CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-18698

    Last Modified: 21 Nov 2024

    An issue was discovered on Xiaomi Mi A1 tissot_sprout:8.1.0/OPM1.171019.026/V9.6.4.0.ODHMIFE devices. They store cleartext Wi-Fi passwords in logcat during the process of setting up the phone as a hotspot.

    Published: 24 Dec 2018
    5.9
    Medium

    CVE-2018-18960

    Last Modified: 21 Nov 2024

    An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices. They use SNMP to find certain devices on the network, but the default version is v2c, allowing an amplification attack.

    Published: 24 Dec 2018
    9.1
    Critical

    CVE-2018-19248

    Last Modified: 21 Nov 2024

    The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote attackers to upload a firmware file and reset the printer without authentication by making a request to the /DOWN/FIRMWAREUPDATE/ROM1 URI and a POST request to the /FIRMWAREUPDATE URI.

    Published: 24 Dec 2018
    7.5
    High

    CVE-2018-18959

    Last Modified: 21 Nov 2024

    An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices. On the 'Air Print Setting' web page, if the data for 'Bonjour Service Location' at /PRESENTATION/BONJOUR is more than 251 bytes when sending data for Air Print Setting, then the device no longer functions until a reboot.

    Published: 24 Dec 2018
    7.5
    High

    CVE-2018-19232

    Last Modified: 21 Nov 2024

    The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote attackers to cause a denial of service via a FIRMWAREUPDATE GET request, as demonstrated by the /DOWN/FIRMWAREUPDATE/ROM1 URI.

    Published: 24 Dec 2018
    6.3
    Medium

    CVE-2018-7796

    Last Modified: 21 Nov 2024

    A Buffer Error vulnerability exists in PowerSuite 2, all released versions (VW3A8104 & Patches), which could cause an overflow in the memcpy function, leading to corruption of data and program instability.

    Published: 24 Dec 2018
    8.8
    High

    CVE-2018-7802

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could give access to the web interface with full privileges.

    Published: 24 Dec 2018
    7.5
    High

    CVE-2018-7835

    Last Modified: 21 Nov 2024

    An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in IIoT Monitor 3.1.38 which could allow access to files available to SYSTEM user.

    Published: 24 Dec 2018
    7.5
    High

    CVE-2018-7837

    Last Modified: 21 Nov 2024

    An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow the software to resolve documents outside of the intended sphere of control, causing the software to embed incorrect documents into its output and expose restricted information.

    Published: 24 Dec 2018
    8.7
    High

    CVE-2018-7793

    Last Modified: 21 Nov 2024

    A Credential Management vulnerability exists in FoxView HMI SCADA (All Foxboro DCS, Foxboro Evo, and IA Series versions prior to Foxboro DCS Control Core Services 9.4 (CCS 9.4) and FoxView 10.5.) which could cause unauthorized disclosure, modification, or disruption in service when the password is modified without permission.

    Published: 24 Dec 2018
    8.8
    High

    CVE-2018-7832

    Last Modified: 21 Nov 2024

    An Improper Input Validation vulnerability exists in Pro-Face GP-Pro EX v4.08 and previous versions which could cause the execution arbitrary executable when GP-Pro EX is launched.

    Published: 24 Dec 2018
    9.8
    Critical

    CVE-2018-7800

    Last Modified: 21 Nov 2024

    A Hard-coded Credentials vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable an attacker to gain access to the device.

    Published: 24 Dec 2018
    8.8
    High

    CVE-2018-7801

    Last Modified: 21 Nov 2024

    A Code Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable access with maximum privileges when a remote code execution is performed.

    Published: 24 Dec 2018
    9.8
    Critical

    CVE-2018-7836

    Last Modified: 21 Nov 2024

    An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious files.

    Published: 24 Dec 2018
    8.3
    High

    CVE-2018-8919

    Last Modified: 14 Jan 2025

    Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to steal credentials via unspecified vectors.

    Published: 24 Dec 2018
    7.2
    High

    CVE-2018-8920

    Last Modified: 14 Jan 2025

    Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary content to have an unspecified impact by exporting an archive in CSV format.

    Published: 24 Dec 2018
    6.5
    Medium

    CVE-2018-8917

    Last Modified: 14 Jan 2025

    Cross-site scripting (XSS) vulnerability in info.cgi in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary web script or HTML via the host parameter.

    Published: 24 Dec 2018
    6.5
    Medium

    CVE-2018-8918

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in info.cgi in Synology Router Manager (SRM) before 1.1.7-6941 allows remote attackers to inject arbitrary web script or HTML via the host parameter.

    Published: 24 Dec 2018
    8.1
    High

    CVE-2018-15465

    Last Modified: 26 Nov 2024

    A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface. The vulnerability is due to improper validation of user privileges when using the web management interface. An attacker could exploit this vulnerability by sending specific HTTP requests via HTTPS to an affected device as an unprivileged user. An exploit could allow the attacker to retrieve files (including the running configuration) from the device or to upload and replace software images on the device.

    Published: 24 Dec 2018
    7.8
    High

    CVE-2018-19357

    Last Modified: 21 Nov 2024

    XMPlay 3.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted http:// URL in a .m3u file.

    Published: 24 Dec 2018
    8.8
    High

    CVE-2018-20425

    Last Modified: 21 Nov 2024

    libming 0.4.8 has a NULL pointer dereference in the pushdup function of the decompile.c file.

    Published: 24 Dec 2018
    8.8
    High

    CVE-2018-20426

    Last Modified: 21 Nov 2024

    libming 0.4.8 has a NULL pointer dereference in the newVar3 function of the decompile.c file, a different vulnerability than CVE-2018-7866.

    Published: 24 Dec 2018
    8.8
    High

    CVE-2018-20427

    Last Modified: 21 Nov 2024

    libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file, a different vulnerability than CVE-2018-9132.

    Published: 24 Dec 2018
    6.5
    Medium

    CVE-2018-20431

    Last Modified: 21 Nov 2024

    GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_metadata() in plugins/ole2_extractor.c.

    Published: 24 Dec 2018
    8.8
    High

    CVE-2018-20429

    Last Modified: 21 Nov 2024

    libming 0.4.8 has a NULL pointer dereference in the getName function of the decompile.c file, a different vulnerability than CVE-2018-7872 and CVE-2018-9165.

    Published: 24 Dec 2018
    8.8
    High

    CVE-2018-20428

    Last Modified: 21 Nov 2024

    libming 0.4.8 has a NULL pointer dereference in the strlenext function of the decompile.c file, a different vulnerability than CVE-2018-7874.

    Published: 24 Dec 2018
    6.5
    Medium

    CVE-2018-20430

    Last Modified: 21 Nov 2024

    GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRACTOR_common_convert_to_utf8 in common/convert.c.

    Published: 24 Dec 2018
    4.8
    Medium

    CVE-2018-20418

    Last Modified: 21 Nov 2024

    index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.

    Published: 24 Dec 2018
    8.1
    High

    CVE-2018-20423

    Last Modified: 21 Nov 2024

    Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass a "disabled registration" setting by adding a non-existing wxopenid value to the plugin.php ac=wxregister query string.

    Published: 24 Dec 2018
    5.9
    Medium

    CVE-2018-20424

    Last Modified: 21 Nov 2024

    Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbindmp request to plugin.php.

    Published: 24 Dec 2018
    8.1
    High

    CVE-2018-20422

    Last Modified: 21 Nov 2024

    Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common_member_wechatmp to gain login access to an account via a plugin.php ac=wxregister request (the attacker does not have control over which account will be accessed).

    Published: 24 Dec 2018
    8.8
    High

    CVE-2018-20419

    Last Modified: 21 Nov 2024

    DouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account.

    Published: 24 Dec 2018
    4.9
    Medium

    CVE-2018-20420

    Last Modified: 21 Nov 2024

    In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the target web site by creating a template and then using ../ directory traversal in the TemplateName parameter.

    Published: 24 Dec 2018
    7.5
    High

    CVE-2018-20421

    Last Modified: 21 Nov 2024

    Go Ethereum (aka geth) 1.8.19 allows attackers to cause a denial of service (memory consumption) by rewriting the length of a dynamic array in memory, and then writing data to a single memory location with a large index number, as demonstrated by use of "assembly { mstore }" followed by a "c[0xC800000] = 0xFF" assignment.

    Published: 24 Dec 2018
    7.5
    High

    CVE-2018-20410

    Last Modified: 21 Nov 2024

    WellinTech KingSCADA before 3.7.0.0.1 contains a stack-based buffer overflow. The vulnerability is triggered when sending a specially crafted packet to the AlarmServer (AEserver.exe) service listening on TCP port 12401.

    Published: 24 Dec 2018
    7.5
    High

    CVE-2018-20786

    Last Modified: 21 Nov 2024

    libvterm through 0+bzr726, as used in Vim and other products, mishandles certain out-of-memory conditions, leading to a denial of service (application crash), related to screen.c, state.c, and vterm.c.

    Published: 24 Dec 2018
    2.7
    Low

    CVE-2018-20405

    Last Modified: 21 Nov 2024

    BigTree 4.3 allows full path disclosure via authenticated admin/news/ input that triggers a syntax error. NOTE: This has been disputed with the following reasoning: "The issue reported requires full developer level access to the content management system where cross site scripting is not an issue -- you already have full control of the CMS including running arbitrary PHP.

    Published: 23 Dec 2018
    6.5
    Medium

    CVE-2018-20407

    Last Modified: 21 Nov 2024

    An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by mp42hls.

    Published: 23 Dec 2018
    6.5
    Medium

    CVE-2018-20408

    Last Modified: 21 Nov 2024

    An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_StdcFileByteStream::Create in System/StdC/Ap4StdCFileByteStream.cpp, as demonstrated by mp42hls.

    Published: 23 Dec 2018
    6.5
    Medium

    CVE-2018-20409

    Last Modified: 21 Nov 2024

    An issue was discovered in Bento4 1.5.1-627. There is a heap-based buffer over-read in AP4_AvccAtom::Create in Core/Ap4AvccAtom.cpp, as demonstrated by mp42hls.

    Published: 23 Dec 2018
    4.7
    Medium

    CVE-2018-20379

    Last Modified: 21 Nov 2024

    Technicolor DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-160428a devices allow XSS via a Cross Protocol Injection attack with setSSID of 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.1.1.3.10001.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20381

    Last Modified: 21 Nov 2024

    Technicolor DPC2320 dpc2300r2-v202r1244101-150420a-v6 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20382

    Last Modified: 21 Nov 2024

    Jiuzhou BCM93383WRG 139.4410mp1.3921132mp1.899.004404.004 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20385

    Last Modified: 21 Nov 2024

    CastleNet CBV38Z4EC 125.553mp1.39219mp1.899.007, CBV38Z4ECNIT 125.553mp1.39219mp1.899.005ITT, CBW383G4J 37.556mp5.008, and CBW38G4J 37.553mp1.008 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20388

    Last Modified: 21 Nov 2024

    Comtrend CM-6200un 123.447.007 and CM-6300n 123.553mp1.005 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20391

    Last Modified: 21 Nov 2024

    TEKNOTEL CBW700N 81.447.392110.729.024 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20392

    Last Modified: 21 Nov 2024

    S-A WebSTAR DPC2100 v2.0.2r1256-060303 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20394

    Last Modified: 21 Nov 2024

    Thomson DWG849 STC0.01.16, DWG850-4 ST9C.05.25, DWG855 ST80.20.26, and TWG870 STB2.01.36 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20397

    Last Modified: 21 Nov 2024

    mplus CBC383Z CBC383Z_mplus_MDr026 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20399

    Last Modified: 21 Nov 2024

    Motorola SBG901 SBG901-2.10.1.1-GA-00-581-NOSH, SBG941 SBG941-2.11.0.0-GA-07-624-NOSH, and SVG1202 SVG1202-2.1.0.0-GA-14-LTSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018