CVE Feed

    Dashboard / CVE

    4.7
    Medium

    CVE-2018-18398

    Last Modified: 21 Nov 2024

    Xfce Thunar 1.6.15, when Xfce 4.12 is used, mishandles the IBus-Unikey input method for file searches within File Manager, leading to an out-of-bounds read and SEGV. This could potentially be exploited by an arbitrary local user who creates files in /tmp before the victim uses this input method.

    Published: 19 Oct 2018
    9.8
    Critical

    CVE-2018-18529

    Last Modified: 21 Nov 2024

    ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles the key variable. NOTE: a backquote character is not required in the attack URI.

    Published: 19 Oct 2018
    9.8
    Critical

    CVE-2018-18531

    Last Modified: 21 Nov 2024

    text/impl/DefaultTextCreator.java, text/impl/ChineseTextProducer.java, and text/impl/FiveLetterFirstNameTextCreator.java in kaptcha 2.3.2 use the Random (rather than SecureRandom) function for generating CAPTCHA values, which makes it easier for remote attackers to bypass intended access restrictions via a brute-force approach.

    Published: 19 Oct 2018
    9.8
    Critical

    CVE-2018-18530

    Last Modified: 21 Nov 2024

    ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregate variable. NOTE: a backquote character is required in the attack URI.

    Published: 19 Oct 2018
    5.4
    Medium

    CVE-2018-18380

    Last Modified: 21 Nov 2024

    A Session Fixation issue was discovered in Bigtree before 4.2.24. admin.php accepts a user-provided PHP session ID instead of regenerating a new one after a user has logged in to the application. The Session Fixation could allow an attacker to hijack an admin session.

    Published: 19 Oct 2018
    9.8
    Critical

    CVE-2018-18527

    Last Modified: 21 Nov 2024

    OwnTicket 2018-05-23 allows SQL Injection via the showTicketId or editTicketStatusId parameter.

    Published: 19 Oct 2018
    8.8
    High

    CVE-2018-18391

    Last Modified: 21 Nov 2024

    User Privilege Escalation in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

    Published: 19 Oct 2018
    8.8
    High

    CVE-2018-18392

    Last Modified: 21 Nov 2024

    Privilege Escalation via Broken Access Control in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

    Published: 19 Oct 2018
    9.8
    Critical

    CVE-2018-18394

    Last Modified: 21 Nov 2024

    Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

    Published: 19 Oct 2018
    9.8
    Critical

    CVE-2018-18395

    Last Modified: 21 Nov 2024

    Hidden Token Access in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

    Published: 19 Oct 2018
    9.8
    Critical

    CVE-2018-18396

    Last Modified: 21 Nov 2024

    Remote Code Execution in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

    Published: 19 Oct 2018
    9.8
    Critical

    CVE-2018-18393

    Last Modified: 21 Nov 2024

    Password Management Issue in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

    Published: 19 Oct 2018
    7.5
    High

    CVE-2018-18390

    Last Modified: 21 Nov 2024

    User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

    Published: 19 Oct 2018
    6.1
    Medium

    CVE-2018-15313

    Last Modified: 21 Nov 2024

    On F5 BIG-IP AFM 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there is a Reflected Cross Site Scripting vulnerability in undisclosed TMUI page.

    Published: 19 Oct 2018
    6.1
    Medium

    CVE-2018-15314

    Last Modified: 21 Nov 2024

    On F5 BIG-IP AFM 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there is a Reflected Cross Site Scripting vulnerability in undisclosed TMUI page.

    Published: 19 Oct 2018
    5.5
    Medium

    CVE-2018-15316

    Last Modified: 21 Nov 2024

    In F5 BIG-IP APM 13.0.0-13.1.1.1, APM Client 7.1.5-7.1.6, and/or Edge Client 7101-7160, the BIG-IP APM Edge Client component loads the policy library with user permission and bypassing the endpoint checks.

    Published: 19 Oct 2018
    9.8
    Critical

    CVE-2018-4013

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.

    Published: 19 Oct 2018
    6.1
    Medium

    CVE-2018-15312

    Last Modified: 21 Nov 2024

    On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an authenticated user to execute JavaScript for the currently logged-in user.

    Published: 19 Oct 2018
    6.1
    Medium

    CVE-2018-15315

    Last Modified: 21 Nov 2024

    On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there is a reflected Cross Site Scripting (XSS) vulnerability in an undisclosed Configuration Utility page.

    Published: 19 Oct 2018
    7
    High

    CVE-2017-18348

    Last Modified: 21 Nov 2024

    Splunk Enterprise 6.6.x, when configured to run as root but drop privileges to a specific non-root account, allows local users to gain privileges by leveraging access to that non-root account to modify $SPLUNK_HOME/etc/splunk-launch.conf and insert Trojan horse programs into $SPLUNK_HOME/bin, because the non-root setup instructions state that chown should be run across all of $SPLUNK_HOME to give non-root access.

    Published: 19 Oct 2018
    6.5
    Medium

    CVE-2018-18544

    Last Modified: 21 Nov 2024

    There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScript of coders/msl.c in GraphicsMagick before 1.3.31.

    Published: 19 Oct 2018
    3.4
    Low

    CVE-2018-15765

    Last Modified: 21 Nov 2024

    Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability. The log file contents store sensitive data including executed commands to generate authentication tokens which may prove useful to an attacker for crafting malicious authentication tokens for querying the application and subsequent attacks.

    Published: 18 Oct 2018
    5.5
    Medium

    CVE-2018-11079

    Last Modified: 21 Nov 2024

    Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored in plaintext in a configuration file. An authenticated malicious user with access to the configuration file may obtain the exposed password to gain access to the application database.

    Published: 18 Oct 2018
    7.3
    High

    CVE-2018-11080

    Last Modified: 21 Nov 2024

    Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains Improper File Permission Vulnerabilities. The application contains multiple configuration files with world-readable permissions that could allow an authenticated malicious user to utilize the file contents to potentially elevate their privileges.

    Published: 18 Oct 2018
    9.8
    Critical

    CVE-2018-14807

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow vulnerability in Opto 22 PAC Control Basic and PAC Control Professional versions R10.0a and prior may allow remote code execution.

    Published: 18 Oct 2018
    7.5
    High

    CVE-2018-18487

    Last Modified: 21 Nov 2024

    In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, the database backup filename generation uses mt_rand() unsafely, resulting in predictable database backup file locations.

    Published: 18 Oct 2018
    9.8
    Critical

    CVE-2018-18488

    Last Modified: 21 Nov 2024

    In \lib\admin\action\dataaction.class.php in Gxlcms v2.0, SQL Injection exists via the ids[] parameter.

    Published: 18 Oct 2018
    7.5
    High

    CVE-2018-18485

    Last Modified: 21 Nov 2024

    An issue was discovered in PHPSHE 1.7. admin.php?mod=db&act=del allows remote attackers to delete arbitrary files via directory traversal sequences in the dbname parameter. This can be leveraged to reload the product by deleting install.lock.

    Published: 18 Oct 2018
    9.8
    Critical

    CVE-2018-18486

    Last Modified: 21 Nov 2024

    An issue was discovered in PHPSHE 1.7. SQL injection exists via the admin.php?mod=user&act=del user_id[] parameter.

    Published: 18 Oct 2018
    8
    High

    CVE-2015-4630

    Last Modified: 21 Nov 2024

    Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to (1) hijack the authentication of administrators for requests that create a user via a request to members/memberentry.pl or (2) give a user superlibrarian permission via a request to members/member-flags.pl or (3) hijack the authentication of arbitrary users for requests that conduct cross-site scripting (XSS) attacks via the addshelf parameter to opac-shelves.pl.

    Published: 18 Oct 2018
    5.4
    Medium

    CVE-2015-4631

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to inject arbitrary web script or HTML via the (1) tag parameter to opac-search.pl; the (2) value parameter to authorities/authorities-home.pl; the (3) delay parameter to acqui/lateorders.pl; the (4) authtypecode or (5) tagfield to admin/auth_subfields_structure.pl; the (6) tagfield parameter to admin/marc_subfields_structure.pl; the (7) limit parameter to catalogue/search.pl; the (8) bookseller_filter, (9) callnumber_filter, (10) EAN_filter, (11) ISSN_filter, (12) publisher_filter, or (13) title_filter parameter to serials/serials-search.pl; or the (14) author, (15) collectiontitle, (16) copyrightdate, (17) isbn, (18) manageddate_from, (19) manageddate_to, (20) publishercode, (21) suggesteddate_from, or (22) suggesteddate_to parameter to suggestion/suggestion.pl; or the (23) direction, (24) display or (25) addshelf parameter to opac-shelves.pl.

    Published: 18 Oct 2018
    9.8
    Critical

    CVE-2015-4633

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface.

    Published: 18 Oct 2018
    7.5
    High

    CVE-2015-4632

    Last Modified: 21 Nov 2024

    Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the template_path parameter to (1) svc/virtualshelves/search or (2) svc/members/search.

    Published: 18 Oct 2018
    6.5
    Medium

    CVE-2018-18480

    Last Modified: 21 Nov 2024

    A heap-based buffer over-read exists in libopencad 0.2.0 in the ReadMCHAR function in lib/dwg/io.cpp, resulting in an application crash.

    Published: 18 Oct 2018
    6.5
    Medium

    CVE-2018-18481

    Last Modified: 21 Nov 2024

    A heap-based buffer over-read exists in libopencad 0.2.0 in the ReadCHAR function in lib/dwg/io.cpp, resulting in an application crash.

    Published: 18 Oct 2018
    6.5
    Medium

    CVE-2018-18482

    Last Modified: 21 Nov 2024

    An issue was discovered in libpg_query 10-1.0.2. There is a memory leak in pg_query_raw_parse in pg_query_parse.c, which might lead to a denial of service.

    Published: 18 Oct 2018
    6.1
    Medium

    CVE-2018-18478

    Last Modified: 21 Nov 2024

    Persistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web script or HTML via the dashboard_name parameter in the /ajax_form.php resource, related to html/includes/forms/add-dashboard.inc.php, html/includes/forms/delete-dashboard.inc.php, and html/includes/forms/edit-dashboard.inc.php.

    Published: 18 Oct 2018
    9.8
    Critical

    CVE-2018-1822

    Last Modified: 13 Feb 2025

    IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password. This can be used by an attacker to gain administrative control or to deny service. IBM X-Force ID: 150296.

    Published: 18 Oct 2018
    6.2
    Medium

    CVE-2018-1518

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.7 is affected by a weak password encryption vulnerability that could allow a local user to obtain highly sensitive information. IBM X-Force ID: 141682.

    Published: 18 Oct 2018
    5.5
    Medium

    CVE-2018-18454

    Last Modified: 21 Nov 2024

    CCITTFaxStream::readRow() in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.

    Published: 18 Oct 2018
    5.5
    Medium

    CVE-2018-18455

    Last Modified: 21 Nov 2024

    The GfxImageColorMap class in GfxState.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.

    Published: 18 Oct 2018
    5.5
    Medium

    CVE-2018-18456

    Last Modified: 21 Nov 2024

    The function Object::isName() in Object.h (called from Gfx::opSetFillColorN) in Xpdf 4.00 allows remote attackers to cause a denial of service (stack-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.

    Published: 18 Oct 2018
    5.5
    Medium

    CVE-2018-18457

    Last Modified: 21 Nov 2024

    The function DCTStream::readScan in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted pdf file, as demonstrated by pdftoppm.

    Published: 18 Oct 2018
    6.1
    Medium

    CVE-2018-18460

    Last Modified: 21 Nov 2024

    XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivechat-menu-gdpr-page request.

    Published: 18 Oct 2018
    9.8
    Critical

    CVE-2018-18461

    Last Modified: 21 Nov 2024

    The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via PHP code in attachments[] data to models/attachment.php.

    Published: 18 Oct 2018
    5.5
    Medium

    CVE-2018-18458

    Last Modified: 21 Nov 2024

    The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted pdf file, as demonstrated by pdftoppm.

    Published: 18 Oct 2018
    5.5
    Medium

    CVE-2018-18459

    Last Modified: 21 Nov 2024

    The function DCTStream::getBlock in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted pdf file, as demonstrated by pdftoppm.

    Published: 18 Oct 2018
    5.7
    Medium

    CVE-2018-19665

    Last Modified: 21 Nov 2024

    The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption.

    Published: 18 Oct 2018
    7.8
    High

    CVE-2018-18281

    Last Modified: 21 Nov 2024

    Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the middle of mremap(), a stale TLB entry can remain for a short time that permits access to a physical page after it has been released back to the page allocator and reused. This is fixed in the following kernel versions: 4.9.135, 4.14.78, 4.18.16, 4.19.

    Published: 18 Oct 2018
    7.8
    High

    CVE-2018-18718

    Last Modified: 21 Nov 2024

    An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the add_themes_from_dir method in dlg-contact-sheet.c because of two successive calls of g_free, each of which frees the same buffer.

    Published: 18 Oct 2018