CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-6703

    Last Modified: 21 Nov 2024

    Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers to cause a Denial of Service and potentially a remote code execution via a specially crafted HTTP header sent to the logging service.

    Published: 11 Dec 2018
    6.1
    Medium

    CVE-2018-2505

    Last Modified: 21 Nov 2024

    SAP Commerce does not sufficiently validate user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability in storefronts that are based on the product. Fixed in versions (SAP Hybris Commerce, versions 6.2, 6.3, 6.4, 6.5, 6.6, 6.7).

    Published: 11 Dec 2018
    6.1
    Medium

    CVE-2018-2504

    Last Modified: 21 Nov 2024

    SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host Header Manipulation or Cross-Site Scripting (XSS) vulnerability. This is fixed in versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50.

    Published: 11 Dec 2018
    7.4
    High

    CVE-2018-2503

    Last Modified: 21 Nov 2024

    By default, the SAP NetWeaver AS Java keystore service does not sufficiently restrict the access to resources that should be protected. This has been fixed in SAP NetWeaver AS Java (ServerCore versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50).

    Published: 11 Dec 2018
    6.1
    Medium

    CVE-2018-2502

    Last Modified: 21 Nov 2024

    TRACE method is enabled in SAP Business One Service Layer . Attacker can use XST (Cross Site Tracing) attack if frontend applications that are using Service Layer has a XSS vulnerability. This has been fixed in SAP Business One Service Layer (B1_ON_HANA, versions 9.2, 9.3).

    Published: 11 Dec 2018
    4.7
    Medium

    CVE-2018-2500

    Last Modified: 21 Nov 2024

    Under certain conditions SAP Mobile Secure Android client (before version 6.60.19942.0 SP28 1711) allows an attacker to access information which would otherwise be restricted.

    Published: 11 Dec 2018
    2.7
    Low

    CVE-2018-2497

    Last Modified: 21 Nov 2024

    The security audit log of SAP HANA, versions 1.0 and 2.0, does not log SELECT events if these events are part of a statement with the syntax CREATE TABLE <table_name> AS SELECT.

    Published: 11 Dec 2018
    8
    High

    CVE-2018-2494

    Last Modified: 21 Nov 2024

    Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP Basis AS ABAP of SAP NetWeaver 700 to 750, from 750 onwards delivered as ABAP Platform.

    Published: 11 Dec 2018
    7.1
    High

    CVE-2018-2492

    Last Modified: 21 Nov 2024

    SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted source. This is fixed in versions 7.2, 7.30, 7.31, 7.40 and 7.50.

    Published: 11 Dec 2018
    5.4
    Medium

    CVE-2018-2486

    Last Modified: 21 Nov 2024

    SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

    Published: 11 Dec 2018
    7.5
    High

    CVE-2018-20064

    Last Modified: 21 Nov 2024

    doorGets 7.0 allows remote attackers to write to arbitrary files via directory traversal, as demonstrated by a dg-user/?controller=theme&action=edit&name=doorgets&file=../../1.txt%00 URI with content in the theme_content_nofi parameter.

    Published: 11 Dec 2018
    6.8
    Medium

    CVE-2018-18810

    Last Modified: 21 Nov 2024

    The Administrator Service component of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, and TIBCO Managed File Transfer Internet Server contains vulnerabilities where an authenticated user with specific privileges can gain access to credentials to other systems. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center: versions up to and including 7.3.2; 8.0.0; 8.0.1; 8.0.2; 8.1.0, and TIBCO Managed File Transfer Internet Server: versions up to and including 7.3.2; 8.0.0; 8.0.1; 8.0.2; 8.1.0.

    Published: 11 Dec 2018
    9.8
    Critical

    CVE-2018-20062

    Last Modified: 7 Nov 2025

    An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\think\Request/input&filter=phpinfo&data=1 query string.

    Published: 11 Dec 2018
    8.8
    High

    CVE-2018-19969

    Last Modified: 21 Nov 2024

    phpMyAdmin 4.7.x and 4.8.x versions prior to 4.8.4 are affected by a series of CSRF flaws. By deceiving a user into clicking on a crafted URL, it is possible to perform harmful SQL operations such as renaming databases, creating new tables/routines, deleting designer pages, adding/deleting users, updating user passwords, killing SQL processes, etc.

    Published: 11 Dec 2018
    6.1
    Medium

    CVE-2018-19970

    Last Modified: 21 Nov 2024

    In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.

    Published: 11 Dec 2018
    7.5
    High

    CVE-2018-20061

    Last Modified: 21 Nov 2024

    A SQL injection issue was discovered in ERPNext 10.x and 11.x through 11.0.3-beta.29. This attack is only available to a logged-in user; however, many ERPNext sites allow account creation via the web. No special privileges are needed to conduct the attack. By calling a JavaScript function that calls a server-side Python function with carefully chosen arguments, a SQL attack can be carried out which allows SQL queries to be constructed to return any columns from any tables in the database. This is related to /api/resource/Item?fields= URIs, frappe.get_list, and frappe.call.

    Published: 11 Dec 2018
    6.5
    Medium

    CVE-2018-19968

    Last Modified: 21 Nov 2024

    An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system.

    Published: 11 Dec 2018
    6.8
    Medium

    CVE-2018-1654

    Last Modified: 21 Nov 2024

    IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 144747.

    Published: 11 Dec 2018
    5.4
    Medium

    CVE-2018-1900

    Last Modified: 21 Nov 2024

    IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152529.

    Published: 11 Dec 2018
    8.1
    High

    CVE-2018-1904

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow remote attackers to execute arbitrary Java code through an administrative client class with a serialized object from untrusted sources. IBM X-Force ID: 152533.

    Published: 11 Dec 2018
    6.2
    Medium

    CVE-2018-1652

    Last Modified: 21 Nov 2024

    IBM DataPower Gateway 7.1.0.0 through 7.1.0.19, 7.2.0.0 through 7.2.0.16, 7.5.0.0 through 7.5.0.10, 7.5.1.0 through 7.5.1.9, 7.5.2.0 through 7.5.2.9, and 7.6.0.0 through 7.6.0.2 and IBM MQ Appliance 8.0.0.0 through 8.0.0.8 and 9.0.1 through 9.0.5 could allow a local user to cause a denial of service through unknown vectors. IBM X-Force ID: 144724.

    Published: 11 Dec 2018
    9.8
    Critical

    CVE-2018-20059

    Last Modified: 21 Nov 2024

    jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.

    Published: 11 Dec 2018
    7.8
    High

    CVE-2023-0030

    Last Modified: 5 Mar 2025

    A use-after-free flaw was found in the Linux kernel’s nouveau driver in how a user triggers a memory overflow that causes the nvkm_vma_tail function to fail. This flaw allows a local user to crash or potentially escalate their privileges on the system.

    Published: 11 Dec 2018
    7.5
    High

    CVE-2018-20058

    Last Modified: 21 Nov 2024

    In Evernote before 7.6 on macOS, there is a local file path traversal issue in attachment previewing, aka MACOSNOTE-28634.

    Published: 11 Dec 2018
    8.8
    High

    CVE-2018-20057

    Last Modified: 21 Nov 2024

    An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. goform/formSysCmd allows remote authenticated users to execute arbitrary OS commands via the sysCmd POST parameter.

    Published: 11 Dec 2018
    9.8
    Critical

    CVE-2018-20056

    Last Modified: 21 Nov 2024

    An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. There is a stack-based buffer overflow allowing remote attackers to execute arbitrary code without authentication via the goform/formLanguageChange currTime parameter.

    Published: 11 Dec 2018
    6.5
    Medium

    CVE-2018-18494

    Last Modified: 25 Nov 2025

    A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

    Published: 11 Dec 2018
    9.8
    Critical

    CVE-2018-18493

    Last Modified: 25 Nov 2025

    A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

    Published: 11 Dec 2018
    9.8
    Critical

    CVE-2018-18492

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

    Published: 11 Dec 2018
    8.8
    High

    CVE-2018-12406

    Last Modified: 21 Nov 2024

    Mozilla developers and community members reported memory safety bugs present in Firefox 63. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 64.

    Published: 11 Dec 2018
    9.8
    Critical

    CVE-2018-12407

    Last Modified: 21 Nov 2024

    A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBuffer11 module. This results in a potentially exploitable crash. This vulnerability affects Firefox < 64.

    Published: 11 Dec 2018
    7.5
    High

    CVE-2018-20125

    Last Modified: 21 Nov 2024

    hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in create_cq_ring or create_qp_rings.

    Published: 11 Dec 2018
    7.5
    High

    CVE-2018-20216

    Last Modified: 21 Nov 2024

    QEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_ring.c because return values are not checked (and -1 is mishandled).

    Published: 11 Dec 2018
    9.8
    Critical

    CVE-2018-18498

    Last Modified: 21 Nov 2024

    A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

    Published: 11 Dec 2018
    7.5
    High

    CVE-2018-20191

    Last Modified: 21 Nov 2024

    hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which allows attackers to cause a denial of service (NULL pointer dereference).

    Published: 11 Dec 2018
    6.5
    Medium

    CVE-2018-18495

    Last Modified: 21 Nov 2024

    WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.

    Published: 11 Dec 2018
    6.5
    Medium

    CVE-2018-18497

    Last Modified: 21 Nov 2024

    Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.

    Published: 11 Dec 2018
    5.5
    Medium

    CVE-2018-20124

    Last Modified: 21 Nov 2024

    hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge value.

    Published: 11 Dec 2018
    5.5
    Medium

    CVE-2018-20126

    Last Modified: 21 Nov 2024

    hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.

    Published: 11 Dec 2018
    —
    Unknown

    CVE-2018-15757

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 10 Dec 2018
    7.5
    High

    CVE-2018-20051

    Last Modified: 21 Nov 2024

    Mishandling of '>' on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via certain ONVIF methods such as CreateUsers, SetImagingSettings, GetStreamUri, and so on.

    Published: 10 Dec 2018
    7.5
    High

    CVE-2018-20050

    Last Modified: 21 Nov 2024

    Mishandling of an empty string on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via the ONVIF GetStreamUri method and GetVideoEncoderConfigurationOptions method.

    Published: 10 Dec 2018
    5.5
    Medium

    CVE-2018-20029

    Last Modified: 25 Feb 2026

    The nxfs.sys driver in the DokanFS library 0.6.0 in NoMachine before 6.4.6 on Windows 10 allows local users to cause a denial of service (BSOD) because uninitialized memory can be read.

    Published: 10 Dec 2018
    8.5
    High

    CVE-2018-1279

    Last Modified: 21 Nov 2024

    Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the network topology can guess this cookie and, if they have access to the right ports on any server in the MQ cluster can use this cookie to gain full control over the entire cluster.

    Published: 10 Dec 2018
    8.1
    High

    CVE-2018-15800

    Last Modified: 21 Nov 2024

    Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing attack to brute-force the signing key, allowing them complete read and write access to the the Bits Service storage.

    Published: 10 Dec 2018
    9.1
    Critical

    CVE-2018-15805

    Last Modified: 21 Nov 2024

    Accusoft PrizmDoc HTML5 Document Viewer before 13.5 contains an XML external entity (XXE) vulnerability, allowing an attacker to read arbitrary files or cause a denial of service (resource consumption).

    Published: 10 Dec 2018
    5.4
    Medium

    CVE-2018-16635

    Last Modified: 21 Nov 2024

    Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php.

    Published: 10 Dec 2018
    6.5
    Medium

    CVE-2018-16636

    Last Modified: 21 Nov 2024

    Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter.

    Published: 10 Dec 2018
    4.7
    Medium

    CVE-2018-3988

    Last Modified: 21 Nov 2024

    Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses the photo feature available in the "attach file" menu, then Signal will leave the picture in its own cache directory, which is available to any application on the system.

    Published: 10 Dec 2018
    9.8
    Critical

    CVE-2016-10502

    Last Modified: 21 Nov 2024

    While generating trusted application id, An integer overflow can occur giving the trusted application an invalid identity in Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835 and SDA660.

    Published: 10 Dec 2018