CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-9436

    Last Modified: 21 Nov 2024

    In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-79164722.

    Published: 6 Nov 2018
    8.8
    High

    CVE-2018-9459

    Last Modified: 21 Nov 2024

    In Attachment of Attachment.java and getFilePath of EmlAttachmentProvider.java, there is a possible Elevation of Privilege due to a path traversal error. This could lead to a remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-66230183.

    Published: 6 Nov 2018
    9.8
    Critical

    CVE-2018-9355

    Last Modified: 21 Nov 2024

    In bta_dm_sdp_result of bta_dm_act.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74016921.

    Published: 6 Nov 2018
    7.5
    High

    CVE-2018-9358

    Last Modified: 21 Nov 2024

    In gatts_process_attribute_req of gatt_sc.cc, there is a possible read of uninitialized data due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-73172115.

    Published: 6 Nov 2018
    7.5
    High

    CVE-2018-9361

    Last Modified: 21 Nov 2024

    In process_l2cap_cmd of l2c_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74202041.

    Published: 6 Nov 2018
    5.5
    Medium

    CVE-2018-9437

    Last Modified: 21 Nov 2024

    In getstring of ID3.cpp there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-78656554.

    Published: 6 Nov 2018
    6.8
    Medium

    CVE-2018-9445

    Last Modified: 21 Nov 2024

    In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local escalation of privilege when mounting a USB device with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-80436257.

    Published: 6 Nov 2018
    9.8
    Critical

    CVE-2018-9446

    Last Modified: 21 Nov 2024

    In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds write due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-80145946.

    Published: 6 Nov 2018
    5.5
    Medium

    CVE-2018-9453

    Last Modified: 21 Nov 2024

    In avdt_msg_prs_cfg of avdt_msg.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-78288378.

    Published: 6 Nov 2018
    4.3
    Medium

    CVE-2018-1606

    Last Modified: 21 Nov 2024

    IBM Jazz based applications (IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational DOORS Next Generation 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Quality Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Rhapsody Design Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Software Architect Design Manager 5.0 through 5.02 and 6.0 through 6.0.1, IBM Rational Team Concert 5.0 through 5.02 and 6.0 through 6.0.6) could allow an authenticated user to obtain sensitive information from an error message that could be used in further attacks against the system. IBM X-Force ID: 143796.

    Published: 6 Nov 2018
    5.9
    Medium

    CVE-2018-1694

    Last Modified: 21 Nov 2024

    IBM Jazz applications (IBM Rational Collaborative Lifecycle Management 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational DOORS Next Generation 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Quality Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Rhapsody Design Manager 5.0 through 5.02 and 6.0 through 6.0.6, IBM Rational Software Architect Design Manager 5.0 through 5.02 and 6.0 through 6.0.1, IBM Rational Team Concert 5.0 through 5.02 and 6.0 through 6.0.6) could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 145609.

    Published: 6 Nov 2018
    8.8
    High

    CVE-2018-16986

    Last Modified: 21 Nov 2024

    Texas Instruments BLE-STACK v2.2.1 for SimpleLink CC2640 and CC2650 devices allows remote attackers to execute arbitrary code via a malformed packet that triggers a buffer overflow.

    Published: 6 Nov 2018
    9.8
    Critical

    CVE-2018-18963

    Last Modified: 21 Nov 2024

    Busca.aspx.cs in Degrau Publicidade e Internet Plataforma de E-commerce allows SQL Injection via the busca/ URI.

    Published: 6 Nov 2018
    4.9
    Medium

    CVE-2018-18964

    Last Modified: 21 Nov 2024

    osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but there are several extensions in which contained HTML can be executed, such as the svg extension.

    Published: 6 Nov 2018
    4.9
    Medium

    CVE-2018-18965

    Last Modified: 21 Nov 2024

    osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but there are several alternative cases in which HTML can be executed, such as a file with no extension or an unrecognized extension (e.g., the test or test.asdf filename).

    Published: 6 Nov 2018
    4.9
    Medium

    CVE-2018-18966

    Last Modified: 21 Nov 2024

    osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. The .htaccess file in catalog/images/ bans the html extension, but Internet Explorer render HTML elements in a .eml file.

    Published: 6 Nov 2018
    7.5
    High

    CVE-2018-18980

    Last Modified: 21 Nov 2024

    An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.

    Published: 6 Nov 2018
    7.5
    High

    CVE-2018-16470

    Last Modified: 21 Nov 2024

    There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.

    Published: 6 Nov 2018
    7.5
    High

    CVE-2018-16844

    Last Modified: 21 Nov 2024

    nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.

    Published: 6 Nov 2018
    6.5
    Medium

    CVE-2018-17244

    Last Modified: 21 Nov 2024

    Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms. A request may receive headers intended for another request if the same username is being authenticated concurrently; when used with run as, this can result in the request running as the incorrect user. This could allow a user to access information that they should not have access to.

    Published: 6 Nov 2018
    9.8
    Critical

    CVE-2018-17245

    Last Modified: 21 Nov 2024

    Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP request that could be recovered by an external resource provider.

    Published: 6 Nov 2018
    6.5
    Medium

    CVE-2018-19059

    Last Modified: 21 Nov 2024

    An issue was discovered in Poppler 0.71.0. There is a out-of-bounds read in EmbFile::save2 in FileSpec.cc, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating embedded files before save attempts.

    Published: 6 Nov 2018
    9.8
    Critical

    CVE-2018-17246

    Last Modified: 21 Nov 2024

    Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

    Published: 6 Nov 2018
    7.5
    High

    CVE-2018-16843

    Last Modified: 21 Nov 2024

    nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.

    Published: 6 Nov 2018
    6.1
    Medium

    CVE-2018-16845

    Last Modified: 21 Nov 2024

    nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

    Published: 6 Nov 2018
    6.1
    Medium

    CVE-2018-16471

    Last Modified: 21 Nov 2024

    There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable.

    Published: 6 Nov 2018
    6.5
    Medium

    CVE-2018-19058

    Last Modified: 21 Nov 2024

    An issue was discovered in Poppler 0.71.0. There is a reachable abort in Object.h, will lead to denial of service because EmbFile::save2 in FileSpec.cc lacks a stream check before saving an embedded file.

    Published: 6 Nov 2018
    6.5
    Medium

    CVE-2018-19060

    Last Modified: 21 Nov 2024

    An issue was discovered in Poppler 0.71.0. There is a NULL pointer dereference in goo/GooString.h, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating a filename of an embedded file before constructing a save path.

    Published: 6 Nov 2018
    6.5
    Medium

    CVE-2018-19967

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing guest OS users to cause a denial of service (host OS hang) because Xen does not work around Intel's mishandling of certain HLE transactions associated with the KACQUIRE instruction prefix.

    Published: 6 Nov 2018
    7.8
    High

    CVE-2018-17905

    Last Modified: 21 Nov 2024

    When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memory corruption may occur within a specific object.

    Published: 5 Nov 2018
    3.3
    Low

    CVE-2018-17907

    Last Modified: 21 Nov 2024

    When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with the value of an offset, an attacker can force the application to read a value outside of an array.

    Published: 5 Nov 2018
    7.8
    High

    CVE-2018-17913

    Last Modified: 21 Nov 2024

    A type confusion vulnerability exists when processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, which may allow an attacker to execute code in the context of the application.

    Published: 5 Nov 2018
    7.8
    High

    CVE-2018-17909

    Last Modified: 21 Nov 2024

    When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, the application fails to check if it is referencing freed memory, which may allow an attacker to execute code under the context of the application.

    Published: 5 Nov 2018
    8.8
    High

    CVE-2018-13396

    Last Modified: 21 Nov 2024

    There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system.

    Published: 5 Nov 2018
    8.8
    High

    CVE-2018-13397

    Last Modified: 21 Nov 2024

    There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.

    Published: 5 Nov 2018
    9.8
    Critical

    CVE-2018-18957

    Last Modified: 21 Nov 2024

    An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_publisher.c.

    Published: 5 Nov 2018
    7.5
    High

    CVE-2018-18956

    Last Modified: 21 Nov 2024

    The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a denial of service (segfault and daemon crash) via crafted input to the SMTP parser, as exploited in the wild in November 2018.

    Published: 5 Nov 2018
    8.1
    High

    CVE-2018-18820

    Last Modified: 21 Nov 2024

    A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for that specific resource including a crafted header, leading to denial of service and potentially remote code execution.

    Published: 5 Nov 2018
    9.8
    Critical

    CVE-2018-9208

    Last Modified: 21 Nov 2024

    Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut <= v1.1Beta

    Published: 5 Nov 2018
    9.8
    Critical

    CVE-2018-18949

    Last Modified: 21 Nov 2024

    Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.

    Published: 5 Nov 2018
    7.5
    High

    CVE-2018-18950

    Last Modified: 21 Nov 2024

    KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directory in the kindeditor/attached/ folder via the path parameter without authentication.

    Published: 5 Nov 2018
    4.8
    Medium

    CVE-2018-18952

    Last Modified: 21 Nov 2024

    JEECMS 9.3 has XSS via an index.do#/content/update?type=update URI.

    Published: 5 Nov 2018
    9.1
    Critical

    CVE-2018-18933

    Last Modified: 21 Nov 2024

    The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Read Access Violation near NULL starting at FoxitReader!safe_vsnprintf+0x00000000002c4330" issue.

    Published: 5 Nov 2018
    8.8
    High

    CVE-2018-18935

    Last Modified: 21 Nov 2024

    An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as demonstrated by adding a level=1 account.

    Published: 5 Nov 2018
    7.5
    High

    CVE-2018-18936

    Last Modified: 21 Nov 2024

    An issue was discovered in PopojiCMS v2.0.1. admin_library.php allows remote attackers to delete arbitrary files via directory traversal in the po-admin/route.php?mod=library&act=delete id parameter.

    Published: 5 Nov 2018
    7.5
    High

    CVE-2018-18937

    Last Modified: 21 Nov 2024

    An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in ClientDataSet_getValues in client/ied_connection.c.

    Published: 5 Nov 2018
    4.8
    Medium

    CVE-2018-18938

    Last Modified: 5 May 2025

    An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to details/open/ within a second input field.

    Published: 5 Nov 2018
    4.8
    Medium

    CVE-2018-18939

    Last Modified: 21 Nov 2024

    An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via a seventh input field.

    Published: 5 Nov 2018
    4.8
    Medium

    CVE-2018-18943

    Last Modified: 21 Nov 2024

    An issue was discovered in baserCMS before 4.1.4. In the Register New Category feature of the Upload menu, the category name can be used for XSS via the data[UploaderCategory][name] parameter to an admin/uploader/uploader_categories/edit URI.

    Published: 5 Nov 2018
    9.8
    Critical

    CVE-2018-18934

    Last Modified: 21 Nov 2024

    An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the fupload parameter to upload a ZIP file containing arbitrary PHP code (that is extracted and can be executed). This can also be exploited via CSRF.

    Published: 5 Nov 2018