CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2018-19279

    Last Modified: 21 Nov 2024

    PRIMX ZoneCentral before 6.1.2236 on Windows sometimes leaks the plaintext of NTFS files. On non-SSD devices, this is limited to a 5-second window and file sizes less than 600 bytes. The effect on SSD devices may be greater.

    Published: 14 Nov 2018
    9.8
    Critical

    CVE-2018-19281

    Last Modified: 21 Nov 2024

    Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.

    Published: 14 Nov 2018
    6.1
    Medium

    CVE-2018-19280

    Last Modified: 21 Nov 2024

    Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro.

    Published: 14 Nov 2018
    9.8
    Critical

    CVE-2018-5495

    Last Modified: 21 Nov 2024

    All StorageGRID Webscale versions are susceptible to a vulnerability which could permit an unauthenticated attacker to communicate with systems on the same network as the StorageGRID Webscale Admin Node via HTTP or to take over services on the Admin Node.

    Published: 14 Nov 2018
    9.8
    Critical

    CVE-2018-15708

    Last Modified: 21 Nov 2024

    Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.

    Published: 14 Nov 2018
    7.8
    High

    CVE-2018-15710

    Last Modified: 21 Nov 2024

    Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.

    Published: 14 Nov 2018
    8.8
    High

    CVE-2018-15711

    Last Modified: 21 Nov 2024

    Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new API key to execute API calls at elevated privileges.

    Published: 14 Nov 2018
    6.1
    Medium

    CVE-2018-15712

    Last Modified: 21 Nov 2024

    Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php.

    Published: 14 Nov 2018
    5.4
    Medium

    CVE-2018-15713

    Last Modified: 21 Nov 2024

    Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address in admin/users.php.

    Published: 14 Nov 2018
    6.1
    Medium

    CVE-2018-15714

    Last Modified: 21 Nov 2024

    Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.

    Published: 14 Nov 2018
    6.5
    Medium

    CVE-2018-9347

    Last Modified: 21 Nov 2024

    In function SMF_ParseMetaEvent of file eas_smf.c there is incorrect input validation causing an infinite loop. This could lead to a remote temporary DoS with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-68664359

    Published: 14 Nov 2018
    5.5
    Medium

    CVE-2018-9457

    Last Modified: 21 Nov 2024

    In onCheckedChanged of BluetoothPairingController.java, there is a possible way to retrieve contact information due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-72872376

    Published: 14 Nov 2018
    8.8
    High

    CVE-2018-9521

    Last Modified: 21 Nov 2024

    In parseMPEGCCData of NuPlayer2CCDecoder.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-111874331

    Published: 14 Nov 2018
    7.8
    High

    CVE-2018-9522

    Last Modified: 21 Nov 2024

    In the serialization functions of StatsLogEventWrapper.java, there is a possible out-of-bounds write due to unnecessary functionality which may be abused. This could lead to local escalation of privilege in the system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112550251

    Published: 14 Nov 2018
    7.8
    High

    CVE-2018-9523

    Last Modified: 21 Nov 2024

    In Parcel.writeMapInternal of Parcel.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-112859604

    Published: 14 Nov 2018
    7.8
    High

    CVE-2018-9524

    Last Modified: 21 Nov 2024

    In functionality implemented in System UI, there are insufficient protections implemented around overlay windows. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1. Android ID: A-34170870

    Published: 14 Nov 2018
    7.8
    High

    CVE-2018-9525

    Last Modified: 21 Nov 2024

    In the AndroidManifest.xml file defining the SliceBroadcastReceiver handler for com.android.settings.slice.action.WIFI_CHANGED, there is a possible permissions bypass due to a confused deputy. This could lead to local escalation of privilege, allowing a local attacker to change device settings, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-111330641

    Published: 14 Nov 2018
    7.5
    High

    CVE-2018-9526

    Last Modified: 21 Nov 2024

    In device configuration data, there is an improperly configured setting. This could lead to remote disclosure of device location. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112159033

    Published: 14 Nov 2018
    7.8
    High

    CVE-2018-9527

    Last Modified: 21 Nov 2024

    In vorbis_book_decodev_set of codebook.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-112159345

    Published: 14 Nov 2018
    8.8
    High

    CVE-2018-9529

    Last Modified: 21 Nov 2024

    In ixheaacd_individual_ch_stream of ixheaacd_channel.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112551874

    Published: 14 Nov 2018
    8.8
    High

    CVE-2018-9530

    Last Modified: 21 Nov 2024

    In ixheaacd_tns_ar_filter_dec of ixheaacd_aac_tns.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112609715

    Published: 14 Nov 2018
    7.8
    High

    CVE-2018-9531

    Last Modified: 21 Nov 2024

    In AudioSpecificConfig_Parse of tpdec_asc.cpp, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112661641

    Published: 14 Nov 2018
    8.8
    High

    CVE-2018-9532

    Last Modified: 21 Nov 2024

    In ixheaacd_extract_frame_info_ld of ixheaacd_env_extr.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112765917

    Published: 14 Nov 2018
    8.8
    High

    CVE-2018-9533

    Last Modified: 21 Nov 2024

    In ixheaacd_dec_data_init of ixheaacd_create.c there is a possible out of write read due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112766520

    Published: 14 Nov 2018
    7.8
    High

    CVE-2018-9536

    Last Modified: 21 Nov 2024

    In numerous functions of libFDK, there are possible out of bounds writes due to incorrect bounds checks. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112662184

    Published: 14 Nov 2018
    8.8
    High

    CVE-2018-9537

    Last Modified: 21 Nov 2024

    In CAacDecoder_DecodeFrame of aacdecode.cpp, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution in the media server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112891564

    Published: 14 Nov 2018
    7
    High

    CVE-2018-9539

    Last Modified: 21 Nov 2024

    In the ClearKey CAS descrambler, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-113027383

    Published: 14 Nov 2018
    7.5
    High

    CVE-2018-9542

    Last Modified: 21 Nov 2024

    In avrc_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-111896861

    Published: 14 Nov 2018
    5.5
    Medium

    CVE-2018-9543

    Last Modified: 21 Nov 2024

    In trim_device of f2fs_format_utils.c, it is possible that the data partition is not wiped during a factory reset. This could lead to local information disclosure after factory reset with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-112868088.

    Published: 14 Nov 2018
    5.5
    Medium

    CVE-2018-9544

    Last Modified: 21 Nov 2024

    In register_app of btif_hd.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113037220

    Published: 14 Nov 2018
    7.8
    High

    CVE-2018-9545

    Last Modified: 21 Nov 2024

    In BTA_HdRegisterApp of bta_hd_api.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113111784

    Published: 14 Nov 2018
    9.8
    Critical

    CVE-2018-9580

    Last Modified: 21 Nov 2024

    A Elevation of privilege vulnerability in the HTC bootloader. Product: Android. Versions: Android kernel. Android ID: A-76222002.

    Published: 14 Nov 2018
    8.8
    High

    CVE-2018-9528

    Last Modified: 21 Nov 2024

    In ixheaacd_over_lap_add1_armv8 of ixheaacd_overlap_add1.s there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112551721

    Published: 14 Nov 2018
    8.8
    High

    CVE-2018-9534

    Last Modified: 21 Nov 2024

    In ixheaacd_mps_getstridemap of ixheaacd_mps_parse.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112857941

    Published: 14 Nov 2018
    7.5
    High

    CVE-2018-9540

    Last Modified: 21 Nov 2024

    In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-111450417

    Published: 14 Nov 2018
    8.8
    High

    CVE-2018-15709

    Last Modified: 21 Nov 2024

    Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.

    Published: 14 Nov 2018
    8.8
    High

    CVE-2018-9535

    Last Modified: 21 Nov 2024

    In ixheaacd_reset_acelp_data_fix of ixheaacd_lpc.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112858010

    Published: 14 Nov 2018
    7.5
    High

    CVE-2018-9541

    Last Modified: 21 Nov 2024

    In avrc_pars_vendor_rsp of avcr_pars_ct.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-111450531

    Published: 14 Nov 2018
    6.5
    Medium

    CVE-2018-7357

    Last Modified: 21 Nov 2024

    ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper access control vulnerability, which may allow an unauthorized user to gain unauthorized access.

    Published: 14 Nov 2018
    6.5
    Medium

    CVE-2018-7358

    Last Modified: 21 Nov 2024

    ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerability, which may allow an unauthorized user to perform unauthorized operations.

    Published: 14 Nov 2018
    6.5
    Medium

    CVE-2018-3621

    Last Modified: 21 Nov 2024

    Insufficient input validation in the Intel Driver & Support Assistant before 3.6.0.4 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.

    Published: 14 Nov 2018
    7.8
    High

    CVE-2018-3697

    Last Modified: 21 Nov 2024

    Improper directory permissions in the installer for the Intel Media Server Studio may allow unprivileged users to potentially enable an escalation of privilege via local access.

    Published: 14 Nov 2018
    7.8
    High

    CVE-2018-3698

    Last Modified: 21 Nov 2024

    Improper file permissions in the installer for the Intel Ready Mode Technology may allow an unprivileged user to potentially gain privileged access via local access.

    Published: 14 Nov 2018
    6.1
    Medium

    CVE-2018-3699

    Last Modified: 21 Nov 2024

    Cross-site scripting in the Intel RAID Web Console v3 for Windows may allow an unauthenticated user to elevate privilege via remote access.

    Published: 14 Nov 2018
    5.5
    Medium

    CVE-2018-3696

    Last Modified: 21 Nov 2024

    Authentication bypass in the Intel RAID Web Console 3 for Windows before 4.186 may allow an unprivileged user to potentially gain administrative privileges via local access.

    Published: 14 Nov 2018
    7.8
    High

    CVE-2018-12174

    Last Modified: 21 Nov 2024

    Heap overflow in Intel Trace Analyzer 2018 in Intel Parallel Studio XE 2018 Update 3 may allow an authenticated user to potentially escalate privileges via local access.

    Published: 14 Nov 2018
    7.8
    High

    CVE-2018-3635

    Last Modified: 21 Nov 2024

    Insufficient input validation in installer in Intel Rapid Store Technology (RST) before version 16.7 may allow an unprivileged user to potentially elevate privileges or cause an installer denial of service via local access.

    Published: 14 Nov 2018
    8.8
    High

    CVE-2018-19271

    Last Modified: 21 Nov 2024

    Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.28) allows SQL Injection via the main.php searchH parameter.

    Published: 14 Nov 2018
    8.8
    High

    CVE-2018-19277

    Last Modified: 21 Nov 2024

    securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file

    Published: 14 Nov 2018
    7.8
    High

    CVE-2018-19270

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-16276. Reason: This candidate is a reservation duplicate of CVE-2018-16276. Notes: All CVE users should reference CVE-2018-16276 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 14 Nov 2018