CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-20750

    Last Modified: 21 Nov 2024

    LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.

    Published: 6 Jan 2019
    9.8
    Critical

    CVE-2018-11788

    Last Modified: 21 Nov 2024

    Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. Apache Karaf XMLInputFactory class doesn't contain any mitigation codes against XXE. This is a potential security risk as an user can inject external XML entities in Apache Karaf version prior to 4.1.7 or 4.2.2. It has been fixed in Apache Karaf 4.1.7 and 4.2.2 releases.

    Published: 6 Jan 2019
    9.8
    Critical

    CVE-2018-20748

    Last Modified: 21 Nov 2024

    LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete.

    Published: 6 Jan 2019
    9.8
    Critical

    CVE-2018-20749

    Last Modified: 21 Nov 2024

    LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.

    Published: 6 Jan 2019
    9.8
    Critical

    CVE-2019-5312

    Last Modified: 12 Sept 2025

    An issue was discovered in weixin-java-tools v3.3.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. NOTE: this issue exists because of an incomplete fix for CVE-2018-20318.

    Published: 4 Jan 2019
    5.4
    Medium

    CVE-2018-1657

    Last Modified: 25 Mar 2025

    IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 144883.

    Published: 4 Jan 2019
    5.3
    Medium

    CVE-2018-1888

    Last Modified: 21 Nov 2024

    An untrusted search path vulnerability in IBM i Access for Windows versions 7.1 and earlier on Windows can allow arbitrary code execution via a Trojan horse DLL in the current working directory, related to use of the LoadLibrary function. IBM X-Force ID: 152079.

    Published: 4 Jan 2019
    6.1
    Medium

    CVE-2019-5311

    Last Modified: 21 Nov 2024

    An issue was discovered in YUNUCMS V1.1.8. app/index/controller/Show.php has an XSS vulnerability via the index.php/index/show/index cw parameter.

    Published: 4 Jan 2019
    4.3
    Medium

    CVE-2018-1859

    Last Modified: 21 Nov 2024

    IBM API Connect 5.0.0.0 through 5.0.8.4 could allow a user authenticated as an administrator with limited rights to escalate their privileges. IBM X-Force ID: 151258.

    Published: 4 Jan 2019
    5.4
    Medium

    CVE-2018-1951

    Last Modified: 25 Mar 2025

    IBM Publishing Engine 2.1.2, 6.0.5, and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153494.

    Published: 4 Jan 2019
    6.1
    Medium

    CVE-2019-5310

    Last Modified: 21 Nov 2024

    YUNUCMS 1.1.8 has XSS in app/admin/controller/System.php because crafted data can be written to the sys.php file, as demonstrated by site_title in an admin/system/basic POST request.

    Published: 4 Jan 2019
    7.2
    High

    CVE-2019-5009

    Last Modified: 21 Nov 2024

    Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and has a size of 150x40. One can put PHP code into the image; PHP code can be executed using "<? ?>" tags, as demonstrated by a CompanyDetailsSave action. This bypasses the bad-file-extensions protection mechanism. It is related to actions/CompanyDetailsSave.php, actions/UpdateCompanyLogo.php, and models/CompanyDetails.php.

    Published: 4 Jan 2019
    7.5
    High

    CVE-2019-5008

    Last Modified: 21 Nov 2024

    hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a denial of service via a device driver.

    Published: 4 Jan 2019
    7.5
    High

    CVE-2018-20176

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain several Out-Of- Bounds Reads in the file secure.c that result in a Denial of Service (segfault).

    Published: 4 Jan 2019
    7.5
    High

    CVE-2018-20178

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function process_demand_active() that results in a Denial of Service (segfault).

    Published: 4 Jan 2019
    9.8
    Critical

    CVE-2018-20180

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_process() and results in memory corruption and probably even a remote code execution.

    Published: 4 Jan 2019
    9.8
    Critical

    CVE-2018-20182

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain a Buffer Overflow over the global variables in the function seamless_process_line() that results in memory corruption and probably even a remote code execution.

    Published: 4 Jan 2019
    7.5
    High

    CVE-2018-8791

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpdr_process() that results in an information leak.

    Published: 4 Jan 2019
    7.5
    High

    CVE-2018-8792

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function cssp_read_tsrequest() that results in a Denial of Service (segfault).

    Published: 4 Jan 2019
    9.8
    Critical

    CVE-2018-8794

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() and results in a memory corruption and possibly even a remote code execution.

    Published: 4 Jan 2019
    7.5
    High

    CVE-2018-8798

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpsnd_process_ping() that results in an information leak.

    Published: 4 Jan 2019
    7.5
    High

    CVE-2018-8799

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that results in a Denial of Service (segfault).

    Published: 4 Jan 2019
    9.8
    Critical

    CVE-2018-8800

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corruption and probably even a remote code execution.

    Published: 4 Jan 2019
    8.8
    High

    CVE-2019-6128

    Last Modified: 21 Nov 2024

    The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.

    Published: 4 Jan 2019
    —
    Unknown

    CVE-2019-5313

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 4 Jan 2019
    —
    Unknown

    CVE-2019-5316

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 4 Jan 2019
    —
    Unknown

    CVE-2019-5325

    Last Modified: 7 Nov 2023

    CVE was unused by HPE.

    Published: 4 Jan 2019
    7.5
    High

    CVE-2018-20174

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function ui_clip_handle_data() that results in an information leak.

    Published: 4 Jan 2019
    7.5
    High

    CVE-2018-20175

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contains several Integer Signedness errors that lead to Out-Of-Bounds Reads in the file mcs.c and result in a Denial of Service (segfault).

    Published: 4 Jan 2019
    9.8
    Critical

    CVE-2018-20177

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in the function rdp_in_unistr() and results in memory corruption and possibly even a remote code execution.

    Published: 4 Jan 2019
    9.8
    Critical

    CVE-2018-20179

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function lspci_process() and results in memory corruption and probably even a remote code execution.

    Published: 4 Jan 2019
    9.8
    Critical

    CVE-2018-20181

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamless_process() and results in memory corruption and probably even a remote code execution.

    Published: 4 Jan 2019
    7.8
    High

    CVE-2018-20669

    Last Modified: 21 Nov 2024

    An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL function call to overwrite arbitrary kernel memory, resulting in a Denial of Service or privilege escalation.

    Published: 4 Jan 2019
    9.8
    Critical

    CVE-2018-8793

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_read_tsrequest() that results in a memory corruption and probably even a remote code execution.

    Published: 4 Jan 2019
    9.8
    Critical

    CVE-2018-8795

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in function process_bitmap_updates() and results in a memory corruption and probably even a remote code execution.

    Published: 4 Jan 2019
    7.5
    High

    CVE-2018-8796

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_bitmap_updates() that results in a Denial of Service (segfault).

    Published: 4 Jan 2019
    9.8
    Critical

    CVE-2018-8797

    Last Modified: 21 Nov 2024

    rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function process_plane() that results in a memory corruption and probably even a remote code execution.

    Published: 4 Jan 2019
    6.1
    Medium

    CVE-2018-8827

    Last Modified: 21 Nov 2024

    The admin web interface on Technicolor MediaAccess TG789vac v2 HP devices with firmware v16.3.7190-2761005-20161004084353 displays unsanitised user input, which allows an unauthenticated malicious user to embed JavaScript into the Log viewer interface via a crafted HTTP Referer header, aka XSS.

    Published: 3 Jan 2019
    5.5
    Medium

    CVE-2019-5005

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. They allowed Denial of Service (application crash) via image data, because two bytes are written to the end of the allocated memory without judging whether this will cause corruption.

    Published: 3 Jan 2019
    5.5
    Medium

    CVE-2019-5006

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is a NULL pointer dereference during PDF parsing.

    Published: 3 Jan 2019
    7.1
    High

    CVE-2019-5007

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is an Out-of-Bounds Read Information Disclosure and crash due to a NULL pointer dereference when reading TIFF data during TIFF parsing.

    Published: 3 Jan 2019
    9
    Critical

    CVE-2018-4012

    Last Modified: 21 Nov 2024

    An exploitable buffer overflow vulnerability exists in the HTTP header-parsing function of the Webroot BrightCloud SDK. The function bc_http_read_header incorrectly handles overlong headers, leading to arbitrary code execution. An unauthenticated attacker could impersonate a remote BrightCloud server to trigger this vulnerability.

    Published: 3 Jan 2019
    5.5
    Medium

    CVE-2018-3986

    Last Modified: 21 Nov 2024

    An exploitable information disclosure vulnerability exists in the "Secret Chats" functionality of the Telegram Android messaging application version 4.9.0. The "Secret Chats" functionality allows a user to delete all traces of a chat, either by using a time trigger or by direct request. There is a bug in this functionality that leaves behind photos taken and shared on the secret chats, even after the chats are deleted. These photos will be stored in the device and accessible to all applications installed on the Android device.

    Published: 3 Jan 2019
    7.5
    High

    CVE-2018-19249

    Last Modified: 21 Nov 2024

    The Stripe API v1 allows remote attackers to bypass intended access restrictions by replaying api.stripe.com /v1/tokens XMLHttpRequest data, parsing the response under the object card{}, and reading the cvc_check information if the creation is successful without charging the actual card used in the transaction.

    Published: 3 Jan 2019
    9.8
    Critical

    CVE-2018-18995

    Last Modified: 21 Nov 2024

    Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet or web interfaces, which could enable various effects vectors, including conducting device resets, reading or modifying registers, and changing configuration settings such as IP addresses.

    Published: 3 Jan 2019
    6.1
    Medium

    CVE-2018-18997

    Last Modified: 21 Nov 2024

    Pluto Safety PLC Gateway Ethernet devices in ABB GATE-E1 and GATE-E2 all versions allows an unauthenticated attacker using the administrative web interface to insert an HTML/Javascript payload into any of the device properties, which may allow an attacker to display/execute the payload in a visitor browser.

    Published: 3 Jan 2019
    4.3
    Medium

    CVE-2018-15780

    Last Modified: 21 Nov 2024

    RSA Archer versions prior to 6.5.0.1 contain an improper access control vulnerability. A remote malicious user could potentially exploit this vulnerability to bypass authorization checks and gain read access to restricted user information.

    Published: 3 Jan 2019
    5.3
    Medium

    CVE-2018-18004

    Last Modified: 21 Nov 2024

    Incorrect Access Control in mod_inetd.cgi in VIVOTEK Network Camera Series products with firmware before XXXXXX-VVTK-0X09a allows remote attackers to enable arbitrary system services via a URL parameter.

    Published: 3 Jan 2019
    6.1
    Medium

    CVE-2018-18005

    Last Modified: 21 Nov 2024

    Cross-site scripting in event_script.js in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript via a URL query string parameter.

    Published: 3 Jan 2019
    6.1
    Medium

    CVE-2018-18244

    Last Modified: 21 Nov 2024

    Cross-site scripting in syslog.html in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript code via an HTTP Referer Header.

    Published: 3 Jan 2019