CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2018-10152

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 6 Dec 2018
    —
    Unknown

    CVE-2018-10153

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 6 Dec 2018
    —
    Unknown

    CVE-2018-10154

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 6 Dec 2018
    —
    Unknown

    CVE-2018-10155

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 6 Dec 2018
    —
    Unknown

    CVE-2018-10156

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 6 Dec 2018
    —
    Unknown

    CVE-2018-10157

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 6 Dec 2018
    —
    Unknown

    CVE-2018-10158

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 6 Dec 2018
    —
    Unknown

    CVE-2018-10161

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 6 Dec 2018
    —
    Unknown

    CVE-2018-10162

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 6 Dec 2018
    —
    Unknown

    CVE-2018-10163

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 6 Dec 2018
    4
    Medium

    CVE-2018-1505

    Last Modified: 21 Nov 2024

    IBM i2 Enterprise Insight Analysis 2.1.7 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 141413.

    Published: 6 Dec 2018
    5.9
    Medium

    CVE-2018-1525

    Last Modified: 21 Nov 2024

    IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 142117.

    Published: 6 Dec 2018
    5.4
    Medium

    CVE-2018-1871

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.0.0, 3.0.2, and 3.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 151329.

    Published: 6 Dec 2018
    4.3
    Medium

    CVE-2018-1935

    Last Modified: 21 Nov 2024

    IBM Connections 5.0, 5.5, and 6.0 could allow an authenticated user to obtain sensitive information from invalid request error messages. IBM X-Force ID: 153315.

    Published: 6 Dec 2018
    7.8
    High

    CVE-2018-9538

    Last Modified: 21 Nov 2024

    In V4L2SliceVideoDecodeAccelerator::Dequeue of v4l2_slice_video_decode_accelerator.cc, there is a possible out of bounds read of a function pointer due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.1 Android-9. Android ID: A-112181526.

    Published: 6 Dec 2018
    7.8
    High

    CVE-2018-9547

    Last Modified: 21 Nov 2024

    In unflatten of GraphicBuffer.cpp, there is a possible bad fd close due to improper input validation. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.1 Android-9. Android ID: A-114223584.

    Published: 6 Dec 2018
    7.8
    High

    CVE-2018-9550

    Last Modified: 21 Nov 2024

    In CAacDecoder_Init of aacdecoder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112660981.

    Published: 6 Dec 2018
    7.8
    High

    CVE-2018-9551

    Last Modified: 21 Nov 2024

    In CAacDecoder_Init of aacdecoder.cpp, there is a possible out-of-bound write due to a missing bounds check. This could lead to remote code execution in the media server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112891548.

    Published: 6 Dec 2018
    5.5
    Medium

    CVE-2018-9552

    Last Modified: 21 Nov 2024

    In ihevcd_sao_shift_ctb of ihevcd_sao.c there is a possible out of bounds write due to missing bounds check. This could lead to information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-113260892.

    Published: 6 Dec 2018
    7.8
    High

    CVE-2018-9553

    Last Modified: 21 Nov 2024

    In MasteringMetadata::Parse of mkvparser.cc there is a possible double free due to an insecure default value. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-116615297.

    Published: 6 Dec 2018
    5.5
    Medium

    CVE-2018-9554

    Last Modified: 21 Nov 2024

    In dumpExtractors of IMediaExtractor.cp, there is a possible disclosure of recently accessed media files due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1. Android ID: A-114770654.

    Published: 6 Dec 2018
    7.8
    High

    CVE-2018-9557

    Last Modified: 21 Nov 2024

    In really_install_package of install.cpp, there is a possible free of arbitrary memory due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2. Android ID: A-35385357.

    Published: 6 Dec 2018
    7.8
    High

    CVE-2018-9558

    Last Modified: 21 Nov 2024

    In rw_t2t_handle_tlv_detect of rw_t2t_ndef.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC kernel with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-112161557.

    Published: 6 Dec 2018
    7.8
    High

    CVE-2018-9559

    Last Modified: 21 Nov 2024

    In persist_set_key and other functions of cryptfs.cpp, there is a possible out-of-bounds write due to an uncaught error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-112731440.

    Published: 6 Dec 2018
    7.8
    High

    CVE-2018-9560

    Last Modified: 21 Nov 2024

    In HID_DevAddRecord of hidd_api.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege in the Bluetooth service with User execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-79946737.

    Published: 6 Dec 2018
    7.5
    High

    CVE-2018-9565

    Last Modified: 21 Nov 2024

    In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-16680558.

    Published: 6 Dec 2018
    5.7
    Medium

    CVE-2018-9566

    Last Modified: 21 Nov 2024

    In process_service_search_rsp of sdp_discovery.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure when connecting to a malicious Bluetooth device with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-74249842.

    Published: 6 Dec 2018
    7.8
    High

    CVE-2018-9567

    Last Modified: 21 Nov 2024

    On Pixel devices there is a bug causing verified boot to show the same certificate fingerprint despite using different signing keys. This may lead to local escalation of privilege if people are relying on those fingerprints to determine what version of the OS the device is running, with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-65543936.

    Published: 6 Dec 2018
    5.5
    Medium

    CVE-2018-9548

    Last Modified: 21 Nov 2024

    In multiple functions of ContentProvider.java, there is a possible permission bypass due to a missing URI validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-112555574.

    Published: 6 Dec 2018
    8.8
    High

    CVE-2018-9555

    Last Modified: 21 Nov 2024

    In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-112321180.

    Published: 6 Dec 2018
    7.5
    High

    CVE-2018-9562

    Last Modified: 21 Nov 2024

    In bta_ag_do_disc of bta_ag_sdp.cc, there is a possible out-of-bound read due to an incorrect parameter size. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113164621.

    Published: 6 Dec 2018
    —
    Unknown

    CVE-2018-10150

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 6 Dec 2018
    —
    Unknown

    CVE-2018-10160

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 6 Dec 2018
    —
    Unknown

    CVE-2018-10159

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 6 Dec 2018
    6.1
    Medium

    CVE-2018-1504

    Last Modified: 21 Nov 2024

    IBM i2 Enterprise Insight Analysis 2.1.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 141340.

    Published: 6 Dec 2018
    7.8
    High

    CVE-2018-9549

    Last Modified: 21 Nov 2024

    In lppTransposer of lpp_tran.cpp there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-112160868.

    Published: 6 Dec 2018
    9.8
    Critical

    CVE-2018-9556

    Last Modified: 21 Nov 2024

    In ParsePayloadHeader of payload_metadata.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113118184.

    Published: 6 Dec 2018
    7
    High

    CVE-2018-15332

    Last Modified: 21 Nov 2024

    The svpn component of the F5 BIG-IP APM client prior to version 7.1.7.2 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host in a race condition.

    Published: 6 Dec 2018
    8.8
    High

    CVE-2018-19907

    Last Modified: 21 Nov 2024

    A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/Editing a template file (.ftl filetype) that triggers a call to freemarker.template.utility.Execute in the FreeMarker library during rendering of a web page.

    Published: 6 Dec 2018
    7.2
    High

    CVE-2018-19895

    Last Modified: 21 Nov 2024

    ThinkCMF X2.2.2 has SQL Injection via the function edit_post() in NavController.class.php and is exploitable with the manager privilege via the parentid parameter in a nav action.

    Published: 6 Dec 2018
    7.2
    High

    CVE-2018-19897

    Last Modified: 21 Nov 2024

    ThinkCMF X2.2.2 has SQL Injection via the function _listorders() in AdminbaseController.class.php and is exploitable with the manager privilege via the listorders[key][1] parameter in a Link listorders action.

    Published: 6 Dec 2018
    7.2
    High

    CVE-2018-19896

    Last Modified: 21 Nov 2024

    ThinkCMF X2.2.2 has SQL Injection via the function delete() in SlideController.class.php and is exploitable with the manager privilege via the ids[] parameter in a slide action.

    Published: 6 Dec 2018
    8.8
    High

    CVE-2018-19898

    Last Modified: 21 Nov 2024

    ThinkCMF X2.2.2 has SQL Injection via the method edit_post in ArticleController.class.php and is exploitable by normal authenticated users via the post[id][1] parameter in an article edit_post action.

    Published: 6 Dec 2018
    7.2
    High

    CVE-2018-19894

    Last Modified: 21 Nov 2024

    ThinkCMF X2.2.2 has SQL Injection via the functions check() and delete() in CommentadminController.class.php and is exploitable with the manager privilege via the ids[] parameter in a commentadmin action.

    Published: 6 Dec 2018
    9.8
    Critical

    CVE-2018-19893

    Last Modified: 21 Nov 2024

    SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string.

    Published: 6 Dec 2018
    4.8
    Medium

    CVE-2018-19892

    Last Modified: 21 Nov 2024

    DomainMOD through 4.11.01 has XSS via the admin/dw/add-server.php DisplayName, HostName, or UserName field.

    Published: 6 Dec 2018
    5.5
    Medium

    CVE-2018-19881

    Last Modified: 21 Nov 2024

    In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl.

    Published: 6 Dec 2018
    5.5
    Medium

    CVE-2018-19882

    Last Modified: 21 Nov 2024

    In Artifex MuPDF 1.14.0, the svg_run_image function in svg/svg-run.c allows remote attackers to cause a denial of service (href_att NULL pointer dereference and application crash) via a crafted svg file, as demonstrated by mupdf-gl.

    Published: 6 Dec 2018
    5.5
    Medium

    CVE-2018-19887

    Last Modified: 21 Nov 2024

    An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the book 4 case.

    Published: 6 Dec 2018
    5.5
    Medium

    CVE-2018-19889

    Last Modified: 21 Nov 2024

    An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the book 6 case.

    Published: 6 Dec 2018