CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2018-15447

    Last Modified: 26 Nov 2024

    A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected application.

    Published: 8 Nov 2018
    7.5
    High

    CVE-2018-15448

    Last Modified: 26 Nov 2024

    A vulnerability in the user management functions of Cisco Registered Envelope Service could allow an unauthenticated, remote attacker to discover sensitive user information. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to an insecure configuration that allows improper indexing. An attacker could exploit this vulnerability by using a search engine to look for specific data strings. A successful exploit could allow the attacker to discover certain sensitive information about the application, including usernames.

    Published: 8 Nov 2018
    6.3
    Medium

    CVE-2018-15444

    Last Modified: 26 Nov 2024

    A vulnerability in the web-based user interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by convincing a user of an affected system to import a crafted XML file with malicious entries, which could allow the attacker to read and write files within the affected application.

    Published: 8 Nov 2018
    5.3
    Medium

    CVE-2018-15446

    Last Modified: 26 Nov 2024

    A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper protections on data that is returned from user meeting requests when the Guest access via ID and passcode option is set to Legacy mode. An attacker could exploit this vulnerability by sending meeting requests to an affected system. A successful exploit could allow the attacker to determine the values of meeting room unique identifiers, possibly allowing the attacker to conduct further exploits.

    Published: 8 Nov 2018
    8.8
    High

    CVE-2018-19114

    Last Modified: 21 Nov 2024

    An issue was discovered in MinDoc through v1.0.2. It allows attackers to gain privileges by uploading an image file with contents that represent an admin session, and then sending a Cookie: header with a mindoc_id value containing the relative pathname of this uploaded file. For example, the mindoc_id (aka session ID) could be of the form aa/../../uploads/blog/201811/attach_#.jpg where '#' is a hex value displayed in the upload field of a manage/blogs/edit/ screen.

    Published: 8 Nov 2018
    6.3
    Medium

    CVE-2018-15445

    Last Modified: 26 Nov 2024

    A vulnerability in the web-based management interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on a targeted device via a web browser and with the privileges of the user.

    Published: 8 Nov 2018
    4.8
    Medium

    CVE-2018-15393

    Last Modified: 26 Nov 2024

    A vulnerability in the web-based management interface of Cisco Content Security Management Appliance (SMA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a maliciously crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

    Published: 8 Nov 2018
    9.8
    Critical

    CVE-2018-15439

    Last Modified: 26 Nov 2024

    A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected software enables a privileged user account without notifying administrators of the system. An attacker could exploit this vulnerability by using this account to log in to an affected device and execute commands with full admin rights. Cisco has not released software updates that address this vulnerability. This advisory will be updated with fixed software information once fixed software becomes available. There is a workaround to address this vulnerability.

    Published: 8 Nov 2018
    9.8
    Critical

    CVE-2018-15394

    Last Modified: 26 Nov 2024

    A vulnerability in the Stealthwatch Management Console (SMC) of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected system. The vulnerability is due to an insecure system configuration. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted application. An exploit could allow the attacker to gain unauthenticated access, resulting in elevated privileges in the SMC.

    Published: 8 Nov 2018
    5.5
    Medium

    CVE-2018-15437

    Last Modified: 26 Nov 2024

    A vulnerability in the system scanning component of Cisco Immunet and Cisco Advanced Malware Protection (AMP) for Endpoints running on Microsoft Windows could allow a local attacker to disable the scanning functionality of the product. This could allow executable files to be launched on the system without being analyzed for threats. The vulnerability is due to improper process resource handling. An attacker could exploit this vulnerability by gaining local access to a system running Microsoft Windows and protected by Cisco Immunet or Cisco AMP for Endpoints and executing a malicious file. A successful exploit could allow the attacker to prevent the scanning services from functioning properly and ultimately prevent the system from being protected from further intrusion.

    Published: 8 Nov 2018
    5.8
    Medium

    CVE-2018-15443

    Last Modified: 26 Nov 2024

    A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a configured Intrusion Prevention System (IPS) rule that inspects certain types of TCP traffic. The vulnerability is due to incorrect TCP retransmission handling. An attacker could exploit this vulnerability by sending a crafted TCP connection request through an affected device. A successful exploit could allow the attacker to bypass configured IPS rules and allow uninspected traffic onto the network.

    Published: 8 Nov 2018
    9.8
    Critical

    CVE-2018-15381

    Last Modified: 26 Nov 2024

    A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a malicious serialized Java object to the listening Java Remote Method Invocation (RMI) service. A successful exploit could allow the attacker to execute arbitrary commands on the device with root privileges.

    Published: 8 Nov 2018
    6.5
    Medium

    CVE-2018-0284

    Last Modified: 26 Nov 2024

    A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The vulnerability occurs when handling requests to the local status page. An exploit could allow the attacker to establish an interactive session to the device with elevated privileges. The attacker could then use the elevated privileges to further compromise the device or obtain additional configuration data from the device that is being exploited.

    Published: 8 Nov 2018
    8.1
    High

    CVE-2018-11777

    Last Modified: 21 Nov 2024

    In Apache Hive 2.3.3, 3.1.0 and earlier, local resources on HiveServer2 machines are not properly protected against malicious user if ranger, sentry or sql standard authorizer is not in use.

    Published: 8 Nov 2018
    4.3
    Medium

    CVE-2018-1314

    Last Modified: 21 Nov 2024

    In Apache Hive 2.3.3, 3.1.0 and earlier, Hive "EXPLAIN" operation does not check for necessary authorization of involved entities in a query. An unauthorized user can do "EXPLAIN" on arbitrary table or view and expose table metadata and statistics.

    Published: 8 Nov 2018
    5.5
    Medium

    CVE-2018-6433

    Last Modified: 21 Nov 2024

    A vulnerability in the secryptocfg export command of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to bypass the export file access restrictions and initiate a file copy from the source to a remote system.

    Published: 8 Nov 2018
    7.8
    High

    CVE-2018-6441

    Last Modified: 21 Nov 2024

    A vulnerability in Secure Shell implementation of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to provide arbitrary environment variables, and bypass the restricted configuration shell.

    Published: 8 Nov 2018
    7.5
    High

    CVE-2018-6434

    Last Modified: 21 Nov 2024

    A vulnerability in the web management interface of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow attackers to intercept or manipulate a user's session ID.

    Published: 8 Nov 2018
    8.8
    High

    CVE-2018-6442

    Last Modified: 21 Nov 2024

    A vulnerability in the Brocade Webtools firmware update section of Brocade Fabric OS before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow remote authenticated attackers to execute arbitrary commands.

    Published: 8 Nov 2018
    7.8
    High

    CVE-2018-6435

    Last Modified: 21 Nov 2024

    A Vulnerability in the secryptocfg command of Brocade Fabric OS command line interface (CLI) versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to escape the restricted shell and, and gain root access.

    Published: 8 Nov 2018
    8.8
    High

    CVE-2018-19104

    Last Modified: 21 Nov 2024

    In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges.

    Published: 8 Nov 2018
    8.8
    High

    CVE-2018-19109

    Last Modified: 21 Nov 2024

    tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/cms/column/list directly to read the column list page or edit a column.

    Published: 8 Nov 2018
    6.5
    Medium

    CVE-2018-19110

    Last Modified: 21 Nov 2024

    The skin-management feature in tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/user/skin/list directly because controller\usercontroller.java maps a /skin/list request to the function skinList, and lacks an authorization check.

    Published: 8 Nov 2018
    5.3
    Medium

    CVE-2018-19111

    Last Modified: 21 Nov 2024

    The Google Cardboard application 1.8 for Android and 1.2 for iOS sends potentially private cleartext information to the Unity 3D Stats web site, as demonstrated by device make, model, and OS.

    Published: 8 Nov 2018
    7.8
    High

    CVE-2018-19105

    Last Modified: 21 Nov 2024

    LibreCAD 2.1.3 allows remote attackers to cause a denial of service (0x89C04589 write access violation and application crash) or possibly have unspecified other impact via a crafted file.

    Published: 8 Nov 2018
    5.3
    Medium

    CVE-2018-1000845

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultID: CVE-2017-6519. Reason: This candidate is a duplicate of CVE-2017-6519. Notes: All CVE users should reference CVE-2017-6519 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 8 Nov 2018
    7.5
    High

    CVE-2018-19045

    Last Modified: 21 Nov 2024

    keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive information.

    Published: 8 Nov 2018
    6.5
    Medium

    CVE-2018-19149

    Last Modified: 21 Nov 2024

    Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment.

    Published: 8 Nov 2018
    4.7
    Medium

    CVE-2018-19044

    Last Modified: 21 Nov 2024

    keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats. This allowed local users to overwrite arbitrary files if fs.protected_symlinks is set to 0, as demonstrated by a symlink from /tmp/keepalived.data or /tmp/keepalived.stats to /etc/passwd.

    Published: 8 Nov 2018
    4.7
    Medium

    CVE-2018-19046

    Last Modified: 21 Nov 2024

    keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats. If a local attacker had previously created a file with the expected name (e.g., /tmp/keepalived.data or /tmp/keepalived.stats), with read access for the attacker and write access for the keepalived process, then this potentially leaked sensitive information.

    Published: 8 Nov 2018
    9.8
    Critical

    CVE-2018-19115

    Last Modified: 21 Nov 2024

    keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status code and instead writes an unlimited amount of data to the heap.

    Published: 8 Nov 2018
    9.8
    Critical

    CVE-2018-16850

    Last Modified: 21 Nov 2024

    postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser privileges.

    Published: 8 Nov 2018
    5.9
    Medium

    CVE-2018-16150

    Last Modified: 21 Nov 2024

    In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification does not reject excess data after the hash value. Consequently, a remote attacker can forge signatures when small public exponents are being used, which could lead to impersonation through fake X.509 certificates. This is a variant of CVE-2006-4340.

    Published: 7 Nov 2018
    5.9
    Medium

    CVE-2018-16149

    Last Modified: 21 Nov 2024

    In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification blindly trusts the declared lengths in the ASN.1 structure. Consequently, when small public exponents are being used, a remote attacker can generate purposefully crafted signatures (and put them on X.509 certificates) to induce illegal memory access and crash the verifier.

    Published: 7 Nov 2018
    5.9
    Medium

    CVE-2018-16253

    Last Modified: 21 Nov 2024

    In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification does not properly verify the ASN.1 metadata. Consequently, a remote attacker can forge signatures when small public exponents are being used, which could lead to impersonation through fake X.509 certificates. This is an even more permissive variant of CVE-2006-4790 and CVE-2014-1568.

    Published: 7 Nov 2018
    5.4
    Medium

    CVE-2018-19089

    Last Modified: 21 Nov 2024

    tianti 2.3 has stored XSS in the userlist module via the tianti-module-admin/user/ajax/save_role name parameter, which is mishandled in tianti-module-admin\src\main\webapp\WEB-INF\views\user\user_list.jsp.

    Published: 7 Nov 2018
    5.4
    Medium

    CVE-2018-19090

    Last Modified: 21 Nov 2024

    tianti 2.3 has stored XSS in the article management module via an article title.

    Published: 7 Nov 2018
    5.4
    Medium

    CVE-2018-19091

    Last Modified: 21 Nov 2024

    tianti 2.3 has reflected XSS in the user management module via the tianti-module-admin/user/list userName parameter.

    Published: 7 Nov 2018
    6.1
    Medium

    CVE-2018-19092

    Last Modified: 21 Nov 2024

    An issue was discovered in YzmCMS v5.2. It has XSS via a search/index/archives/pubtime/ query string, as demonstrated by the search/index/archives/pubtime/1526387722/page/1.html URI. NOTE: this does not obtain a user's cookie.

    Published: 7 Nov 2018
    7.5
    High

    CVE-2018-19093

    Last Modified: 21 Nov 2024

    An issue has been found in libIEC61850 v1.3. It is a SEGV in ControlObjectClient_setCommandTerminationHandler in client/client_control.c. NOTE: the software maintainer disputes this because it requires incorrect usage of the client_example_control program

    Published: 7 Nov 2018
    4.9
    Medium

    CVE-2018-19068

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The CGIProxy.fcgi?cmd=setTelnetSwitch feature is authorized for hidden factory credentials.

    Published: 7 Nov 2018
    7.8
    High

    CVE-2018-19071

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. /mnt/mtd/boot.sh has 0777 permissions, allowing local users to control the commands executed at system start-up.

    Published: 7 Nov 2018
    5.5
    Medium

    CVE-2018-19072

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. /mnt/mtd/app has 0777 permissions, allowing local users to replace an archive file (within that directory) to control what is extracted to RAM at boot time.

    Published: 7 Nov 2018
    7.2
    High

    CVE-2018-19073

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. They allow attackers to execute arbitrary OS commands via shell metacharacters in the modelName, by leveraging /mnt/mtd/app/config/ProductConfig.xml write access.

    Published: 7 Nov 2018
    7.5
    High

    CVE-2018-19074

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The firewall has no effect except for blocking port 443 and partially blocking port 88.

    Published: 7 Nov 2018
    9.8
    Critical

    CVE-2018-19078

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The response to an ONVIF media GetStreamUri request contains the administrator username and password.

    Published: 7 Nov 2018
    6.1
    Medium

    CVE-2018-19080

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetHostname method allows unauthenticated persistent XSS.

    Published: 7 Nov 2018
    9.8
    Critical

    CVE-2018-19081

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS method allows remote attackers to execute arbitrary OS commands via the IPv4Address field.

    Published: 7 Nov 2018
    9.8
    Critical

    CVE-2018-19082

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS method allows remote attackers to conduct stack-based buffer overflow attacks via the IPv4Address field.

    Published: 7 Nov 2018
    7.5
    High

    CVE-2018-19065

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The exported device configuration is encrypted with the hardcoded BpP+2R9*Q password in some cases.

    Published: 7 Nov 2018