CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2018-17946

    Last Modified: 21 Nov 2024

    The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Galleryerror, or Galleryupdated parameter.

    Published: 3 Oct 2018
    4.3
    Medium

    CVE-2018-11784

    Last Modified: 21 Nov 2024

    When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.

    Published: 3 Oct 2018
    6.5
    Medium

    CVE-2018-12541

    Last Modified: 21 Nov 2024

    In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory. There should be a reasonnable limit (8192 bytes) above which the WebSocket gets an HTTP response with the 413 status code and the connection gets closed.

    Published: 3 Oct 2018
    7.1
    High

    CVE-2018-18021

    Last Modified: 21 Nov 2024

    arch/arm64/kvm/guest.c in KVM in the Linux kernel before 4.18.12 on the arm64 platform mishandles the KVM_SET_ON_REG ioctl. This is exploitable by attackers who can create virtual machines. An attacker can arbitrarily redirect the hypervisor flow of control (with full register control). An attacker can also cause a denial of service (hypervisor panic) via an illegal exception return. This occurs because of insufficient restrictions on userspace access to the core register file, and because PSTATE.M validation does not prevent unintended execution modes.

    Published: 3 Oct 2018
    9.8
    Critical

    CVE-2018-14822

    Last Modified: 21 Nov 2024

    Entes EMG12 versions 2.57 and prior an information exposure through query strings vulnerability in the web interface has been identified, which may allow an attacker to impersonate a legitimate user and execute arbitrary code.

    Published: 2 Oct 2018
    9.8
    Critical

    CVE-2018-14826

    Last Modified: 21 Nov 2024

    Entes EMG12 versions 2.57 and prior The application uses a web interface where it is possible for an attacker to bypass authentication with a specially crafted URL. This could allow for remote code execution.

    Published: 2 Oct 2018
    8.8
    High

    CVE-2018-3944

    Last Modified: 21 Nov 2024

    An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

    Published: 2 Oct 2018
    7.8
    High

    CVE-2018-3958

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Subject property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

    Published: 2 Oct 2018
    7.8
    High

    CVE-2018-3959

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Author property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

    Published: 2 Oct 2018
    7.8
    High

    CVE-2018-3960

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Producer property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

    Published: 2 Oct 2018
    7.8
    High

    CVE-2018-3961

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Creator property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

    Published: 2 Oct 2018
    7.6
    High

    CVE-2017-7908

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15 and prior. A malicious HTML file that loads the ActiveX controls can trigger the vulnerability via unchecked function calls.

    Published: 2 Oct 2018
    7.8
    High

    CVE-2018-3957

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Keywords property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

    Published: 2 Oct 2018
    8.8
    High

    CVE-2018-3943

    Last Modified: 21 Nov 2024

    An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

    Published: 2 Oct 2018
    7.3
    High

    CVE-2018-3962

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the CreationDate property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

    Published: 2 Oct 2018
    7.8
    High

    CVE-2018-11748

    Last Modified: 21 Nov 2024

    Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world readable. This issue has been resolved as of device_manager 2.7.0.

    Published: 2 Oct 2018
    5.5
    Medium

    CVE-2018-11752

    Last Modified: 21 Nov 2024

    Previous releases of the Puppet cisco_ios module output SSH session debug information including login credentials to a world readable file on every run. These issues have been resolved in the 0.4.0 release.

    Published: 2 Oct 2018
    9.8
    Critical

    CVE-2018-9476

    Last Modified: 21 Nov 2024

    In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible use-after-free due to improper locking. This could lead to remote escalation of privilege in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android ID: A-109699112

    Published: 2 Oct 2018
    7.8
    High

    CVE-2018-9490

    Last Modified: 21 Nov 2024

    In CollectValuesOrEntriesImpl of elements.cc, there is possible remote code execution due to type confusion. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111274046

    Published: 2 Oct 2018
    7.8
    High

    CVE-2018-9491

    Last Modified: 21 Nov 2024

    In AMediaCodecCryptoInfo_new of NdkMediaCodec.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in external apps with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111603051

    Published: 2 Oct 2018
    7.8
    High

    CVE-2018-9492

    Last Modified: 21 Nov 2024

    In checkGrantUriPermissionLocked of ActivityManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android-9.0 Android ID: A-111934948

    Published: 2 Oct 2018
    7.8
    High

    CVE-2018-9497

    Last Modified: 21 Nov 2024

    In impeg2_fmt_conv_yuv420p_to_yuv420sp_uv_av8 of impeg2_format_conv.s there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-74078669

    Published: 2 Oct 2018
    7.8
    High

    CVE-2018-9498

    Last Modified: 21 Nov 2024

    In SkSampler::Fill of SkSampler.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-78354855

    Published: 2 Oct 2018
    5.5
    Medium

    CVE-2018-9499

    Last Modified: 21 Nov 2024

    In readVector of iCrypto.cpp, there is a possible invalid read due to uninitialized data. This could lead to local information disclosure from the DRM server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-79218474

    Published: 2 Oct 2018
    7.8
    High

    CVE-2018-9501

    Last Modified: 21 Nov 2024

    In the SetupWizard, there is a possible Factory Reset Protection bypass due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-110034419

    Published: 2 Oct 2018
    6.5
    Medium

    CVE-2018-9502

    Last Modified: 21 Nov 2024

    In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111936792

    Published: 2 Oct 2018
    7.5
    High

    CVE-2018-9503

    Last Modified: 21 Nov 2024

    In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-80432928

    Published: 2 Oct 2018
    8.8
    High

    CVE-2018-9504

    Last Modified: 21 Nov 2024

    In sdp_copy_raw_data of sdp_discovery.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution over bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-110216176

    Published: 2 Oct 2018
    6.5
    Medium

    CVE-2018-9505

    Last Modified: 21 Nov 2024

    In mca_ccb_hdl_req of mca_cact.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-110791536

    Published: 2 Oct 2018
    6.5
    Medium

    CVE-2018-9506

    Last Modified: 21 Nov 2024

    In avrc_msg_cback of avrc_api.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111803925

    Published: 2 Oct 2018
    6.5
    Medium

    CVE-2018-9507

    Last Modified: 21 Nov 2024

    In bta_av_proc_meta_cmd of bta_av_act.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111893951

    Published: 2 Oct 2018
    6.5
    Medium

    CVE-2018-9510

    Last Modified: 21 Nov 2024

    In smp_proc_enc_info of smp_act.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111937065

    Published: 2 Oct 2018
    5.5
    Medium

    CVE-2018-9511

    Last Modified: 21 Nov 2024

    In ipSecSetEncapSocketOwner of XfrmController.cpp, there is a possible failure to initialize a security feature due to uninitialized data. This could lead to local denial of service of IPsec on sockets with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-9.0 Android ID: A-111650288

    Published: 2 Oct 2018
    7.8
    High

    CVE-2018-9513

    Last Modified: 21 Nov 2024

    In copy_process of fork.c, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-111081202 References: N/A

    Published: 2 Oct 2018
    7.8
    High

    CVE-2018-9514

    Last Modified: 21 Nov 2024

    In sdcardfs_open of file.c, there is a possible Use After Free due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-111642636 References: N/A

    Published: 2 Oct 2018
    7.8
    High

    CVE-2018-9515

    Last Modified: 21 Nov 2024

    In sdcardfs_create and sdcardfs_mkdir of inode.c, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-111641492 References: N/A

    Published: 2 Oct 2018
    7.8
    High

    CVE-2018-9473

    Last Modified: 21 Nov 2024

    In ihevcd_parse_sei_payload of ihevcd_parse_headers.c, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0 Android ID: A-65484460

    Published: 2 Oct 2018
    5.5
    Medium

    CVE-2018-9493

    Last Modified: 21 Nov 2024

    In the content provider of the download manager, there is a possible SQL injection due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111085900

    Published: 2 Oct 2018
    6.5
    Medium

    CVE-2018-11750

    Last Modified: 21 Nov 2024

    Previous releases of the Puppet cisco_ios module did not validate a host's identity before starting a SSH connection. As of the 0.4.0 release of cisco_ios, host key checking is enabled by default.

    Published: 2 Oct 2018
    5.5
    Medium

    CVE-2018-9452

    Last Modified: 21 Nov 2024

    In getOffsetForHorizontal of Layout.java, there is a possible application hang due to a slow width calculation. This could lead to remote denial of service if a contact with many hidden unicode characters were sent to the device and used by a local app, with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-78464361

    Published: 2 Oct 2018
    7.8
    High

    CVE-2018-9496

    Last Modified: 21 Nov 2024

    In ixheaacd_real_synth_fft_p3 of ixheaacd_esbr_fft.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-9.0 Android ID: A-110769924

    Published: 2 Oct 2018
    6.5
    Medium

    CVE-2018-9508

    Last Modified: 21 Nov 2024

    In smp_process_keypress_notification of smp_act.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-111936834

    Published: 2 Oct 2018
    6.5
    Medium

    CVE-2018-9509

    Last Modified: 21 Nov 2024

    In smp_proc_master_id of smp_act.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111937027

    Published: 2 Oct 2018
    6.1
    Medium

    CVE-2018-15563

    Last Modified: 21 Nov 2024

    _core/admin/pages/add/ in Subrion CMS 4.2.1 has XSS via the titles[en] parameter.

    Published: 2 Oct 2018
    8.1
    High

    CVE-2018-15752

    Last Modified: 21 Nov 2024

    An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. Cleartext Transmission of Sensitive Information allows man-in-the-middle attackers to eavesdrop authentication information between the application and the server.

    Published: 2 Oct 2018
    6.1
    Medium

    CVE-2018-17587

    Last Modified: 21 Nov 2024

    AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

    Published: 2 Oct 2018
    6.1
    Medium

    CVE-2018-17590

    Last Modified: 21 Nov 2024

    AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

    Published: 2 Oct 2018
    6.1
    Medium

    CVE-2018-17591

    Last Modified: 21 Nov 2024

    AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

    Published: 2 Oct 2018
    6.1
    Medium

    CVE-2018-17593

    Last Modified: 21 Nov 2024

    AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

    Published: 2 Oct 2018
    6.1
    Medium

    CVE-2018-17594

    Last Modified: 21 Nov 2024

    AirTies Air 5443v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

    Published: 2 Oct 2018