CVE Feed

    Dashboard / CVE

    4
    Medium

    CVE-2018-1957

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 9 could allow sensitive information to be available caused by mishandling of data by the application based on an incorrect return by the httpServletRequest#authenticate() API when an unprotected URI is accessed. IBM X-Force ID: 153629.

    Published: 10 Dec 2018
    6.1
    Medium

    CVE-2018-1671

    Last Modified: 21 Nov 2024

    IBM Curam Social Program Management 7.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-force ID: 144951.

    Published: 10 Dec 2018
    —
    Unknown

    CVE-2016-8489

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10242. Reason: This candidate is a reservation duplicate of CVE-2016-10242. Notes: All CVE users should reference CVE-2016-10242 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Dec 2018
    4.8
    Medium

    CVE-2018-20010

    Last Modified: 21 Nov 2024

    DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.

    Published: 10 Dec 2018
    4.8
    Medium

    CVE-2018-20012

    Last Modified: 21 Nov 2024

    PHPCMF 4.1.3 has XSS via the first input field to the index.php?s=member&c=register&m=index URI.

    Published: 10 Dec 2018
    7.5
    High

    CVE-2018-20018

    Last Modified: 21 Nov 2024

    S-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI.

    Published: 10 Dec 2018
    4.8
    Medium

    CVE-2018-20017

    Last Modified: 21 Nov 2024

    SEMCMS 3.5 has XSS via the first text box to the SEMCMS_Main.php URI.

    Published: 10 Dec 2018
    4.8
    Medium

    CVE-2018-20009

    Last Modified: 21 Nov 2024

    DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.

    Published: 10 Dec 2018
    8.8
    High

    CVE-2018-20015

    Last Modified: 21 Nov 2024

    YzmCMS v5.2 has admin/role/add.html CSRF.

    Published: 10 Dec 2018
    4.8
    Medium

    CVE-2018-20011

    Last Modified: 21 Nov 2024

    DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.

    Published: 10 Dec 2018
    8.8
    High

    CVE-2018-20004

    Last Modified: 21 Nov 2024

    An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a double-precision floating point number and the '<order type="real">' substring, as demonstrated by testmxml.

    Published: 10 Dec 2018
    5.5
    Medium

    CVE-2018-20005

    Last Modified: 21 Nov 2024

    An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc.

    Published: 10 Dec 2018
    6.1
    Medium

    CVE-2018-20006

    Last Modified: 21 Nov 2024

    An issue was discovered in PHPok v5.0.055. There is a Stored XSS vulnerability via the title parameter to api.php?c=post&f=save (reachable via the index.php?id=book URI).

    Published: 10 Dec 2018
    7.5
    High

    CVE-2018-20000

    Last Modified: 21 Nov 2024

    Apereo Bedework bw-webdav before 4.0.3 allows XXE attacks, as demonstrated by an invite-reply document that reads a local file, related to webdav/servlet/common/MethodBase.java and webdav/servlet/common/PostRequestPars.java.

    Published: 10 Dec 2018
    6.5
    Medium

    CVE-2018-20001

    Last Modified: 21 Nov 2024

    In Libav 12.3, there is a floating point exception in the range_decode_culshift function (called from range_decode_bits) in libavcodec/apedec.c that will lead to remote denial of service via crafted input.

    Published: 10 Dec 2018
    9.8
    Critical

    CVE-2018-19991

    Last Modified: 21 Nov 2024

    VeryNginx 0.3.3 allows remote attackers to bypass the Web Application Firewall feature because there is no error handler (for get_uri_args or get_post_args) to block the API misuse described in CVE-2018-9230.

    Published: 10 Dec 2018
    6.5
    Medium

    CVE-2018-20098

    Last Modified: 21 Nov 2024

    There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

    Published: 10 Dec 2018
    6.5
    Medium

    CVE-2018-20099

    Last Modified: 21 Nov 2024

    There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

    Published: 10 Dec 2018
    6.5
    Medium

    CVE-2018-20096

    Last Modified: 21 Nov 2024

    There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

    Published: 10 Dec 2018
    6.5
    Medium

    CVE-2018-20097

    Last Modified: 21 Nov 2024

    There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

    Published: 10 Dec 2018
    5.9
    Medium

    CVE-2018-19653

    Last Modified: 21 Nov 2024

    HashiCorp Consul 0.5.1 through 1.4.0 can use cleartext agent-to-agent RPC communication because the verify_outgoing setting is improperly documented. NOTE: the vendor has provided reconfiguration steps that do not require a software upgrade.

    Published: 9 Dec 2018
    5.3
    Medium

    CVE-2018-19982

    Last Modified: 21 Nov 2024

    An issue was discovered on KT MC01507L Z-Wave S0 devices. It occurs because HPKP is not implemented. The communication architecture is APP > Server > Controller (HUB) > Node (products which are controlled by HUB). The prerequisite is that the attacker is on the same network as the target HUB, and can use IP Changer to change destination IP addresses (of all packets whose destination IP address is Server) to a proxy-server IP address. This allows sniffing of cleartext between Server and Controller. The cleartext command data is transmitted to Controller using the proxy server's fake certificate, and it is able to control each Node of the HUB. Also, by operating HUB in Z-Wave Pairing Mode, it is possible to obtain the Z-Wave network key.

    Published: 9 Dec 2018
    6.5
    Medium

    CVE-2018-19983

    Last Modified: 21 Nov 2024

    An issue was discovered on Sigma Design Z-Wave S0 through S2 devices. An attacker first prepares a Z-Wave frame-transmission program (e.g., Z-Wave PC Controller, OpenZWave, CC1110, etc.). Next, the attacker conducts a DoS attack against the Z-Wave S0 Security version product by continuously sending divided "Nonce Get (0x98 0x81)" frames. The reason for dividing the "Nonce Get" frame is that, in security version S0, when a node receives a "Nonce Get" frame, the node produces a random new nonce and sends it to the Src node of the received "Nonce Get" frame. After the nonce value is generated and transmitted, the node transitions to wait mode. At this time, when "Nonce Get" is received again, the node discards the previous nonce value and generates a random nonce again. Therefore, because the frame is encrypted with previous nonce value, the received normal frame cannot be decrypted.

    Published: 9 Dec 2018
    8.8
    High

    CVE-2019-6977

    Last Modified: 21 Nov 2024

    gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.

    Published: 9 Dec 2018
    7.5
    High

    CVE-2018-19980

    Last Modified: 21 Nov 2024

    Anker Nebula Capsule Pro NBUI_M1_V2.1.9 devices allow attackers to cause a denial of service (reboot of the underlying Android 7.1.2 operating system) via a crafted application that sends data to WifiService.

    Published: 8 Dec 2018
    9.8
    Critical

    CVE-2018-20721

    Last Modified: 21 Nov 2024

    URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.

    Published: 8 Dec 2018
    6.4
    Medium

    CVE-2018-9519

    Last Modified: 21 Nov 2024

    In easelcomm_hw_build_scatterlist, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System privileges required. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-69808833.

    Published: 7 Dec 2018
    8.8
    High

    CVE-2018-9571

    Last Modified: 21 Nov 2024

    In impd_parse_loud_eq_instructions of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116020594.

    Published: 7 Dec 2018
    7.8
    High

    CVE-2018-9573

    Last Modified: 21 Nov 2024

    In impd_parse_filt_block of impd_drc_dynamic_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116467350.

    Published: 7 Dec 2018
    7.8
    High

    CVE-2018-9575

    Last Modified: 21 Nov 2024

    In impd_parse_dwnmix_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116619387.

    Published: 7 Dec 2018
    7.8
    High

    CVE-2018-9576

    Last Modified: 21 Nov 2024

    In impd_parse_parametric_drc_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116715245.

    Published: 7 Dec 2018
    7.8
    High

    CVE-2018-9577

    Last Modified: 21 Nov 2024

    In impd_parametric_drc_parse_gain_set_params of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116715937.

    Published: 7 Dec 2018
    9.8
    Critical

    CVE-2018-9578

    Last Modified: 21 Nov 2024

    In ixheaacd_adts_crc_start_reg of ixheaacd_adts_crc_check.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113261928.

    Published: 7 Dec 2018
    7.8
    High

    CVE-2018-9570

    Last Modified: 21 Nov 2024

    In impd_parse_drc_ext_v1 of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-115375616.

    Published: 7 Dec 2018
    8.8
    High

    CVE-2018-9572

    Last Modified: 21 Nov 2024

    In impd_drc_parse_coeff of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116224432.

    Published: 7 Dec 2018
    7.8
    High

    CVE-2018-9574

    Last Modified: 21 Nov 2024

    In impd_parse_split_drc_characteristic of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-116619337.

    Published: 7 Dec 2018
    8.8
    High

    CVE-2018-9569

    Last Modified: 21 Nov 2024

    In impd_init_drc_decode_post_config of impd_drc_gain_decoder.c there is a possible out-of-bound write due to incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113885537.

    Published: 7 Dec 2018
    7.2
    High

    CVE-2018-7065

    Last Modified: 21 Nov 2024

    An authenticated SQL injection vulnerability in Aruba ClearPass Policy Manager can lead to privilege escalation. All versions of ClearPass are affected by multiple authenticated SQL injection vulnerabilities. In each case, an authenticated administrative user of any type could exploit this vulnerability to gain access to "appadmin" credentials, leading to complete cluster compromise. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix.

    Published: 7 Dec 2018
    9
    Critical

    CVE-2018-7066

    Last Modified: 21 Nov 2024

    An unauthenticated remote command execution exists in Aruba ClearPass Policy Manager on linked devices. The ClearPass OnConnect feature permits administrators to link other network devices into ClearPass for the purpose of collecting enhanced information about connected endpoints. A defect in the API could allow a remote attacker to execute arbitrary commands on one of the linked devices. This vulnerability is only applicable if credentials for devices have been supplied to ClearPass under Configuration -> Network -> Devices -> CLI Settings. Resolution: Fixed in 6.7.5 and 6.6.10-hotfix.

    Published: 7 Dec 2018
    7.2
    High

    CVE-2018-7067

    Last Modified: 21 Nov 2024

    A Remote Authentication bypass in Aruba ClearPass Policy Manager leads to complete cluster compromise. An authentication flaw in all versions of ClearPass could allow an attacker to compromise the entire cluster through a specially crafted API call. Network access to the administrative web interface is required to exploit this vulnerability. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix.

    Published: 7 Dec 2018
    7.2
    High

    CVE-2018-7079

    Last Modified: 21 Nov 2024

    Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules, which allows any authenticated administrative user to execute those operations regardless of privilege level. This could allow low-privilege users to view, modify, or delete guest users. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix.

    Published: 7 Dec 2018
    8.1
    High

    CVE-2018-7063

    Last Modified: 21 Nov 2024

    In Aruba ClearPass, disabled API admins can still perform read/write operations. In certain circumstances, API admins in ClearPass which have been disabled may still be able to perform read/write operations on parts of the XML API. This can lead to unauthorized access to the API and complete compromise of the ClearPass instance if an attacker knows of the existence of these accounts.

    Published: 7 Dec 2018
    7.5
    High

    CVE-2018-7080

    Last Modified: 21 Nov 2024

    A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP's BLE radio and could then gain access to the AP's console port. This vulnerability is applicable only if the BLE radio has been enabled in affected access points. The BLE radio is disabled by default. Note - Aruba products are NOT affected by a similar vulnerability being tracked as CVE-2018-16986.

    Published: 7 Dec 2018
    7.1
    High

    CVE-2018-1424

    Last Modified: 21 Nov 2024

    IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 139029.

    Published: 7 Dec 2018
    5.3
    Medium

    CVE-2018-1883

    Last Modified: 21 Nov 2024

    A problem within the IBM MQ 9.0.2, 9.0.3, 9.0.4, 9.0.5, and 9.1.0.0 Console REST API Could allow attackers to execute a denial of service attack preventing users from logging into the MQ Console REST API. IBM X-Force ID: 151969.

    Published: 7 Dec 2018
    4.6
    Medium

    CVE-2018-1896

    Last Modified: 21 Nov 2024

    IBM Connections 5.0, 5.5, and 6.0 is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain. IBM X-Force ID: 152456.

    Published: 7 Dec 2018
    7.1
    High

    CVE-2018-1920

    Last Modified: 21 Nov 2024

    IBM Marketing Platform 9.1.0, 9.1.2 and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 152855.

    Published: 7 Dec 2018
    5.9
    Medium

    CVE-2018-1663

    Last Modified: 21 Nov 2024

    IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 144889.

    Published: 7 Dec 2018
    7
    High

    CVE-2018-19960

    Last Modified: 21 Nov 2024

    The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname for logging, which might allow local users to overwrite files or obtain sensitive information by using this pathname.

    Published: 7 Dec 2018
    9.1
    Critical

    CVE-2018-15362

    Last Modified: 21 Nov 2024

    XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0

    Published: 7 Dec 2018