CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-11961

    Last Modified: 21 Nov 2024

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possibility of accessing out of bound vector index When updating some GNSS configurations.

    Published: 20 Dec 2018
    7.8
    High

    CVE-2018-11985

    Last Modified: 21 Nov 2024

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, When allocating heap using user supplied size, Possible heap overflow vulnerability due to integer overflow in roundup to native pointer.

    Published: 20 Dec 2018
    7.8
    High

    CVE-2017-9704

    Last Modified: 21 Nov 2024

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, There is no synchronization between msm_vb2 buffer operations which can lead to use after free.

    Published: 20 Dec 2018
    4.3
    Medium

    CVE-2018-1000815

    Last Modified: 21 Nov 2024

    Brave Software Inc. Brave version version 0.22.810 to 0.24.0 contains a Other/Unknown vulnerability in function ContentSettingsObserver::AllowScript() in content_settings_observer.cc that can result in Websites can run inline JavaScript even if script is blocked, making attackers easier to track users. This attack appear to be exploitable via the victim must visit a specially crafted website. This vulnerability appears to have been fixed in 0.25.2.

    Published: 20 Dec 2018
    7.5
    High

    CVE-2018-1000817

    Last Modified: 21 Nov 2024

    Asset Pipeline Grails Plugin Asset-pipeline plugin version Prior to 2.14.1.1, 2.15.1 and 3.0.6 contains a Incorrect Access Control vulnerability in Applications deployed in Jetty that can result in Download .class files and any arbitrary file. This attack appear to be exploitable via Specially crafted GET request containing directory traversal from assets-pipeline context. This vulnerability appears to have been fixed in 2.14.1.1 (for Grails 2.x), 2.15.1 (for Grails 3 and Java 7) and 3.0.6 (for Grails 3 and Java 8).

    Published: 20 Dec 2018
    10
    Critical

    CVE-2018-1000821

    Last Modified: 21 Nov 2024

    MicroMathematics version before commit 5c05ac8 contains a XML External Entity (XXE) vulnerability in SMathStudio files that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Specially crafted SMathStudio files. This vulnerability appears to have been fixed in after commit 5c05ac8.

    Published: 20 Dec 2018
    10
    Critical

    CVE-2018-1000822

    Last Modified: 21 Nov 2024

    codelibs fess version before commit faa265b contains a XML External Entity (XXE) vulnerability in GSA XML file parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via specially crafted GSA XML files. This vulnerability appears to have been fixed in after commit faa265b.

    Published: 20 Dec 2018
    5.4
    Medium

    CVE-2018-1000847

    Last Modified: 21 Nov 2024

    FreshDNS version 1.0.3 and prior contains a Cross Site Scripting (XSS) vulnerability in Account data form; Zone editor that can result in Execution of attacker's JavaScript code in victim's session. This attack appear to be exploitable via The attacker stores a specially crafted string as their Full Name in their account details. The victim (e.g. the administrator of the FreshDNS instance) opens the User List in the admin interface.. This vulnerability appears to have been fixed in 1.0.5 and later.

    Published: 20 Dec 2018
    8.8
    High

    CVE-2018-1000849

    Last Modified: 21 Nov 2024

    Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Other/Unknown vulnerability in apk-tools (Alpine Linux' package manager) that can result in Remote Code Execution. This attack appear to be exploitable via A specially crafted APK-file can cause apk to write arbitrary data to an attacker-specified file, due to bugs in handling long link target name and the way a regular file is extracted.. This vulnerability appears to have been fixed in 2.6.10, 2.7.6, and 2.10.1.

    Published: 20 Dec 2018
    7.8
    High

    CVE-2018-11960

    Last Modified: 21 Nov 2024

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, A use after free condition can occur in the SPS driver which can lead to error in kernel.

    Published: 20 Dec 2018
    7.8
    High

    CVE-2018-11986

    Last Modified: 21 Nov 2024

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possible buffer overflow in TX and RX FIFOs of microcontroller in camera subsystem used to exchange commands and messages between Micro FW and CPP driver.

    Published: 20 Dec 2018
    6.5
    Medium

    CVE-2018-1661

    Last Modified: 21 Nov 2024

    IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 144887.

    Published: 20 Dec 2018
    8.4
    High

    CVE-2018-1771

    Last Modified: 21 Nov 2024

    IBM Domino 9.0 and 9.0.1 could allow an attacker to execute commands on the system by triggering a buffer overflow in the parsing of command line arguments passed to nsd.exe. IBM X-force ID: 148687.

    Published: 20 Dec 2018
    7.7
    High

    CVE-2018-1778

    Last Modified: 21 Nov 2024

    IBM LoopBack (IBM API Connect 2018.1, 2018.4.1, 5.0.8.0, and 5.0.8.4) could allow an attacker to bypass authentication if the AccessToken Model is exposed over a REST API, it is then possible for anyone to create an AccessToken for any User provided they know the userId and can hence get access to the other user’s data / access to their privileges (if the user happens to be an Admin for example). IBM X-Force ID: 148801.

    Published: 20 Dec 2018
    7.1
    High

    CVE-2018-1784

    Last Modified: 21 Nov 2024

    IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IBM X-Force ID: 148807.

    Published: 20 Dec 2018
    7.2
    High

    CVE-2018-1973

    Last Modified: 21 Nov 2024

    IBM API Connect 5.0.0.0 through 5.0.8.4 allows a user with limited 'API Administrator level access to give themselves full 'Administrator' level access through the members functionality. IBM X-Force ID: 153914.

    Published: 20 Dec 2018
    8.8
    High

    CVE-2018-5199

    Last Modified: 21 Nov 2024

    In Veraport G3 ALL on MacOS, due to insufficient domain validation, It is possible to overwrite installation file to malicious file. A remote unauthenticated attacker may use this vulnerability to execute arbitrary file.

    Published: 20 Dec 2018
    7.8
    High

    CVE-2018-5200

    Last Modified: 21 Nov 2024

    KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV format file. The problem is that more frame data is copied to heap memory than the size specified in the frame header. This results in a memory corruption and remote code execution.

    Published: 20 Dec 2018
    5.1
    Medium

    CVE-2018-7365

    Last Modified: 21 Nov 2024

    All versions up to ZXCLOUD iRAI V5.01.05 of the ZTE uSmartView product are impacted by untrusted search path vulnerability, which may allow an unauthorized user to perform unauthorized operations.

    Published: 20 Dec 2018
    5.1
    Medium

    CVE-2018-1677

    Last Modified: 21 Nov 2024

    IBM DataPower Gateways 7.1, 7.2, 7.5, 7.5.1, 7.5.2, 7.6, and 7.7 and IBM MQ Appliance are vulnerable to a denial of service, caused by the improper handling of full file system. A local attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 145171.

    Published: 20 Dec 2018
    8.1
    High

    CVE-2018-5198

    Last Modified: 21 Nov 2024

    In Veraport G3 ALL on MacOS, a race condition when calling the Veraport API allow remote attacker to cause arbitrary file download and execution. This results in remote code execution.

    Published: 20 Dec 2018
    6.3
    Medium

    CVE-2018-6669

    Last Modified: 21 Nov 2024

    A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows a remote or local user to execute blacklisted files through an ASP.NET form.

    Published: 20 Dec 2018
    7.5
    High

    CVE-2018-8653

    Last Modified: 29 Oct 2025

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8643.

    Published: 20 Dec 2018
    6.5
    Medium

    CVE-2018-20301

    Last Modified: 21 Nov 2024

    An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, "registration" endpoints (e.g., creating, editing, updating) allow users to update any coherence_fields data. For example, users can automatically confirm their accounts by sending the confirmed_at parameter with their registration request.

    Published: 20 Dec 2018
    5.4
    Medium

    CVE-2018-20306

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the web administration user interface of Pulse Secure Virtual Traffic Manager may allow a remote authenticated attacker to inject web script or HTML via a crafted website and steal sensitive data and credentials. Affected releases are Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1.

    Published: 20 Dec 2018
    4.3
    Medium

    CVE-2018-20307

    Last Modified: 21 Nov 2024

    Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain sensitive historical activity information by leveraging incorrect permission validation.

    Published: 20 Dec 2018
    9.8
    Critical

    CVE-2018-16879

    Last Modified: 21 Nov 2024

    Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.

    Published: 20 Dec 2018
    7.5
    High

    CVE-2018-20030

    Last Modified: 21 Nov 2024

    An error when processing the EXIF_IFD_INTEROPERABILITY and EXIF_IFD_EXIF tags within libexif version 0.6.21 can be exploited to exhaust available CPU resources.

    Published: 20 Dec 2018
    6.1
    Medium

    CVE-2018-20302

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in Steve Pallen Xain before 0.6.2 via the order parameter.

    Published: 20 Dec 2018
    9.8
    Critical

    CVE-2018-20433

    Last Modified: 21 Nov 2024

    c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.

    Published: 20 Dec 2018
    9.8
    Critical

    CVE-2018-20300

    Last Modified: 21 Nov 2024

    Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.

    Published: 20 Dec 2018
    6.5
    Medium

    CVE-2018-20304

    Last Modified: 21 Nov 2024

    wbook_addworksheet in workbook.c in libexcel.a in libexcel 0.01 allows attackers to cause a denial of service (SEGV) via a long second argument. NOTE: this is not a Microsoft product.

    Published: 20 Dec 2018
    9.8
    Critical

    CVE-2018-20305

    Last Modified: 21 Nov 2024

    D-Link DIR-816 A2 1.10 B05 devices allow arbitrary remote code execution without authentication via the newpass parameter. In the /goform/form2userconfig.cgi handler function, a long password may lead to a stack-based buffer overflow and overwrite a return address.

    Published: 20 Dec 2018
    7.5
    High

    CVE-2018-20303

    Last Modified: 21 Nov 2024

    In pkg/tool/path.go in Gogs before 0.11.82.1218, a directory traversal in the file-upload functionality can allow an attacker to create a file under data/sessions on the server, a similar issue to CVE-2018-18925.

    Published: 20 Dec 2018
    6.5
    Medium

    CVE-2018-20481

    Last Modified: 21 Nov 2024

    XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document, when XRefEntry::setFlag in XRef.h is called from Parser::makeStream in Parser.cc.

    Published: 20 Dec 2018
    9.8
    Critical

    CVE-2018-20299

    Last Modified: 21 Nov 2024

    An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4. A malicious client could potentially succeed in the unauthorized execution of code on the device via the network interface, because there is a buffer overflow in the RCP+ parser of the web server.

    Published: 19 Dec 2018
    7.6
    High

    CVE-2018-15798

    Last Modified: 21 Nov 2024

    Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an untrusted website and gain access to that user's access token in Concourse.

    Published: 19 Dec 2018
    7.4
    High

    CVE-2018-15801

    Last Modified: 21 Nov 2024

    Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that case, a malicious user could fashion signed JWTs with the malicious issuer URL that may be granted for the honest issuer.

    Published: 19 Dec 2018
    6.5
    Medium

    CVE-2018-11799

    Last Modified: 21 Nov 2024

    Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 5.0.0 to impersonate other users. The malicious user can construct an XML that results workflows running in other user's name.

    Published: 19 Dec 2018
    4.8
    Medium

    CVE-2018-19506

    Last Modified: 21 Nov 2024

    Zurmo 3.2.4 has XSS via an admin's use of the name parameter in the reports section, aka the app/index.php/reports/default/details?id=1 URI.

    Published: 19 Dec 2018
    4.8
    Medium

    CVE-2018-19507

    Last Modified: 21 Nov 2024

    CMSimple 4.7.5 has XSS via an admin's use of a ?file=config&action=array URI.

    Published: 19 Dec 2018
    4.8
    Medium

    CVE-2018-19508

    Last Modified: 21 Nov 2024

    CMSimple 4.7.5 has XSS via an admin's upload of an SVG file at a ?userfiles&subdir=userfiles/images/flags/ URI.

    Published: 19 Dec 2018
    4.8
    Medium

    CVE-2018-19598

    Last Modified: 21 Nov 2024

    Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request.

    Published: 19 Dec 2018
    4.8
    Medium

    CVE-2018-19596

    Last Modified: 21 Nov 2024

    Zurmo 3.2.4 allows HTML Injection via an admin's use of HTML in the report section, a related issue to CVE-2018-19506.

    Published: 19 Dec 2018
    4.8
    Medium

    CVE-2018-19597

    Last Modified: 21 Nov 2024

    CMS Made Simple 2.2.8 allows XSS via an uploaded SVG document, a related issue to CVE-2017-16798.

    Published: 19 Dec 2018
    7.3
    High

    CVE-2018-18999

    Last Modified: 21 Nov 2024

    WebAccess/SCADA, WebAccess/SCADA Version 8.3.2 installed on Windows 2008 R2 SP1. Lack of proper validation of user supplied input may allow an attacker to cause the overflow of a buffer on the stack.

    Published: 19 Dec 2018
    6.5
    Medium

    CVE-2018-20298

    Last Modified: 21 Nov 2024

    S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary files and obtain NTLMv2 hash values by tricking a user into connecting to a malicious server via the S3 protocol.

    Published: 19 Dec 2018
    6.5
    Medium

    CVE-2018-17192

    Last Modified: 21 Nov 2024

    The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. Mitigation: The fix to consistently apply the security headers was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

    Published: 19 Dec 2018
    7.5
    High

    CVE-2018-17195

    Last Modified: 21 Nov 2024

    The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack. The required attack vector is complex, requiring a scenario with client certificate authentication, same subnet access, and injecting malicious code into an unprotected (plaintext HTTP) website which the targeted user later visits, but the possible damage warranted a Severe severity level. Mitigation: The fix to apply Cross-Origin Resource Sharing (CORS) policy request filtering was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

    Published: 19 Dec 2018
    7.5
    High

    CVE-2018-17194

    Last Modified: 21 Nov 2024

    When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE request, the body was ignored, but if the initial request had a Content-Length value other than 0, the receiving nodes would wait for the body and eventually timeout. Mitigation: The fix to check DELETE requests and overwrite non-zero Content-Length header values was applied on the Apache NiFi 1.8.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

    Published: 19 Dec 2018