CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2018-19335

    Last Modified: 21 Nov 2024

    Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with a crafted groupby value) can be used to obtain sensitive information about the content of bug reports.

    Published: 20 Nov 2018
    5.3
    Medium

    CVE-2018-19334

    Last Modified: 21 Nov 2024

    Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with an unsupported axis) can be used to obtain sensitive information about the content of bug reports.

    Published: 20 Nov 2018
    8.8
    High

    CVE-2018-1000878

    Last Modified: 21 Nov 2024

    libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.

    Published: 20 Nov 2018
    6.5
    Medium

    CVE-2018-1000880

    Last Modified: 21 Nov 2024

    libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: Improper Input Validation vulnerability in WARC parser - libarchive/archive_read_support_format_warc.c, _warc_read() that can result in DoS - quasi-infinite run time and disk usage from tiny file. This attack appear to be exploitable via the victim must open a specially crafted WARC file.

    Published: 20 Nov 2018
    6.5
    Medium

    CVE-2018-14629

    Last Modified: 21 Nov 2024

    A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denial of service.

    Published: 20 Nov 2018
    9.8
    Critical

    CVE-2018-15981

    Last Modified: 21 Nov 2024

    Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 20 Nov 2018
    5.5
    Medium

    CVE-2018-19406

    Last Modified: 21 Nov 2024

    kvm_pv_send_ipi in arch/x86/kvm/lapic.c in the Linux kernel through 4.19.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) via crafted system calls that reach a situation where the apic map is uninitialized.

    Published: 20 Nov 2018
    7.8
    High

    CVE-2018-19476

    Last Modified: 21 Nov 2024

    psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion.

    Published: 20 Nov 2018
    7.8
    High

    CVE-2018-19477

    Last Modified: 21 Nov 2024

    psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.

    Published: 20 Nov 2018
    5.5
    Medium

    CVE-2018-19478

    Last Modified: 21 Nov 2024

    In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when parsing the file.

    Published: 20 Nov 2018
    7.8
    High

    CVE-2018-19963

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because x86 IOREQ server resource accounting (for external emulators) was mishandled.

    Published: 20 Nov 2018
    6.5
    Medium

    CVE-2018-19964

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen 4.11.x allowing x86 guest OS users to cause a denial of service (host OS hang) because the p2m lock remains unavailable indefinitely in certain error conditions.

    Published: 20 Nov 2018
    6.5
    Medium

    CVE-2018-16851

    Last Modified: 21 Nov 2024

    Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of service. During the processing of an LDAP search before Samba's AD DC returns the LDAP entries to the client, the entries are cached in a single memory object with a maximum size of 256MB. When this size is reached, the Samba process providing the LDAP service will follow the NULL pointer, terminating the process. There is no further vulnerability associated with this issue, merely a denial of service.

    Published: 20 Nov 2018
    7.4
    High

    CVE-2018-16857

    Last Modified: 21 Nov 2024

    Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict brute forcing of passwords) in a window of more than 3 minutes may not watch for bad passwords at all. The primary risk from this issue is with regards to domains that have been upgraded from Samba 4.8 and earlier. In these cases the manual testing done to confirm an organisation's password policies apply as expected may not have been re-done after the upgrade.

    Published: 20 Nov 2018
    7.8
    High

    CVE-2018-19134

    Last Modified: 21 Nov 2024

    In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a pattern dictionary was a structure type.

    Published: 20 Nov 2018
    7.5
    High

    CVE-2018-19396

    Last Modified: 21 Nov 2024

    ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call for the com, dotnet, or variant class.

    Published: 20 Nov 2018
    8.8
    High

    CVE-2018-1000877

    Last Modified: 21 Nov 2024

    libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes(), realloc(rar->lzss.window, new_size) with new_size = 0 that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.

    Published: 20 Nov 2018
    6.5
    Medium

    CVE-2018-1000879

    Last Modified: 21 Nov 2024

    libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer Dereference vulnerability in ACL parser - libarchive/archive_acl.c, archive_acl_from_text_l() that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted archive file.

    Published: 20 Nov 2018
    6.5
    Medium

    CVE-2018-16852

    Last Modified: 21 Nov 2024

    Samba from version 4.9.0 and before version 4.9.3 is vulnerable to a NULL pointer de-reference. During the processing of an DNS zone in the DNS management DCE/RPC server, the internal DNS server or the Samba DLZ plugin for BIND9, if the DSPROPERTY_ZONE_MASTER_SERVERS property or DSPROPERTY_ZONE_SCAVENGING_SERVERS property is set, the server will follow a NULL pointer and terminate. There is no further vulnerability associated with this issue, merely a denial of service.

    Published: 20 Nov 2018
    5.5
    Medium

    CVE-2018-19407

    Last Modified: 21 Nov 2024

    The vcpu_scan_ioapic function in arch/x86/kvm/x86.c in the Linux kernel through 4.19.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) via crafted system calls that reach a situation where ioapic is uninitialized.

    Published: 20 Nov 2018
    7.8
    High

    CVE-2018-19475

    Last Modified: 21 Nov 2024

    psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.

    Published: 20 Nov 2018
    8.8
    High

    CVE-2018-19966

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.

    Published: 20 Nov 2018
    8.8
    High

    CVE-2018-17906

    Last Modified: 21 Nov 2024

    Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within third party software may allow an attacker to compromise a component of the system.

    Published: 19 Nov 2018
    9.8
    Critical

    CVE-2018-9209

    Last Modified: 21 Nov 2024

    Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2

    Published: 19 Nov 2018
    9.8
    Critical

    CVE-2018-9207

    Last Modified: 21 Nov 2024

    Arbitrary file upload in jQuery Upload File <= 4.0.2

    Published: 19 Nov 2018
    9.1
    Critical

    CVE-2018-15759

    Last Modified: 21 Nov 2024

    Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials. A remote unauthenticated malicious user may make many requests to the service broker with different credentials, allowing them to infer valid credentials and gain access to perform broker operations.

    Published: 19 Nov 2018
    9.9
    Critical

    CVE-2018-15761

    Last Modified: 21 Nov 2024

    Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a consent page to gain a token with arbitrary scopes that escalates their privileges.

    Published: 19 Nov 2018
    6.2
    Medium

    CVE-2018-1841

    Last Modified: 21 Nov 2024

    IBM Cloud Private 2.1.0 could allow a local user to obtain the CA Private Key due to it being world readable in boot/master node. IBM X-Force ID: 150901.

    Published: 19 Nov 2018
    9.8
    Critical

    CVE-2018-17190

    Last Modified: 21 Nov 2024

    In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The master itself does not, by design, execute user code. A specially-crafted request to the master can, however, cause the master to execute code too. Note that this does not affect standalone clusters with authentication enabled. While the master host typically has less outbound access to other resources than a worker, the execution of code on the master is nevertheless unexpected.

    Published: 19 Nov 2018
    7.8
    High

    CVE-2018-18519

    Last Modified: 21 Nov 2024

    BestXsoftware Best Free Keylogger before 6.0.0 allows local users to gain privileges via a Trojan horse "%PROGRAMFILES%\BFK 5.2.9\syscrb.exe" file because of insecure permissions for the BUILTIN\Users group.

    Published: 19 Nov 2018
    7.8
    High

    CVE-2018-19490

    Last Modified: 21 Nov 2024

    An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.

    Published: 19 Nov 2018
    8.8
    High

    CVE-2018-17479

    Last Modified: 21 Nov 2024

    Incorrect object lifetime calculations in GPU code in Google Chrome prior to 70.0.3538.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 19 Nov 2018
    9.8
    Critical

    CVE-2018-19355

    Last Modified: 21 Nov 2024

    modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equal to product (for upload destinations under modules/productfiles), order (for upload destinations under modules/files), or cart (for upload destinations under modules/cartfiles).

    Published: 19 Nov 2018
    5.3
    Medium

    CVE-2018-19387

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 19 Nov 2018
    7.8
    High

    CVE-2018-19491

    Last Modified: 21 Nov 2024

    An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot postscript terminal is used as a backend.

    Published: 19 Nov 2018
    7.8
    High

    CVE-2018-19492

    Last Modified: 21 Nov 2024

    An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo terminal is used as a backend.

    Published: 19 Nov 2018
    7.5
    High

    CVE-2018-19518

    Last Modified: 21 Nov 2024

    University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_rimap function in c-client/imap4r1.c and the tcp_aopen function in osdep/unix/tcp_unix.c) without preventing argument injection, which might allow remote attackers to execute arbitrary OS commands if the IMAP server name is untrusted input (e.g., entered by a user of a web application) and if rsh has been replaced by a program with different argument semantics. For example, if rsh is a link to ssh (as seen on Debian and Ubuntu systems), then the attack can use an IMAP server name containing a "-oProxyCommand" argument.

    Published: 19 Nov 2018
    6.8
    Medium

    CVE-2008-7320

    Last Modified: 21 Nov 2024

    GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow dialog at an unattended workstation, if the keyring is unlocked. NOTE: this is disputed by a software maintainer because the behavior represents a design decision

    Published: 18 Nov 2018
    6.1
    Medium

    CVE-2018-19351

    Last Modified: 21 Nov 2024

    Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In notebook/nbconvert/handlers.py, NbconvertFileHandler and NbconvertPostHandler do not set a Content Security Policy to prevent this.

    Published: 18 Nov 2018
    6.1
    Medium

    CVE-2018-19352

    Last Modified: 21 Nov 2024

    Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.

    Published: 18 Nov 2018
    6.5
    Medium

    CVE-2018-19353

    Last Modified: 21 Nov 2024

    The ansilove_ansi function in loaders/ansi.c in libansilove 1.0.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.

    Published: 18 Nov 2018
    5.5
    Medium

    CVE-2018-20535

    Last Modified: 21 Nov 2024

    There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during a line-number increment attempt.

    Published: 18 Nov 2018
    9.8
    Critical

    CVE-2018-19360

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.

    Published: 18 Nov 2018
    9.8
    Critical

    CVE-2018-19361

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.

    Published: 18 Nov 2018
    9.8
    Critical

    CVE-2018-19362

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.

    Published: 18 Nov 2018
    5.5
    Medium

    CVE-2018-20538

    Last Modified: 21 Nov 2024

    There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during certain finishes tests.

    Published: 18 Nov 2018
    7.2
    High

    CVE-2018-19349

    Last Modified: 21 Nov 2024

    In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php.

    Published: 17 Nov 2018
    5.4
    Medium

    CVE-2018-19350

    Last Modified: 21 Nov 2024

    In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.

    Published: 17 Nov 2018
    7.1
    High

    CVE-2018-19345

    Last Modified: 21 Nov 2024

    The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Read Access Violation near NULL starting at U3DBrowser!PlugInMain+0x0000000000053f8b" issue.

    Published: 17 Nov 2018
    7.1
    High

    CVE-2018-19346

    Last Modified: 21 Nov 2024

    The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Data from Faulting Address controls Branch Selection starting at U3DBrowser!PlugInMain+0x00000000000d11ea" issue.

    Published: 17 Nov 2018