CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2018-20562

    Last Modified: 21 Nov 2024

    An issue was discovered in DouCo DouPHP 1.5 20181221. admin/article_category.php?rec=update has XSS via the cat_name parameter.

    Published: 28 Dec 2018
    9.8
    Critical

    CVE-2018-1000625

    Last Modified: 21 Nov 2024

    Battelle V2I Hub 2.5.1 contains hard-coded credentials for the administrative account. An attacker could exploit this vulnerability to log in as an admin on any installation and gain unauthorized access to the system.

    Published: 28 Dec 2018
    9.8
    Critical

    CVE-2018-1000626

    Last Modified: 21 Nov 2024

    Battelle V2I Hub 2.5.1 could allow a remote attacker to bypass security restrictions, caused by the lack of requirement to change the default API key. An attacker could exploit this vulnerability using all available API functions containing an unchanged API key to gain unauthorized access to the system.

    Published: 28 Dec 2018
    9.8
    Critical

    CVE-2018-1000627

    Last Modified: 21 Nov 2024

    Battelle V2I Hub 2.5.1 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict access to the API key file. An attacker could exploit this vulnerability to obtain the current API key to gain unauthorized access to the system.

    Published: 28 Dec 2018
    9.8
    Critical

    CVE-2018-1000628

    Last Modified: 21 Nov 2024

    Battelle V2I Hub 2.5.1 could allow a remote attacker to bypass security restrictions, caused by the direct checking of the API key against a user-supplied value in PHP's GET global variable array using PHP's strcmp() function. By adding "[]" to the end of "key" in the URL when accessing API functions, an attacker could exploit this vulnerability to execute API functions.

    Published: 28 Dec 2018
    6.1
    Medium

    CVE-2018-1000629

    Last Modified: 21 Nov 2024

    Battelle V2I Hub 2.5.1 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by api/SystemConfigActions.php?action=add and the index.php script. A remote attacker could exploit this vulnerability using the parameterName or _login_username parameter in a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

    Published: 28 Dec 2018
    9.8
    Critical

    CVE-2018-1000631

    Last Modified: 21 Nov 2024

    Battelle V2I Hub 3.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the tmx/TmxCtl/src/lib/PluginStatus.cpp and TmxControl::user_info() function, which could allow the attacker to view, add, modify or delete information in the back-end database.

    Published: 28 Dec 2018
    7.2
    High

    CVE-2018-1000630

    Last Modified: 21 Nov 2024

    Battelle V2I Hub 2.5.1 is vulnerable to SQL injection. A remote authenticated attacker could send specially-crafted SQL statements to /api/PluginStatusActions.php and /status/pluginStatus.php using the jtSorting or id parameter, which could allow the attacker to view, add, modify or delete information in the back-end database.

    Published: 28 Dec 2018
    7.5
    High

    CVE-2018-1000624

    Last Modified: 21 Nov 2024

    Battelle V2I Hub 2.5.1 is vulnerable to a denial of service, caused by the failure to restrict access to a sensitive functionality. By visiting http://V2I_HUB/UI/powerdown.php, a remote attacker could exploit this vulnerability to shut down the system.

    Published: 28 Dec 2018
    7.8
    High

    CVE-2018-20552

    Last Modified: 21 Nov 2024

    Tcpreplay before 4.3.1 has a heap-based buffer over-read in packet2tree in tree.c.

    Published: 28 Dec 2018
    7.8
    High

    CVE-2018-20553

    Last Modified: 21 Nov 2024

    Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c.

    Published: 28 Dec 2018
    6.5
    Medium

    CVE-2018-20536

    Last Modified: 21 Nov 2024

    There is a heap-based buffer over-read at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that will cause a denial of service.

    Published: 28 Dec 2018
    6.5
    Medium

    CVE-2018-20539

    Last Modified: 21 Nov 2024

    There is a Segmentation fault triggered by illegal address access at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that will cause a denial of service.

    Published: 28 Dec 2018
    6.5
    Medium

    CVE-2018-20540

    Last Modified: 21 Nov 2024

    There is memory leak at liblas::Open (liblas/liblas.hpp) in libLAS 1.8.1.

    Published: 28 Dec 2018
    8.8
    High

    CVE-2018-20542

    Last Modified: 21 Nov 2024

    There is a heap-based buffer-overflow at generator_spgemm_csc_reader.c (function libxsmm_sparse_csc_reader) in LIBXSMM 1.10, a different vulnerability than CVE-2018-20541 (which is in a different part of the source code and is seen at a different address).

    Published: 28 Dec 2018
    6.5
    Medium

    CVE-2018-20543

    Last Modified: 21 Nov 2024

    There is an attempted excessive memory allocation at libxsmm_sparse_csc_reader in generator_spgemm_csc_reader.c in LIBXSMM 1.10 that will cause a denial of service.

    Published: 28 Dec 2018
    8.1
    High

    CVE-2018-20546

    Last Modified: 21 Nov 2024

    There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case.

    Published: 28 Dec 2018
    8.1
    High

    CVE-2018-20547

    Last Modified: 21 Nov 2024

    There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for 24bpp data.

    Published: 28 Dec 2018
    8.8
    High

    CVE-2018-20548

    Last Modified: 21 Nov 2024

    There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 1bpp data.

    Published: 28 Dec 2018
    8.8
    High

    CVE-2018-20549

    Last Modified: 21 Nov 2024

    There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.beta19.

    Published: 28 Dec 2018
    6.5
    Medium

    CVE-2018-20537

    Last Modified: 21 Nov 2024

    There is a NULL pointer dereference at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that will cause a denial of service.

    Published: 28 Dec 2018
    8.8
    High

    CVE-2018-20541

    Last Modified: 21 Nov 2024

    There is a heap-based buffer overflow in libxsmm_sparse_csc_reader at generator_spgemm_csc_reader.c in LIBXSMM 1.10, a different vulnerability than CVE-2018-20542 (which is in a different part of the source code and is seen at different addresses).

    Published: 28 Dec 2018
    6.5
    Medium

    CVE-2018-20544

    Last Modified: 21 Nov 2024

    There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19.

    Published: 28 Dec 2018
    8.8
    High

    CVE-2018-20545

    Last Modified: 21 Nov 2024

    There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.

    Published: 28 Dec 2018
    5.5
    Medium

    CVE-2018-20651

    Last Modified: 21 Nov 2024

    A NULL pointer dereference was discovered in elf_link_add_object_symbols in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31.1. This occurs for a crafted ET_DYN with no program headers. A specially crafted ELF file allows remote attackers to cause a denial of service, as demonstrated by ld.

    Published: 28 Dec 2018
    6.5
    Medium

    CVE-2018-20650

    Last Modified: 21 Nov 2024

    A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach.

    Published: 28 Dec 2018
    4.4
    Medium

    CVE-2019-3701

    Last Modified: 21 Nov 2024

    An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dlc field. The privileged user "root" with CAP_NET_ADMIN can create a CAN frame modification rule that makes the data length code a higher value than the available CAN frame data size. In combination with a configured checksum calculation where the result is stored relatively to the end of the data (e.g. cgw_csum_xor_rel) the tail of the skb (e.g. frag_list pointer in skb_shared_info) can be rewritten which finally can cause a system crash. Because of a missing check, the CAN drivers may write arbitrary content beyond the data registers in the CAN controller's I/O memory when processing can-gw manipulated outgoing frames.

    Published: 28 Dec 2018
    6.5
    Medium

    CVE-2018-20574

    Last Modified: 3 Nov 2025

    The SingleDocParser::HandleFlowMap function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.

    Published: 28 Dec 2018
    6.5
    Medium

    CVE-2018-20712

    Last Modified: 21 Nov 2024

    A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.

    Published: 28 Dec 2018
    6.5
    Medium

    CVE-2018-20570

    Last Modified: 21 Nov 2024

    jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.

    Published: 28 Dec 2018
    9.8
    Critical

    CVE-2018-20784

    Last Modified: 21 Nov 2024

    In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop in update_blocked_averages) or possibly have unspecified other impact by inducing a high load.

    Published: 28 Dec 2018
    6.5
    Medium

    CVE-2018-20573

    Last Modified: 3 Nov 2025

    The Scanner::EnsureTokensInQueue function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.

    Published: 28 Dec 2018
    4.8
    Medium

    CVE-2018-1000887

    Last Modified: 21 Nov 2024

    Peel shopping peel-shopping_9_1_0 version contains a Cross Site Scripting (XSS) vulnerability that can result in an authenticated user injecting java script code in the "Site Name EN" parameter. This attack appears to be exploitable if the malicious user has access to the administration account.

    Published: 27 Dec 2018
    7.5
    High

    CVE-2018-1000890

    Last Modified: 21 Nov 2024

    FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachments.php that can allow the attacker to grab the entire database of the application.

    Published: 27 Dec 2018
    6.5
    Medium

    CVE-2018-20528

    Last Modified: 21 Nov 2024

    JEECMS 9 has SSRF via the ueditor/getRemoteImage.jspx upfile parameter.

    Published: 27 Dec 2018
    8.8
    High

    CVE-2018-1000888

    Last Modified: 21 Nov 2024

    PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is_dir, etc). When extract is called without a specific prefix path, we can trigger unserialization by crafting a tar file with `phar://[path_to_malicious_phar_file]` as path. Object injection can be used to trigger destruct in the loaded PHP classes, e.g. the Archive_Tar class itself. With Archive_Tar object injection, arbitrary file deletion can occur because `@unlink($this->_temp_tarname)` is called. If another class with useful gadget is loaded, it may possible to cause remote code execution that can result in files being deleted or possibly modified. This vulnerability appears to have been fixed in 1.4.4.

    Published: 27 Dec 2018
    8.8
    High

    CVE-2018-1000889

    Last Modified: 21 Nov 2024

    Logisim Evolution version 2.14.3 and earlier contains an XML External Entity (XXE) vulnerability in Circuit file loading functionality (loadXmlFrom in src/com/cburch/logisim/file/XmlReader.java) that can result in information leak, possible RCE depending on system configuration. This attack appears to be exploitable via the victim opening a specially crafted circuit file. This vulnerability appears to have been fixed in 2.14.4.

    Published: 27 Dec 2018
    5.4
    Medium

    CVE-2018-20530

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a Profile field such as Company Address, a related issue to CVE-2018-15896.

    Published: 27 Dec 2018
    6.1
    Medium

    CVE-2018-20524

    Last Modified: 21 Nov 2024

    The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of <<a> in a message, because a danmuWrapper DIV element in chatbox-only\danmu.js is outside the scope of a Content Security Policy (CSP).

    Published: 27 Dec 2018
    6.1
    Medium

    CVE-2018-20520

    Last Modified: 21 Nov 2024

    MiniCMS V1.10 has XSS via the mc-admin/post-edit.php query string, a related issue to CVE-2018-10296 and CVE-2018-16233.

    Published: 27 Dec 2018
    8.1
    High

    CVE-2018-20519

    Last Modified: 21 Nov 2024

    An issue was discovered in 74cms v4.2.111. It allows remote authenticated users to read or modify arbitrary resumes by changing a job-search intention, as demonstrated by the index.php?c=Personal&a=ajax_save_basic pid parameter.

    Published: 27 Dec 2018
    9.8
    Critical

    CVE-2018-20508

    Last Modified: 21 Nov 2024

    CrashFix 1.0.4 has SQL Injection via the User[status] parameter. This is related to actionIndex in UserController.php, and the protected\models\User.php search() function.

    Published: 27 Dec 2018
    7
    High

    CVE-2019-3827

    Last Modified: 21 Nov 2024

    An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users belonging to the wheel group to further escalate its privileges by modifying system files without user's knowledge. Successful exploitation requires uncommon system configuration.

    Published: 27 Dec 2018
    5.5
    Medium

    CVE-2018-20673

    Last Modified: 21 Nov 2024

    The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm.

    Published: 27 Dec 2018
    6.5
    Medium

    CVE-2018-20502

    Last Modified: 21 Nov 2024

    An issue was discovered in Bento4 1.5.1-627. There is an attempt at excessive memory allocation in the AP4_DataBuffer class when called from AP4_HvccAtom::Create in Core/Ap4HvccAtom.cpp.

    Published: 26 Dec 2018
    9.8
    Critical

    CVE-2018-11741

    Last Modified: 21 Nov 2024

    NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GOTO(8) URIs.

    Published: 26 Dec 2018
    9.8
    Critical

    CVE-2018-11742

    Last Modified: 21 Nov 2024

    NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.

    Published: 26 Dec 2018
    7.5
    High

    CVE-2018-17987

    Last Modified: 21 Nov 2024

    The determineWinner function of a smart contract implementation for HashHeroes Tiles, an Ethereum game, uses a certain blockhash value in an attempt to generate a random number for the case where NUM_TILES equals the number of people who purchased a tile, which allows an attacker to control the awarding of the prize by being the last person to purchase a tile.

    Published: 26 Dec 2018
    7.8
    High

    CVE-2018-18535

    Last Modified: 21 Nov 2024

    The Asusgio low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes functionality to read and write Machine Specific Registers (MSRs). This could be leveraged to execute arbitrary ring-0 code.

    Published: 26 Dec 2018
    5.5
    Medium

    CVE-2018-18537

    Last Modified: 21 Nov 2024

    The GLCKIo low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes a path to write an arbitrary DWORD to an arbitrary address.

    Published: 26 Dec 2018