CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2019-0133

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 13 Nov 2018
    Unknown

    CVE-2019-0156

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 13 Nov 2018
    Unknown

    CVE-2019-0167

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 13 Nov 2018
    Unknown

    CVE-2019-0176

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 13 Nov 2018
    6.5
    Medium

    CVE-2018-19876

    Last Modified: 21 Nov 2024

    cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMalloc, leading to an application crash with a "free(): invalid pointer" error.

    Published: 13 Nov 2018
    6.5
    Medium

    CVE-2018-8416

    Last Modified: 21 Nov 2024

    A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1.

    Published: 13 Nov 2018
    7.5
    High

    CVE-2018-15978

    Last Modified: 21 Nov 2024

    Flash Player versions 31.0.0.122 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 13 Nov 2018
    6.5
    Medium

    CVE-2018-19039

    Last Modified: 21 Nov 2024

    Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.

    Published: 13 Nov 2018
    Unknown

    CVE-2019-0125

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 13 Nov 2018
    Unknown

    CVE-2019-0137

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 13 Nov 2018
    9.8
    Critical

    CVE-2018-19220

    Last Modified: 21 Nov 2024

    An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI.

    Published: 12 Nov 2018
    4.8
    Medium

    CVE-2018-19223

    Last Modified: 21 Nov 2024

    An issue was discovered in LAOBANCMS 2.0. It allows XSS via the first input field to the admin/type.php?id=1 URI.

    Published: 12 Nov 2018
    5.3
    Medium

    CVE-2018-19226

    Last Modified: 21 Nov 2024

    An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to list .txt files via a direct request for the /data/0/admin.txt URI.

    Published: 12 Nov 2018
    5.4
    Medium

    CVE-2018-19227

    Last Modified: 21 Nov 2024

    An issue was discovered in LAOBANCMS 2.0. It allows XSS via the admin/liuyan.php neirong[] parameter.

    Published: 12 Nov 2018
    5.4
    Medium

    CVE-2018-19229

    Last Modified: 21 Nov 2024

    An issue was discovered in LAOBANCMS 2.0. It allows XSS via the admin/art.php?typeid=1 biaoti parameter.

    Published: 12 Nov 2018
    7.5
    High

    CVE-2018-19224

    Last Modified: 21 Nov 2024

    An issue was discovered in LAOBANCMS 2.0. /admin/login.php allows spoofing of the id and guanliyuan cookies.

    Published: 12 Nov 2018
    8.8
    High

    CVE-2018-19225

    Last Modified: 21 Nov 2024

    An issue was discovered in LAOBANCMS 2.0. admin/mima.php has CSRF.

    Published: 12 Nov 2018
    7.5
    High

    CVE-2018-19228

    Last Modified: 21 Nov 2024

    An issue was discovered in LAOBANCMS 2.0. It allows arbitrary file deletion via ../ directory traversal in the admin/pic.php del parameter, as demonstrated by deleting install/install.txt to permit a reinstallation.

    Published: 12 Nov 2018
    9.8
    Critical

    CVE-2018-19221

    Last Modified: 21 Nov 2024

    An issue was discovered in LAOBANCMS 2.0. It allows SQL Injection via the admin/login.php guanliyuan parameter.

    Published: 12 Nov 2018
    9.8
    Critical

    CVE-2018-19222

    Last Modified: 21 Nov 2024

    An issue was discovered in LAOBANCMS 2.0. It allows a /install/mysql_hy.php?riqi=0&i=0 attack to reset the admin password, even if install.txt exists.

    Published: 12 Nov 2018
    6.5
    Medium

    CVE-2018-19219

    Last Modified: 21 Nov 2024

    In LibSass 3.5-stable, there is an illegal address access at Sass::Eval::operator that will lead to a DoS attack.

    Published: 12 Nov 2018
    6.5
    Medium

    CVE-2018-19212

    Last Modified: 21 Nov 2024

    In libwebm through 2018-10-03, there is an abort caused by libwebm::Webm2Pes::InitWebmParser() that will lead to a DoS attack.

    Published: 12 Nov 2018
    6.1
    Medium

    CVE-2018-19206

    Last Modified: 21 Nov 2024

    steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.

    Published: 12 Nov 2018
    9.8
    Critical

    CVE-2018-19207

    Last Modified: 21 Nov 2024

    The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018.

    Published: 12 Nov 2018
    7.5
    High

    CVE-2018-19205

    Last Modified: 21 Nov 2024

    Roundcube before 1.3.7 mishandles GnuPG MDC integrity-protection warnings, which makes it easier for attackers to obtain sensitive information, a related issue to CVE-2017-17688. This is associated with plugins/enigma/lib/enigma_driver_gnupg.php.

    Published: 12 Nov 2018
    6.1
    Medium

    CVE-2018-1798

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 149428.

    Published: 12 Nov 2018
    7.5
    High

    CVE-2018-19203

    Last Modified: 21 Nov 2024

    PRTG Network Monitor before 18.2.41.1652 allows remote unauthenticated attackers to terminate the PRTG Core Server Service via a special HTTP request.

    Published: 12 Nov 2018
    5.3
    Medium

    CVE-2018-1786

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect 7.1 and 8.1 dsmc and dsmcad processes incorrectly accumulate TCP/IP sockets in a CLOSE_WAIT state. This can cause TCP/IP resource leakage and may result in a denial of service. IBM X-Force ID: 148871.

    Published: 12 Nov 2018
    8.8
    High

    CVE-2018-19204

    Last Modified: 21 Nov 2024

    PRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS commands with system privileges. When creating an HTTP Advanced Sensor, the user's input in the POST parameter 'proxyport_' is mishandled. The attacker can craft an HTTP request and override the 'writeresult' command-line parameter for HttpAdvancedSensor.exe to store arbitrary data in an arbitrary place on the file system. For example, the attacker can create an executable file in the \Custom Sensors\EXE directory and execute it by creating EXE/Script Sensor.

    Published: 12 Nov 2018
    4.8
    Medium

    CVE-2018-1884

    Last Modified: 21 Nov 2024

    IBM Case Manager 5.2.0.0, 5.2.0.4, 5.2.1.0, 5.2.1.7, 5.3.0.0, and 5.3.3.0 is vulnerable to a "zip slip" vulnerability which could allow a remote attacker to execute code using directory traversal techniques. IBM X-Force ID: 151970.

    Published: 12 Nov 2018
    8.8
    High

    CVE-2018-19192

    Last Modified: 21 Nov 2024

    An issue was discovered in XiaoCms 20141229. admin/index.php?c=content&a=add&catid=3 has CSRF, as demonstrated by entering news via the data[content] parameter.

    Published: 12 Nov 2018
    6.1
    Medium

    CVE-2018-19195

    Last Modified: 21 Nov 2024

    An issue was discovered in XiaoCms 20141229. There is XSS related to the template\default\show_product.html file.

    Published: 12 Nov 2018
    4.9
    Medium

    CVE-2018-19197

    Last Modified: 21 Nov 2024

    An issue was discovered in XiaoCms 20141229. admin\controller\database.php allows arbitrary directory deletion via admin/index.php?c=database&a=import&paths[]=../ directory traversal.

    Published: 12 Nov 2018
    9.8
    Critical

    CVE-2018-19185

    Last Modified: 21 Nov 2024

    An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/asn1/ber_encoder.c. This is exploitable even after CVE-2018-18834 has been patched, with a different dataSetValue sequence than the CVE-2018-18834 attack vector.

    Published: 12 Nov 2018
    6.1
    Medium

    CVE-2018-19193

    Last Modified: 21 Nov 2024

    An issue was discovered in XiaoCms 20141229. There is XSS via the largest input box on the "New news" screen.

    Published: 12 Nov 2018
    9.8
    Critical

    CVE-2018-19196

    Last Modified: 21 Nov 2024

    An issue was discovered in XiaoCms 20141229. It allows remote attackers to execute arbitrary code by using the type parameter to bypass the standard admin\controller\uploadfile.php restrictions on uploaded file types (jpg, jpeg, bmp, png, gif), as demonstrated by an admin/index.php?c=uploadfile&a=uploadify_upload&type=php URI.

    Published: 12 Nov 2018
    5.3
    Medium

    CVE-2018-19194

    Last Modified: 21 Nov 2024

    An issue was discovered in XiaoCms 20141229. /admin/index.php?c=database allows full path disclosure in a "failed to open stream" error message.

    Published: 12 Nov 2018
    8.8
    High

    CVE-2018-18920

    Last Modified: 21 Nov 2024

    Py-EVM v0.2.0-alpha.33 allows attackers to make a vm.execute_bytecode call that triggers computation._stack.values with '"stack": [100, 100, 0]' where b'\x' was expected, resulting in an execution failure because of an invalid opcode. This is reportedly related to "smart contracts can be executed indefinitely without gas being paid."

    Published: 12 Nov 2018
    7.5
    High

    CVE-2018-19184

    Last Modified: 21 Nov 2024

    cmd/evm/runner.go in Go Ethereum (aka geth) 1.8.17 allows attackers to cause a denial of service (SEGV) via crafted bytecode.

    Published: 12 Nov 2018
    7.5
    High

    CVE-2018-19183

    Last Modified: 21 Nov 2024

    ethereumjs-vm 2.4.0 allows attackers to cause a denial of service (vm.runCode failure and REVERT) via a "code: Buffer.from(my_code, 'hex')" attribute. NOTE: the vendor disputes this because REVERT is a normal bytecode that can be triggered from high-level source code, leading to a normal programmatic execution result.

    Published: 12 Nov 2018
    6.5
    Medium

    CVE-2018-19217

    Last Modified: 21 Nov 2024

    In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party

    Published: 12 Nov 2018
    5.5
    Medium

    CVE-2018-19755

    Last Modified: 21 Nov 2024

    There is an illegal address access at asm/preproc.c (function: is_mmacro) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service (out-of-bounds array access) because a certain conversion can result in a negative integer.

    Published: 12 Nov 2018
    7.5
    High

    CVE-2018-20783

    Last Modified: 21 Nov 2024

    In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. This is related to phar_parse_pharfile in ext/phar/phar.c.

    Published: 12 Nov 2018
    7.4
    High

    CVE-2018-17187

    Last Modified: 21 Nov 2024

    The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods. Unless a verification mode was explicitly configured, client and server modes previously defaulted as documented to not verifying a peer certificate, with options to configure this explicitly or select a certificate verification mode with or without hostname verification being performed. The latter hostname verifying mode was not implemented in Apache Qpid Proton-J versions 0.3 to 0.29.0, with attempts to use it resulting in an exception. This left only the option to verify the certificate is trusted, leaving such a client vulnerable to Man In The Middle (MITM) attack. Uses of the Proton-J protocol engine which do not utilise the optional transport TLS wrapper are not impacted, e.g. usage within Qpid JMS. Uses of Proton-J utilising the optional transport TLS wrapper layer that wish to enable hostname verification must be upgraded to version 0.30.0 or later and utilise the VerifyMode#VERIFY_PEER_NAME configuration, which is now the default for client mode usage unless configured otherwise.

    Published: 12 Nov 2018
    7.5
    High

    CVE-2018-20679

    Last Modified: 9 Jun 2025

    An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server, client, and relay) allows a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is related to verification in udhcp_get_option() in networking/udhcp/common.c that 4-byte options are indeed 4 bytes.

    Published: 12 Nov 2018
    9.8
    Critical

    CVE-2018-19180

    Last Modified: 21 Nov 2024

    statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php.

    Published: 11 Nov 2018
    7.5
    High

    CVE-2018-19181

    Last Modified: 21 Nov 2024

    statics/ueditor/php/vendor/Local.class.php in YUNUCMS 1.1.5 allows arbitrary file deletion via the statics/ueditor/php/controller.php?action=remove key parameter, as demonstrated by using directory traversal to delete the install.lock file.

    Published: 11 Nov 2018
    5.4
    Medium

    CVE-2018-19178

    Last Modified: 21 Nov 2024

    In JEESNS 1.3, com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java allows stored XSS via an HTML EMBED element, a different vulnerability than CVE-2018-17886.

    Published: 11 Nov 2018
    6.5
    Medium

    CVE-2018-19143

    Last Modified: 21 Nov 2024

    Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13 allows an authenticated user to delete files via a modified submission form because upload caching is mishandled.

    Published: 11 Nov 2018
    4.8
    Medium

    CVE-2018-19170

    Last Modified: 21 Nov 2024

    In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/setting URI, as demonstrated by the web_name parameter.

    Published: 11 Nov 2018