CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-11862

    Last Modified: 21 Nov 2024

    Buffer overflow can happen in WLAN module due to lack of validation of the input length in Snapdragon Mobile in version SD 845, SD 850, SDA660.

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11867

    Last Modified: 21 Nov 2024

    Lack of buffer length check before copying in WLAN function while processing FIPS event, can lead to a buffer overflow in Snapdragon Mobile in version SD 845.

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11871

    Last Modified: 21 Nov 2024

    Buffer overwrite can happen in WLAN function while processing set pdev parameter command due to lack of input validation in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version IPQ4019, IPQ8064, IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8996AU, QCA6174A, QCA6564, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, QCA9531, QCA9558, QCA9563, QCA9880, QCA9886, QCA9980, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDM630, SDM632, SDM636, SDM660, SDM710, SDX20, Snapdragon_High_Med_2016.

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11875

    Last Modified: 21 Nov 2024

    Lack of check of buffer size before copying in a WLAN function can lead to a buffer overflow in Snapdragon Mobile in version SD 845, SD 850.

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11877

    Last Modified: 21 Nov 2024

    When the buffer length passed is very large in WLAN, bounds check could be bypassed leading to potential buffer overwrite in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11880

    Last Modified: 21 Nov 2024

    Incorrect bound check can lead to potential buffer overwrite in WLAN function in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11882

    Last Modified: 21 Nov 2024

    Incorrect bound check can lead to potential buffer overwrite in WLAN controller in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11884

    Last Modified: 21 Nov 2024

    Improper input validation leads to buffer overflow while processing network list offload command in WLAN function in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-17908

    Last Modified: 21 Nov 2024

    WebAccess Versions 8.3.2 and prior. During installation, the application installer disables user access control and does not re-enable it after the installation is complete. This could allow an attacker to run elevated arbitrary code.

    Published: 29 Oct 2018
    8.8
    High

    CVE-2018-18387

    Last Modified: 21 Nov 2024

    playSMS through 1.4.2 allows Privilege Escalation through Daemon abuse.

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11858

    Last Modified: 21 Nov 2024

    When processing IE set command, buffer overwrite may occur due to lack of input validation of the IE length in Snapdragon Mobile in version SD 835, SD 845, SD 850.

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11861

    Last Modified: 21 Nov 2024

    Buffer overflow can happen in WLAN function due to lack of validation of the input length in Snapdragon Mobile in version SD 845, SD 850, SDA660.

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11872

    Last Modified: 21 Nov 2024

    Improper input validation leads to buffer overwrite in the WLAN function that handles WMI commands in Snapdragon Mobile in version SD 845, SD 850, SDA660

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11866

    Last Modified: 21 Nov 2024

    Integer overflow may happen in WLAN when calculating an internal structure size due to lack of validation of the input length in Snapdragon Mobile, Snapdragon Wear in version IPQ8074, MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 835, SD 845, SD 850, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM710, Snapdragon_High_Med_2016.

    Published: 29 Oct 2018
    5.5
    Medium

    CVE-2017-18281

    Last Modified: 21 Nov 2024

    A bool variable in Video function, which gets typecasted to int before being read could result in an out of bound read access in all Android releases from CAF using the linux kernel

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11876

    Last Modified: 21 Nov 2024

    Lack of input validation while copying to buffer in WLAN will lead to a buffer overflow in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11859

    Last Modified: 21 Nov 2024

    Buffer overwrite can happen in WLAN due to lack of validation of the input length in Snapdragon Mobile in version SD 845, SD 850.

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11865

    Last Modified: 21 Nov 2024

    Integer overflow may happen when calculating an internal structure size due to lack of validation of the input length in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 835, SD 845, SD 850, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM710, Snapdragon_High_Med_2016.

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11870

    Last Modified: 21 Nov 2024

    Buffer overwrite can occur when the legacy rates count received from the host is not checked against the maximum number of legacy rates in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8996AU, QCA4531, QCA6174A, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, SD 210/SD 212/SD 205, SD 425, SD 600, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDX20.

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11873

    Last Modified: 21 Nov 2024

    Improper input validation leads to buffer overwrite in the WLAN function that handles WLAN roam buffer in Snapdragon Mobile in version SD 845.

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11874

    Last Modified: 21 Nov 2024

    Buffer overflow if the length of passphrase is more than 32 when setting up secure NDP connection in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-11879

    Last Modified: 21 Nov 2024

    When the buffer length passed is very large, bounds check could be bypassed leading to potential buffer overwrite in Snapdragon Mobile in version SD 845

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-17910

    Last Modified: 21 Nov 2024

    WebAccess Versions 8.3.2 and prior. The application fails to properly validate the length of user-supplied data, causing a buffer overflow condition that allows for arbitrary remote code execution.

    Published: 29 Oct 2018
    2.7
    Low

    CVE-2018-1380

    Last Modified: 21 Nov 2024

    IBM InfoSphere Master Data Management Collaboration Server 11.4, 11.5, and 11.6 could allow an authenticated user with CA level access to change change their ca-id to another users and read sensitive information. IBM X-Force ID: 138077.

    Published: 29 Oct 2018
    5.4
    Medium

    CVE-2018-1766

    Last Modified: 21 Nov 2024

    IBM Team Concert (RTC) 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148620.

    Published: 29 Oct 2018
    6.1
    Medium

    CVE-2018-1767

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148621.

    Published: 29 Oct 2018
    6.1
    Medium

    CVE-2018-18781

    Last Modified: 21 Nov 2024

    DedeCMS 5.7 SP2 allows XSS via the /member/uploads_select.php f or keyword parameter.

    Published: 29 Oct 2018
    6.1
    Medium

    CVE-2018-18782

    Last Modified: 21 Nov 2024

    Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.

    Published: 29 Oct 2018
    6.1
    Medium

    CVE-2018-18783

    Last Modified: 21 Nov 2024

    XSS was discovered in SEMCMS V3.4 via the semcms_remail.php?type=ok umail parameter.

    Published: 29 Oct 2018
    7.2
    High

    CVE-2018-18784

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 8.3. SQL Injection exists in admin/tagmanage.php via the tabletag parameter. (This needs an admin user login.)

    Published: 29 Oct 2018
    9.8
    Critical

    CVE-2018-18785

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php.

    Published: 29 Oct 2018
    9.8
    Critical

    CVE-2018-18786

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.

    Published: 29 Oct 2018
    7.2
    High

    CVE-2018-18788

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 8.3. SQL Injection exists in admin/classmanage.php via the tablename parameter. (This needs an admin user login.)

    Published: 29 Oct 2018
    9.8
    Critical

    CVE-2018-18791

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie.

    Published: 29 Oct 2018
    9.8
    Critical

    CVE-2018-18792

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie.

    Published: 29 Oct 2018
    9.8
    Critical

    CVE-2018-18787

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie.

    Published: 29 Oct 2018
    9.8
    Critical

    CVE-2018-18789

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php.

    Published: 29 Oct 2018
    7.2
    High

    CVE-2018-18790

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 8.3. SQL Injection exists in admin/special_add.php via a zxbigclassid cookie. (This needs an admin user login.)

    Published: 29 Oct 2018
    6.5
    Medium

    CVE-2018-18778

    Last Modified: 21 Nov 2024

    ACME mini_httpd before 1.30 lets remote users read arbitrary files.

    Published: 29 Oct 2018
    7.5
    High

    CVE-2018-18771

    Last Modified: 21 Nov 2024

    An issue was discovered in LuLu CMS through 2015-05-14. backend\modules\filemanager\controllers\DefaultController.php allows arbitrary file upload by entering a filename, directory name, and PHP code into the three text input fields.

    Published: 29 Oct 2018
    8.8
    High

    CVE-2018-1000866

    Last Modified: 21 Nov 2024

    A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java, groovy-cps/lib/src/main/java/com/cloudbees/groovy/cps/SandboxCpsTransformer.java that allows attackers with Job/Configure permission, or unauthorized attackers with SCM commit privileges and corresponding pipelines based on Jenkinsfiles set up in Jenkins, to execute arbitrary code on the Jenkins master JVM

    Published: 29 Oct 2018
    5.5
    Medium

    CVE-2018-19213

    Last Modified: 21 Nov 2024

    Netwide Assembler (NASM) through 2.14rc16 has memory leaks that may lead to DoS, related to nasm_malloc in nasmlib/malloc.c.

    Published: 29 Oct 2018
    6.5
    Medium

    CVE-2018-19758

    Last Modified: 21 Nov 2024

    There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service.

    Published: 29 Oct 2018
    8.8
    High

    CVE-2018-1000865

    Last Modified: 21 Nov 2024

    A sandbox bypass vulnerability exists in Script Security Plugin 1.47 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java that allows attackers with Job/Configure permission to execute arbitrary code on the Jenkins master JVM, if plugins using the Groovy sandbox are installed.

    Published: 29 Oct 2018
    7.8
    High

    CVE-2018-19215

    Last Modified: 21 Nov 2024

    Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and ! characters.

    Published: 29 Oct 2018
    9.8
    Critical

    CVE-2018-18752

    Last Modified: 21 Nov 2024

    Webiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/WsSaveToModel.php logo parameter.

    Published: 28 Oct 2018
    9.8
    Critical

    CVE-2018-18754

    Last Modified: 21 Nov 2024

    ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file.

    Published: 28 Oct 2018
    9.8
    Critical

    CVE-2018-18753

    Last Modified: 21 Nov 2024

    Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.

    Published: 28 Oct 2018
    5.4
    Medium

    CVE-2018-18733

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in Catfish CMS 4.8.30, related to "write source code," a similar issue to CVE-2018-13999.

    Published: 28 Oct 2018
    5.4
    Medium

    CVE-2018-18736

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in catfish blog 2.0.33, related to "write source code."

    Published: 28 Oct 2018