CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2018-3900

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. An attacker can make the camera scan a QR code to trigger this vulnerability. Alternatively, a user could be convinced to display a QR code from the internet to their camera, which could exploit this vulnerability.

    Published: 1 Nov 2018
    8
    High

    CVE-2018-3910

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the cloud OTA setup functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted SSID can cause a command injection, resulting in code execution. An attacker can cause a camera to connect to this SSID to trigger this vulnerability. Alternatively, an attacker can convince a user to connect their camera to this SSID.

    Published: 1 Nov 2018
    7.5
    High

    CVE-2018-3928

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can cause a settings change, resulting in denial of service. An attacker can send a set of packets to trigger this vulnerability.

    Published: 1 Nov 2018
    8.8
    High

    CVE-2018-3977

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.3. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.

    Published: 1 Nov 2018
    8.1
    High

    CVE-2018-3947

    Last Modified: 21 Nov 2024

    An exploitable information disclosure vulnerability exists in the phone-to-camera communications of Yi Home Camera 27US 1.8.7.0D. An attacker can sniff network traffic to exploit this vulnerability.

    Published: 1 Nov 2018
    5.6
    Medium

    CVE-2018-7356

    Last Modified: 21 Nov 2024

    All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vulnerability, which can generate easily predictable ISN, and allows remote attackers to spoof connections.

    Published: 1 Nov 2018
    7.5
    High

    CVE-2016-2120

    Last Modified: 21 Nov 2024

    An issue has been found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 allowing an authorized user to crash the server by inserting a specially crafted record in a zone under their control then sending a DNS query for that record. The issue is due to an integer overflow when checking if the content of the record matches the expected size, allowing an attacker to cause a read past the buffer boundary.

    Published: 1 Nov 2018
    8.6
    High

    CVE-2018-15454

    Last Modified: 11 Aug 2026

    A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload or trigger high CPU, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of SIP traffic. An attacker could exploit this vulnerability by sending SIP requests designed to specifically trigger this issue at a high rate across an affected device. Software updates that address this vulnerability are not yet available.

    Published: 1 Nov 2018
    9.8
    Critical

    CVE-2018-18887

    Last Modified: 21 Nov 2024

    S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).

    Published: 1 Nov 2018
    9.8
    Critical

    CVE-2018-18888

    Last Modified: 21 Nov 2024

    An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upload of arbitrary PHP files because the file extension is not properly checked and uploaded files are not properly renamed.

    Published: 1 Nov 2018
    5.3
    Medium

    CVE-2018-18890

    Last Modified: 21 Nov 2024

    MiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename.

    Published: 1 Nov 2018
    9.8
    Critical

    CVE-2018-18892

    Last Modified: 21 Nov 2024

    MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php.

    Published: 1 Nov 2018
    7.5
    High

    CVE-2018-18891

    Last Modified: 21 Nov 2024

    MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs too late.

    Published: 1 Nov 2018
    7.8
    High

    CVE-2018-16847

    Last Modified: 21 Nov 2024

    An OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU. It could occur in nvme_cmb_ops routines in nvme device. A guest user/process could use this flaw to crash the QEMU process resulting in DoS or potentially run arbitrary code with privileges of the QEMU process.

    Published: 1 Nov 2018
    6.5
    Medium

    CVE-2018-18897

    Last Modified: 21 Nov 2024

    An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo.

    Published: 1 Nov 2018
    6.5
    Medium

    CVE-2018-15705

    Last Modified: 21 Nov 2024

    WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API. An attacker can use this vulnerability to remotely execute arbitrary code.

    Published: 31 Oct 2018
    6.5
    Medium

    CVE-2018-15706

    Last Modified: 21 Nov 2024

    WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal vulnerability in the readFile API.

    Published: 31 Oct 2018
    5.4
    Medium

    CVE-2018-15707

    Last Modified: 21 Nov 2024

    Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things.

    Published: 31 Oct 2018
    4.3
    Medium

    CVE-2018-13281

    Last Modified: 14 Jan 2025

    Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the file_path parameter.

    Published: 31 Oct 2018
    5.6
    Medium

    CVE-2018-13282

    Last Modified: 21 Nov 2024

    Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

    Published: 31 Oct 2018
    9.8
    Critical

    CVE-2018-18874

    Last Modified: 21 Nov 2024

    nc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, with a .php filename and "Content-Type: application/octet-stream" to the index.php?action=file_manager_upload URI.

    Published: 31 Oct 2018
    7.5
    High

    CVE-2018-15326

    Last Modified: 21 Nov 2024

    In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.2, the CRLDP Auth access policy agent may treat revoked certificates as valid when the BIG-IP APM system fails to download a new Certificate Revocation List.

    Published: 31 Oct 2018
    5.9
    Medium

    CVE-2018-15323

    Last Modified: 21 Nov 2024

    On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, in certain circumstances, when processing traffic through a Virtual Server with an associated MQTT profile, the TMM process may produce a core file and take the configured HA action.

    Published: 31 Oct 2018
    5.9
    Medium

    CVE-2018-15324

    Last Modified: 21 Nov 2024

    On BIG-IP APM 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, TMM may restart when processing a specially crafted request with APM portal access.

    Published: 31 Oct 2018
    7.5
    High

    CVE-2018-15319

    Last Modified: 21 Nov 2024

    On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.6, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is exposed with the non-default "normalize URI" configuration options used in iRules and/or BIG-IP LTM policies.

    Published: 31 Oct 2018
    4.9
    Medium

    CVE-2018-15321

    Last Modified: 21 Nov 2024

    When BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-IQ Centralized Management 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, iWorkflow 2.1.0-2.3.0, or Enterprise Manager 3.1.1 is licensed for Appliance Mode, Admin and Resource administrator roles can by-pass BIG-IP Appliance Mode restrictions to overwrite critical system files. Attackers of high privilege level are able to overwrite critical system files which bypasses security controls in place to limit TMSH commands. This is possible with an administrator or resource administrator roles when granted TMSH. Resource administrator roles must have TMSH access in order to perform this attack.

    Published: 31 Oct 2018
    7.2
    High

    CVE-2018-15327

    Last Modified: 21 Nov 2024

    In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1 or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.

    Published: 31 Oct 2018
    7.5
    High

    CVE-2018-15317

    Last Modified: 21 Nov 2024

    In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.2.1-11.6.3.2, an attacker sending specially crafted SSL records to a SSL Virtual Server will cause corruption in the SSL data structures leading to intermittent decrypt BAD_RECORD_MAC errors. Clients will be unable to access the application load balanced by a virtual server with an SSL profile until tmm is restarted.

    Published: 31 Oct 2018
    7.5
    High

    CVE-2018-15318

    Last Modified: 21 Nov 2024

    In BIG-IP 14.0.0-14.0.0.2, 13.1.0.4-13.1.1.1, or 12.1.3.4-12.1.3.6, If an MPTCP connection receives an abort signal while the initial flow is not the primary flow, the initial flow will remain after the closing procedure is complete. TMM may restart and produce a core file as a result of this condition.

    Published: 31 Oct 2018
    7.5
    High

    CVE-2018-15320

    Last Modified: 21 Nov 2024

    On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, undisclosed traffic patterns may lead to denial of service conditions for the BIG-IP system. The configuration which exposes this condition is the BIG-IP self IP address which is part of a VLAN group and has the Port Lockdown setting configured with anything other than "allow-all".

    Published: 31 Oct 2018
    6.5
    Medium

    CVE-2018-15322

    Last Modified: 21 Nov 2024

    On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-IQ Centralized Management 6.0.0-6.0.1, 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, iWorkflow 2.0.1-2.3.0, or Enterprise Manager 3.1.1 a BIG-IP user granted with tmsh access may cause the BIG-IP system to experience denial-of-service (DoS) when the BIG-IP user uses the tmsh utility to run the edit cli preference command and proceeds to save the changes to another filename repeatedly. This action utilises storage space on the /var partition and when performed repeatedly causes the /var partition to be full.

    Published: 31 Oct 2018
    4.3
    Medium

    CVE-2018-15325

    Last Modified: 21 Nov 2024

    In BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, iControl and TMSH usage by authenticated users may leak a small amount of memory when executing commands

    Published: 31 Oct 2018
    7.3
    High

    CVE-2018-1851

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server Liberty OpenID Connect could allow a remote attacker to execute arbitrary code on the system, caused by improper deserialization. By sending a specially-crafted request to the RP service, an attacker could exploit this vulnerability to execute arbitrary code. IBM X-Force ID: 150999.

    Published: 31 Oct 2018
    6.5
    Medium

    CVE-2018-14654

    Last Modified: 21 Nov 2024

    The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volumes could exploit this via the 'GF_XATTROP_ENTRY_IN_KEY' xattrop to create arbitrary, empty files on the target server.

    Published: 31 Oct 2018
    8.8
    High

    CVE-2018-14651

    Last Modified: 21 Nov 2024

    It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of these flaws to execute arbitrary code, create arbitrary files, or cause denial of service on glusterfs server nodes via symlinks to relative paths.

    Published: 31 Oct 2018
    6.5
    Medium

    CVE-2018-14652

    Last Modified: 21 Nov 2024

    The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling the 'GF_XATTR_CLRLK_CMD' xattr in the 'pl_getxattr' function. A remote authenticated attacker could exploit this on a mounted volume to cause a denial of service.

    Published: 31 Oct 2018
    6.5
    Medium

    CVE-2018-14659

    Last Modified: 21 Nov 2024

    The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr. A remote, authenticated attacker could exploit this by mounting a Gluster volume and repeatedly calling 'setxattr(2)' to trigger a state dump and create an arbitrary number of files in the server's runtime directory.

    Published: 31 Oct 2018
    6.5
    Medium

    CVE-2018-14660

    Last Modified: 21 Nov 2024

    A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitively resulting in memory exhaustion of glusterfs server node.

    Published: 31 Oct 2018
    6.5
    Medium

    CVE-2018-14661

    Last Modified: 21 Nov 2024

    It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vulnerable to a format string attack. A remote, authenticated attacker could use this flaw to cause remote denial of service.

    Published: 31 Oct 2018
    8.8
    High

    CVE-2018-14653

    Last Modified: 21 Nov 2024

    The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_getspec_req' RPC message. A remote authenticated attacker could exploit this to cause a denial of service or other potential unspecified impact.

    Published: 31 Oct 2018
    6.1
    Medium

    CVE-2018-18868

    Last Modified: 21 Nov 2024

    No-CMS 1.1.3 is prone to Persistent XSS via a contact_us name parameter, as demonstrated by the VG48Z5PqVWname parameter.

    Published: 31 Oct 2018
    9.8
    Critical

    CVE-2018-18869

    Last Modified: 21 Nov 2024

    EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter.

    Published: 31 Oct 2018
    7.5
    High

    CVE-2018-18853

    Last Modified: 21 Nov 2024

    Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of a field composed of many decimal digits.

    Published: 31 Oct 2018
    7.5
    High

    CVE-2018-18854

    Last Modified: 21 Nov 2024

    Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of many JSON object fields (with keys that have the same hash code).

    Published: 31 Oct 2018
    8.6
    High

    CVE-2018-18867

    Last Modified: 21 Nov 2024

    An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-15495.

    Published: 31 Oct 2018
    8.8
    High

    CVE-2018-18850

    Last Modified: 21 Nov 2024

    In Octopus Deploy 2018.8.0 through 2018.9.x before 2018.9.1, an authenticated user with permission to modify deployment processes could upload a maliciously crafted YAML configuration, potentially allowing for remote execution of arbitrary code, running in the same context as the Octopus Server (for self-hosted installations by default, SYSTEM).

    Published: 31 Oct 2018
    5.3
    Medium

    CVE-2018-20852

    Last Modified: 21 Nov 2024

    http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by using a server with a hostname that has another valid hostname as a suffix (e.g., pythonicexample.com to steal cookies for example.com). When a program uses http.cookiejar.DefaultPolicy and tries to do an HTTP connection to an attacker-controlled server, existing cookies can be leaked to the attacker. This affects 2.x through 2.7.16, 3.x before 3.4.10, 3.5.x before 3.5.7, 3.6.x before 3.6.9, and 3.7.x before 3.7.3.

    Published: 31 Oct 2018
    5.5
    Medium

    CVE-2018-18873

    Last Modified: 21 Nov 2024

    An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c.

    Published: 31 Oct 2018
    9.8
    Critical

    CVE-2018-16840

    Last Modified: 16 Apr 2026

    A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and cleaning up an 'easy' handle in the `Curl_close()` function, the library code first frees a struct (without nulling the pointer) and might then subsequently erroneously write to a struct field within that already freed struct.

    Published: 31 Oct 2018
    6.1
    Medium

    CVE-2018-19131

    Last Modified: 21 Nov 2024

    Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.

    Published: 31 Oct 2018