CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-18659

    Last Modified: 21 Nov 2024

    An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-19 Unauthenticated XXE in /management/UdpHttpService issue.

    Published: 26 Oct 2018
    6.1
    Medium

    CVE-2018-18660

    Last Modified: 21 Nov 2024

    An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-21 Reflected Cross-site Scripting via /authenticationendpoint/domain.jsp issue.

    Published: 26 Oct 2018
    7.8
    High

    CVE-2017-18310

    Last Modified: 21 Nov 2024

    ClientEnv exposes services 0-32 to HLOS in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_2016

    Published: 26 Oct 2018
    7.8
    High

    CVE-2018-11853

    Last Modified: 21 Nov 2024

    Lack of check on out of range for channels When processing channel list set command will lead to buffer flow in Snapdragon Mobile, Snapdragon Wear in version IPQ8074, MDM9206, MDM9607, MDM9650, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 835, SD 845, SD 850, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM710, Snapdragon_High_Med_2016

    Published: 26 Oct 2018
    5.5
    Medium

    CVE-2018-11951

    Last Modified: 21 Nov 2024

    Improper access control in core module lead XBL_LOADER performs the ZI region clear for QTEE instead of XBL_SEC in Snapdragon Mobile in version SD 845, SD 850.

    Published: 26 Oct 2018
    7.1
    High

    CVE-2017-18309

    Last Modified: 21 Nov 2024

    A micro-core of QMP transportation may cause a macro-core to read from or write to arbitrary memory in Snapdragon Mobile in version SD 845, SD 850.

    Published: 26 Oct 2018
    7.8
    High

    CVE-2017-18124

    Last Modified: 21 Nov 2024

    During secure boot, addition is performed on uint8 ptrs which led to overflow issue in Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version FSM9055, IPQ4019, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDX20

    Published: 26 Oct 2018
    7.8
    High

    CVE-2017-18308

    Last Modified: 21 Nov 2024

    Modem segments are unlocked after authentication, leaving modem segments open to all in Snapdragon Mobile, Snapdragon Wear in version MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 425, SD 430

    Published: 26 Oct 2018
    7.8
    High

    CVE-2017-18311

    Last Modified: 21 Nov 2024

    XPU Master privilege escalation is possible due to improper access control of unused configuration xPU ports where unused configuration ports are open in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_2016.

    Published: 26 Oct 2018
    7.8
    High

    CVE-2018-11305

    Last Modified: 21 Nov 2024

    When a series of FDAL messages are sent to the modem, a Use After Free condition can occur in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SDA660, SDX20.

    Published: 26 Oct 2018
    7.8
    High

    CVE-2018-11822

    Last Modified: 21 Nov 2024

    A possible integer overflow may happen in WLAN during memory allocation in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660

    Published: 26 Oct 2018
    7.8
    High

    CVE-2018-11824

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow can occur in a firmware routine in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835, SD 845, SD 850, SDA660

    Published: 26 Oct 2018
    7.5
    High

    CVE-2018-11828

    Last Modified: 21 Nov 2024

    When FW tries to get random mac address generated from new SW RNG and ADC values read are constant then DUT get struck in loop while trying to get random ADC samples in Snapdragon Mobile in version SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52

    Published: 26 Oct 2018
    4.7
    Medium

    CVE-2018-11846

    Last Modified: 21 Nov 2024

    The use of a non-time-constant memory comparison operation can lead to timing/side channel attacks in Snapdragon Mobile in version SD 210/SD 212/SD 205, SD 845, SD 850

    Published: 26 Oct 2018
    7.8
    High

    CVE-2018-11849

    Last Modified: 21 Nov 2024

    Lack of check on out of range of bssid parameter When processing scan start command will lead to buffer flow in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8996AU, QCA4531, QCA6174A, QCA6564, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, QCA9886, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDM630, SDM632, SDM636, SDM660, SDM710, SDX20, Snapdragon_High_Med_2016

    Published: 26 Oct 2018
    5.5
    Medium

    CVE-2018-18662

    Last Modified: 21 Nov 2024

    There is an out-of-bounds read in fz_run_t3_glyph in fitz/font.c in Artifex MuPDF 1.14.0, as demonstrated by mutool.

    Published: 26 Oct 2018
    7.8
    High

    CVE-2018-3588

    Last Modified: 21 Nov 2024

    There is improper access control of the SSC and GPU mapped regions which lead to inject code from HLOS in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 820, SD 820A, SD 835, SDA660.

    Published: 26 Oct 2018
    7.8
    High

    CVE-2018-5866

    Last Modified: 21 Nov 2024

    While processing logs, data is copied into a buffer pointed to by an untrusted pointer in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 835, SD 845, SD 850, SDA660.

    Published: 26 Oct 2018
    7.8
    High

    CVE-2018-5914

    Last Modified: 21 Nov 2024

    Improper input validation in TZ led to array out of bound in TZ function while accessing the peripheral details using the incoming data in Snapdragon Mobile, Snapdragon Wear version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 835, SDA660.

    Published: 26 Oct 2018
    7.8
    High

    CVE-2018-18656

    Last Modified: 21 Nov 2024

    The PureVPN client before 6.1.0 for Windows stores Login Credentials (username and password) in cleartext. The location of such files is %PROGRAMDATA%\purevpn\config\login.conf. Additionally, all local users can read this file.

    Published: 26 Oct 2018
    8.8
    High

    CVE-2018-15688

    Last Modified: 9 Jun 2025

    A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.

    Published: 26 Oct 2018
    4.3
    Medium

    CVE-2018-18655

    Last Modified: 21 Nov 2024

    Prayer through 1.3.5 sends a Referer header, containing a user's username, when a user clicks on a link in their email because header.t lacks a no-referrer setting.

    Published: 26 Oct 2018
    9.1
    Critical

    CVE-2018-18765

    Last Modified: 21 Nov 2024

    An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13. It is a heap-based buffer over-read in mg_mqtt_next_subscribe_topic. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bounds memory read potentially resulting in information disclosure and denial of service. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.

    Published: 26 Oct 2018
    7.8
    High

    CVE-2018-18653

    Last Modified: 21 Nov 2024

    The Linux kernel, as used in Ubuntu 18.10 and when booted with UEFI Secure Boot enabled, allows privileged local users to bypass intended Secure Boot restrictions and execute untrusted code by loading arbitrary kernel modules. This occurs because a modified kernel/module.c, in conjunction with certain configuration options, leads to mishandling of the result of signature verification.

    Published: 26 Oct 2018
    9.1
    Critical

    CVE-2018-18764

    Last Modified: 21 Nov 2024

    An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13. It is a heap-based buffer over-read in a parse_mqtt getu16 call. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bounds memory read potentially resulting in information disclosure and denial of service. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.

    Published: 26 Oct 2018
    7.8
    High

    CVE-2018-15686

    Last Modified: 9 Jun 2025

    A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.

    Published: 26 Oct 2018
    7
    High

    CVE-2018-15687

    Last Modified: 9 Jun 2025

    A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239.

    Published: 26 Oct 2018
    7.8
    High

    CVE-2018-18654

    Last Modified: 21 Nov 2024

    Crossroads 2.81 does not properly handle the /tmp directory during a build of xr. A local attacker can first create a world-writable subdirectory in a certain location under the /tmp directory, wait until a user process copies xr there, and then replace the entire contents of this subdirectory to include a Trojan horse xr.

    Published: 26 Oct 2018
    7.2
    High

    CVE-2018-18652

    Last Modified: 21 Nov 2024

    A remote command execution vulnerability in Veritas NetBackup Appliance before 3.1.2 allows authenticated administrators to execute arbitrary commands as root. This issue was caused by insufficient filtering of user provided input.

    Published: 25 Oct 2018
    6.1
    Medium

    CVE-2018-17904

    Last Modified: 21 Nov 2024

    Reliance 4 SCADA/HMI, Version 4.7.3 Update 3 and prior. This vulnerability could allow an unauthorized attacker to inject arbitrary code.

    Published: 25 Oct 2018
    5.5
    Medium

    CVE-2018-3970

    Last Modified: 21 Nov 2024

    An exploitable memory disclosure vulnerability exists in the 0x222000 IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially crafted IRP request can cause the driver to return uninitialized memory, resulting in kernel memory disclosure. An attacker can send an IRP request to trigger this vulnerability.

    Published: 25 Oct 2018
    7.8
    High

    CVE-2018-3971

    Last Modified: 21 Nov 2024

    An exploitable arbitrary write vulnerability exists in the 0x2222CC IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially crafted IRP request can cause the driver to write data under controlled by an attacker address, resulting in memory corruption. An attacker can send IRP request to trigger this vulnerability.

    Published: 25 Oct 2018
    6.6
    Medium

    CVE-2018-14665

    Last Modified: 29 Aug 2025

    A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.

    Published: 25 Oct 2018
    5.5
    Medium

    CVE-2018-18650

    Last Modified: 21 Nov 2024

    An issue was discovered in Xpdf 4.00. XRef::readXRefStream in XRef.cc allows attackers to launch a denial of service (Integer Overflow) via a crafted /Size value in a pdf file, as demonstrated by pdftohtml. This is mainly caused by the program attempting a malloc operation for a large amount of memory.

    Published: 25 Oct 2018
    5.5
    Medium

    CVE-2018-18651

    Last Modified: 21 Nov 2024

    An issue was discovered in Xpdf 4.00. catalog->getNumPages() in AcroForm.cc allows attackers to launch a denial of service (hang caused by large loop) via a specific pdf file, as demonstrated by pdftohtml. This is mainly caused by a large number after the /Count field in the file.

    Published: 25 Oct 2018
    5.5
    Medium

    CVE-2018-18849

    Last Modified: 21 Nov 2024

    In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.

    Published: 25 Oct 2018
    6.5
    Medium

    CVE-2018-18661

    Last Modified: 21 Nov 2024

    An issue was discovered in LibTIFF 4.0.9. There is a NULL pointer dereference in the function LZWDecode in the file tif_lzw.c.

    Published: 25 Oct 2018
    5.9
    Medium

    CVE-2018-0735

    Last Modified: 21 Nov 2024

    The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).

    Published: 25 Oct 2018
    9.8
    Critical

    CVE-2018-13342

    Last Modified: 21 Nov 2024

    The server API in the Anda app relies on hardcoded credentials.

    Published: 24 Oct 2018
    5.3
    Medium

    CVE-2018-15750

    Last Modified: 21 Nov 2024

    Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.

    Published: 24 Oct 2018
    9.1
    Critical

    CVE-2018-17903

    Last Modified: 21 Nov 2024

    SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to a replay attack and command forgery.

    Published: 24 Oct 2018
    6.9
    Medium

    CVE-2018-17923

    Last Modified: 21 Nov 2024

    SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that an attacker with physical access to the product may able to reprogram it.

    Published: 24 Oct 2018
    6.1
    Medium

    CVE-2018-18551

    Last Modified: 21 Nov 2024

    ServersCheck Monitoring Software through 14.3.3 has Persistent and Reflected XSS via the sensors.html status parameter, sensors.html type parameter, sensors.html device parameter, report.html location parameter, group_delete.html group parameter, report_save.html query parameter, sensors.html location parameter, or group_delete.html group parameter.

    Published: 24 Oct 2018
    5.3
    Medium

    CVE-2018-18566

    Last Modified: 21 Nov 2024

    The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Business.

    Published: 24 Oct 2018
    5.9
    Medium

    CVE-2018-18568

    Last Modified: 21 Nov 2024

    Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to validate X.509 certificates when used with an on-premise installation with Skype for Business.

    Published: 24 Oct 2018
    6.1
    Medium

    CVE-2018-18621

    Last Modified: 21 Nov 2024

    CommuniGate Pro 6.2 allows stored XSS via a message body in Pronto! Mail Composer, which is mishandled in /MIME/INBOX-MM-1/ if the raw email link (in .txt format) is modified and then renamed with a .html or .wssp extension.

    Published: 24 Oct 2018
    8.1
    High

    CVE-2018-18638

    Last Modified: 21 Nov 2024

    A command injection vulnerability in the setup API in the Neato Botvac Connected 2.2.0 allows network attackers to execute arbitrary commands via shell metacharacters in the ntp field within JSON data to the /robot/initialize endpoint.

    Published: 24 Oct 2018
    9.8
    Critical

    CVE-2018-8955

    Last Modified: 21 Nov 2024

    The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remote attackers to execute arbitrary code by changing the filename while leaving the file's digital signature unchanged.

    Published: 24 Oct 2018
    9.8
    Critical

    CVE-2018-15751

    Last Modified: 21 Nov 2024

    SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).

    Published: 24 Oct 2018
    8.8
    High

    CVE-2018-17921

    Last Modified: 21 Nov 2024

    SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that may allow an attacker to force-pair the device without human interaction.

    Published: 24 Oct 2018