. This issue was addressed through improved permission validation.

    Published: 11 Jan 2019
    7.8
    High

    CVE-2018-4330

    Last Modified: 21 Nov 2024

    In iOS before 11.4, a memory corruption issue exists and was addressed with improved memory handling.

    Published: 11 Jan 2019
    7.5
    High

    CVE-2017-13888

    Last Modified: 21 Nov 2024

    In iOS before 11.2, a type confusion issue was addressed with improved memory handling.

    Published: 11 Jan 2019
    7.5
    High

    CVE-2017-13887

    Last Modified: 21 Nov 2024

    In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation. This was addressed with improved state management.

    Published: 11 Jan 2019
    8.8
    High

    CVE-2018-4404

    Last Modified: 21 Nov 2024

    In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improved memory handling.

    Published: 11 Jan 2019
    9.8
    Critical

    CVE-2018-4147

    Last Modified: 21 Nov 2024

    In iCloud for Windows before 7.3, Safari before 11.0.3, iTunes before 12.7.3 for Windows, and iOS before 11.2.5, multiple memory corruption issues exist and were addressed with improved memory handling.

    Published: 11 Jan 2019
    7.5
    High

    CVE-2018-4185

    Last Modified: 21 Nov 2024

    In iOS before 11.3, tvOS before 11.3, watchOS before 4.3, and macOS before High Sierra 10.13.4, an information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling.

    Published: 11 Jan 2019
    5.9
    Medium

    CVE-2016-4642

    Last Modified: 21 Nov 2024

    In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, proxy authentication incorrectly reported HTTP proxies received credentials securely. This issue was addressed through improved warnings.

    Published: 11 Jan 2019
    6.5
    Medium

    CVE-2016-4643

    Last Modified: 21 Nov 2024

    In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing of 407 responses. This issue was addressed through improved response validation.

    Published: 11 Jan 2019
    6.5
    Medium

    CVE-2016-4644

    Last Modified: 21 Nov 2024

    In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with the credentials.

    Published: 11 Jan 2019
    7.8
    High

    CVE-2016-7576

    Last Modified: 21 Nov 2024

    In iOS before 9.3.3, a memory corruption issue existed in the kernel. This issue was addressed through improved memory handling.

    Published: 11 Jan 2019
    6.5
    Medium

    CVE-2017-13886

    Last Modified: 21 Nov 2024

    In macOS High Sierra before 10.13.2, an access issue existed with privileged WiFi system configuration. This issue was addressed with additional restrictions.

    Published: 11 Jan 2019
    9.8
    Critical

    CVE-2017-13889

    Last Modified: 21 Nov 2024

    In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic error existed in the validation of credentials. This was addressed with improved credential validation.

    Published: 11 Jan 2019
    6.5
    Medium

    CVE-2017-13891

    Last Modified: 21 Nov 2024

    In iOS before 11.2, an inconsistent user interface issue was addressed through improved state management.

    Published: 11 Jan 2019
    5.9
    Medium

    CVE-2017-2411

    Last Modified: 21 Nov 2024

    In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.

    Published: 11 Jan 2019
    9.8
    Critical

    CVE-2018-4189

    Last Modified: 21 Nov 2024

    In iOS before 11.2.5, macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, watchOS before 4.2.2, and tvOS before 11.2.5, a memory corruption issue exists and was addressed with improved memory handling.

    Published: 11 Jan 2019
    8.8
    High

    CVE-2018-4208

    Last Modified: 21 Nov 2024

    In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.

    Published: 11 Jan 2019
    8.8
    High

    CVE-2018-4209

    Last Modified: 21 Nov 2024

    In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.

    Published: 11 Jan 2019
    9.8
    Critical

    CVE-2018-4254

    Last Modified: 21 Nov 2024

    In macOS High Sierra before 10.13.5, an input validation issue existed in the kernel. This issue was addressed with improved input validation.

    Published: 11 Jan 2019
    8.8
    High

    CVE-2018-4262

    Last Modified: 21 Nov 2024

    In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, multiple memory corruption issues were addressed with improved memory handling.

    Published: 11 Jan 2019
    7.5
    High

    CVE-2019-6136

    Last Modified: 21 Nov 2024

    An issue has been found in libIEC61850 v1.3.1. Ethernet_setProtocolFilter in hal/ethernet/linux/ethernet_linux.c has a SEGV, as demonstrated by sv_subscriber_example.c and sv_subscriber.c.

    Published: 11 Jan 2019
    —
    Unknown

    CVE-2018-20132

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 11 Jan 2019
    7.5
    High

    CVE-2019-6135

    Last Modified: 21 Nov 2024

    An issue has been found in libIEC61850 v1.3.1. Memory_malloc in hal/memory/lib_memory.c has a memory leak when called from Asn1PrimitiveValue_create in mms/asn1/asn1_ber_primitive_value.c, as demonstrated by goose_publisher_example.c and iec61850_9_2_LE_example.c.

    Published: 11 Jan 2019
    7.5
    High

    CVE-2019-6137

    Last Modified: 21 Nov 2024

    An issue was discovered in lib60870 2.1.1. LinkLayer_setAddress in link_layer/link_layer.c has a NULL pointer dereference.

    Published: 11 Jan 2019
    7.5
    High

    CVE-2019-6138

    Last Modified: 21 Nov 2024

    An issue has been found in libIEC61850 v1.3.1. Memory_malloc and Memory_calloc in hal/memory/lib_memory.c have memory leaks when called from mms/iso_mms/common/mms_value.c, server/mms_mapping/mms_mapping.c, and server/mms_mapping/mms_sv.c (via common/string_utilities.c), as demonstrated by iec61850_9_2_LE_example.c.

    Published: 11 Jan 2019
    5.8
    Medium

    CVE-2018-15464

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco 900 Series Aggregation Services Router (ASR) software could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient handling of certain broadcast packets ingress to the device. An attacker could exploit this vulnerability by sending large streams of broadcast packets to an affected device. If successful, an exploit could allow an attacker to impact services running on the device, resulting in a partial DoS condition.

    Published: 11 Jan 2019
    5.3
    Medium

    CVE-2018-15466

    Last Modified: 21 Nov 2024

    A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface. The attacker would need to have access to the internal VLAN where CPS is deployed. The vulnerability is due to lack of authentication. An attacker could exploit this vulnerability by directly connecting to the Graphite web interface. An exploit could allow the attacker to access various statistics and Key Performance Indicators (KPIs) regarding the Cisco Policy Suite environment.

    Published: 11 Jan 2019
    6.1
    Medium

    CVE-2018-15467

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information.

    Published: 11 Jan 2019
    7.5
    High

    CVE-2019-6126

    Last Modified: 21 Nov 2024

    The Admin Panel of PHP Scripts Mall Advance Peer to Peer MLM Script v1.7.0 allows remote attackers to bypass intended access restrictions by directly navigating to admin/dashboard.php or admin/user.php, as demonstrated by disclosure of information about users and staff.

    Published: 11 Jan 2019
    7.2
    High

    CVE-2019-6127

    Last Modified: 21 Nov 2024

    An issue was discovered in XiaoCms 20141229. It allows admin/index.php?c=database table[] SQL injection. This can be used for PHP code execution via "INTO OUTFILE" with a .php filename.

    Published: 11 Jan 2019
    5.5
    Medium

    CVE-2019-6130

    Last Modified: 21 Nov 2024

    Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. This is related to page-number mishandling in cbz/mucbz.c, cbz/muimg.c, and svg/svg-doc.c.

    Published: 11 Jan 2019
    5.5
    Medium

    CVE-2019-6131

    Last Modified: 21 Nov 2024

    svg-run.c in Artifex MuPDF 1.14.0 has infinite recursion with stack consumption in svg_run_use_symbol, svg_run_element, and svg_run_use, as demonstrated by mutool.

    Published: 11 Jan 2019
    7.5
    High

    CVE-2019-6132

    Last Modified: 21 Nov 2024

    An issue was discovered in Bento4 v1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp when called from the AP4_EsdsAtom class in Core/Ap4EsdsAtom.cpp, as demonstrated by mp42aac.

    Published: 11 Jan 2019
    6.5
    Medium

    CVE-2019-6129

    Last Modified: 28 May 2026

    png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer.

    Published: 11 Jan 2019
    —
    Unknown

    CVE-2019-6174

    Last Modified: 29 Jul 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 11 Jan 2019
    7.8
    High

    CVE-2019-6778

    Last Modified: 21 Nov 2024

    In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.

    Published: 11 Jan 2019
    6.5
    Medium

    CVE-2019-3459

    Last Modified: 21 Nov 2024

    A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.

    Published: 11 Jan 2019
    6.5
    Medium

    CVE-2019-6461

    Last Modified: 21 Nov 2024

    An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c.

    Published: 11 Jan 2019
    6.5
    Medium

    CVE-2019-6462

    Last Modified: 21 Nov 2024

    An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.

    Published: 11 Jan 2019
    6.5
    Medium

    CVE-2019-7148

    Last Modified: 21 Nov 2024

    An attempted excessive memory allocation was discovered in the function read_long_names in elf_begin.c in libelf in elfutils 0.174. Remote attackers could leverage this vulnerability to cause a denial-of-service via crafted elf input, which leads to an out-of-memory exception. NOTE: The maintainers believe this is not a real issue, but instead a "warning caused by ASAN because the allocation is big. By setting ASAN_OPTIONS=allocator_may_return_null=1 and running the reproducer, nothing happens."

    Published: 11 Jan 2019
    6.5
    Medium

    CVE-2019-3460

    Last Modified: 21 Nov 2024

    A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1.

    Published: 11 Jan 2019
    —
    Unknown

    CVE-2019-6141

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 11 Jan 2019
    —
    Unknown

    CVE-2019-6148

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 11 Jan 2019
    —
    Unknown

    CVE-2019-6162

    Last Modified: 29 Jul 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 11 Jan 2019
    —
    Unknown

    CVE-2019-6164

    Last Modified: 29 Jul 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 11 Jan 2019
    —
    Unknown

    CVE-2019-6185

    Last Modified: 29 Jul 2024

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 11 Jan 2019
    5.5
    Medium

    CVE-2019-6501

    Last Modified: 21 Nov 2024

    In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.

    Published: 11 Jan 2019