CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2018-15702

    Last Modified: 21 Nov 2024

    The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to CSRF due to insufficient validation of the referer field.

    Published: 1 Oct 2018
    7.8
    High

    CVE-2018-3982

    Last Modified: 21 Nov 2024

    An exploitable arbitrary write vulnerability exists in the Word document parser of the Atlantis Word Processor 3.0.2.3 and 3.0.2.5. A specially crafted document can prevent Atlas from adding elements to an array that is indexed by a loop. When reading from this array, the application will use an out-of-bounds index which can result in arbitrary data being read as a pointer. Later, when the application attempts to write to said pointer, an arbitrary write will occur. This can allow an attacker to further corrupt memory, which leads to code execution under the context of the application. An attacker must convince a victim to open a document in order to trigger this vulnerability.

    Published: 1 Oct 2018
    7.8
    High

    CVE-2018-3999

    Last Modified: 21 Nov 2024

    An exploitable stack-based buffer overflow vulnerability exists in the JPEG parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted image embedded within a document can cause a length to be miscalculated and underflow. This length is then treated as unsigned and then used in a copying operation. Due to the length underflow, the application will then write outside the bounds of a stack buffer, resulting in a buffer overflow. An attacker must convince a victim to open a document in order to trigger this vulnerability.

    Published: 1 Oct 2018
    7.8
    High

    CVE-2018-4001

    Last Modified: 21 Nov 2024

    An exploitable uninitialized pointer vulnerability exists in the Office Open XML parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted document can cause an uninitialized pointer representing a TTableRow to be assigned to a variable on the stack. This variable is later dereferenced and then written to allow for controlled heap corruption, which can lead to code execution under the context of the application. An attacker must convince a victim to open a document in order to trigger this vulnerability.

    Published: 1 Oct 2018
    8.8
    High

    CVE-2018-10605

    Last Modified: 21 Nov 2024

    Martem TELEM GW6/GWM versions prior to 2.0.87-4018403-k4 may allow unprivileged users to modify/upload a new system configuration or take the full control over the RTU using default credentials to connect to the RTU.

    Published: 1 Oct 2018
    6.5
    Medium

    CVE-2018-14808

    Last Modified: 21 Nov 2024

    Emerson AMS Device Manager v12.0 to v13.5. Non-administrative users are able to change executable and library files on the affected products.

    Published: 1 Oct 2018
    9.8
    Critical

    CVE-2018-14804

    Last Modified: 21 Nov 2024

    Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution.

    Published: 1 Oct 2018
    5
    Medium

    CVE-2018-1672

    Last Modified: 21 Nov 2024

    IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user. IBM X-Force ID: 144958.

    Published: 1 Oct 2018
    5.3
    Medium

    CVE-2018-1420

    Last Modified: 21 Nov 2024

    IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.

    Published: 1 Oct 2018
    5.3
    Medium

    CVE-2018-14788

    Last Modified: 21 Nov 2024

    Fuji Electric Alpha5 Smart Loader Versions 3.7 and prior. A buffer overflow information disclosure vulnerability occurs when parsing certain file types.

    Published: 1 Oct 2018
    9.8
    Critical

    CVE-2018-14802

    Last Modified: 21 Nov 2024

    Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. The program does not properly check user-supplied comments which may allow for arbitrary remote code execution.

    Published: 1 Oct 2018
    5.3
    Medium

    CVE-2018-14798

    Last Modified: 21 Nov 2024

    Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. The program does not properly parse FNC files that may allow for information disclosure.

    Published: 1 Oct 2018
    9.8
    Critical

    CVE-2018-14790

    Last Modified: 21 Nov 2024

    Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. A buffer over-read vulnerability may allow remote code execution on the device.

    Published: 1 Oct 2018
    9.8
    Critical

    CVE-2018-14794

    Last Modified: 21 Nov 2024

    Fuji Electric Alpha5 Smart Loader Versions 3.7 and prior. The device does not perform a check on the length/size of a project file before copying the entire contents of the file to a heap-based buffer.

    Published: 1 Oct 2018
    6.5
    Medium

    CVE-2018-17427

    Last Modified: 21 Nov 2024

    SIMDComp before 0.1.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) because it can read (and then discard) extra bytes.

    Published: 1 Oct 2018
    9.8
    Critical

    CVE-2018-17825

    Last Modified: 21 Nov 2024

    An issue was discovered in AdPlug 2.3.1. There are several double-free vulnerabilities in the CEmuopl class in emuopl.cpp because of a destructor's two OPLDestroy calls, each of which frees TL_TABLE, SIN_TABLE, AMS_TABLE, and VIB_TABLE.

    Published: 1 Oct 2018
    8.8
    High

    CVE-2018-17826

    Last Modified: 21 Nov 2024

    HisiPHP 1.0.8 allows CSRF via admin.php/admin/user/adduser.html to add an administrator account. The attacker can then use that account to execute arbitrary PHP code by leveraging app/common/model/AdminAnnex.php to add .php to the default list of allowable file-upload types (.jpg, .png, .gif, .jpeg, and .ico).

    Published: 1 Oct 2018
    7.2
    High

    CVE-2018-17827

    Last Modified: 21 Nov 2024

    HisiPHP 1.0.8 allows remote attackers to execute arbitrary PHP code by editing a plugin's name to contain that code. This name is then injected into app/admin/model/AdminPlugins.php.

    Published: 1 Oct 2018
    5.4
    Medium

    CVE-2018-17830

    Last Modified: 21 Nov 2024

    The $args variable in addons/mediapool/pages/index.php in REDAXO 5.6.2 is not effectively filtered, because names are not restricted (only values are restricted). The attacker can insert XSS payloads via an index.php?page=mediapool/media&opener_input_field=&args[ substring.

    Published: 1 Oct 2018
    9.8
    Critical

    CVE-2018-17831

    Last Modified: 21 Nov 2024

    In REDAXO before 5.6.3, a critical SQL injection vulnerability has been discovered in the rex_list class because of the prepareQuery function in core/lib/list.php, via the index.php?page=users/users sort parameter. Endangered was the backend and the frontend only if rex_list were used.

    Published: 1 Oct 2018
    6.1
    Medium

    CVE-2018-17832

    Last Modified: 21 Nov 2024

    XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.

    Published: 1 Oct 2018
    4.8
    Medium

    CVE-2018-17835

    Last Modified: 21 Nov 2024

    An issue was discovered in GetSimple CMS 3.3.15. An administrator can insert stored XSS via the admin/settings.php Custom Permalink Structure parameter, which injects the XSS payload into any page created at the admin/pages.php URI.

    Published: 1 Oct 2018
    8.8
    High

    CVE-2018-17836

    Last Modified: 21 Nov 2024

    An issue was discovered in JTBC(PHP) 3.0.1.6. It allows remote attackers to execute arbitrary PHP code by using a /console/file/manage.php?type=action&action=addfile&path=..%2F substring to upload, in conjunction with a multipart/form-data PHP payload.

    Published: 1 Oct 2018
    7.5
    High

    CVE-2018-17837

    Last Modified: 21 Nov 2024

    An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file deletion is possible via a /console/file/manage.php?type=action&action=delete&path=c%3A%2F substring.

    Published: 1 Oct 2018
    Unknown

    CVE-2018-17851

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 1 Oct 2018
    6.5
    Medium

    CVE-2018-17854

    Last Modified: 21 Nov 2024

    SIMDComp before 0.1.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) because it can read (and then discard) extra bytes. NOTE: this issue exists because of an incomplete fix for CVE-2018-17427.

    Published: 1 Oct 2018
    7.8
    High

    CVE-2015-9268

    Last Modified: 21 Nov 2024

    Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime.

    Published: 1 Oct 2018
    9.8
    Critical

    CVE-2018-17852

    Last Modified: 21 Nov 2024

    A SQL injection was discovered in WUZHI CMS 4.1.0 in coreframe/app/coupon/admin/card.php via the groupname parameter to the /index.php?m=coupon&f=card&v=detail_listing URI.

    Published: 1 Oct 2018
    5.5
    Medium

    CVE-2015-9267

    Last Modified: 21 Nov 2024

    Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Trojan horse program.

    Published: 1 Oct 2018
    7.5
    High

    CVE-2018-17838

    Last Modified: 21 Nov 2024

    An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file read operations are possible via a /console/#/console/file/manage.php?type=list&path=c:/ substring.

    Published: 1 Oct 2018
    Unknown

    CVE-2018-17850

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 1 Oct 2018
    6.5
    Medium

    CVE-2018-17216

    Last Modified: 21 Nov 2024

    An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is password hash exposure to privileged users.

    Published: 1 Oct 2018
    7.5
    High

    CVE-2018-17217

    Last Modified: 21 Nov 2024

    An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is a hardcoded encryption key.

    Published: 1 Oct 2018
    5.4
    Medium

    CVE-2018-17218

    Last Modified: 21 Nov 2024

    An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is reflected XSS in the SQUEAL search function.

    Published: 1 Oct 2018
    9.1
    Critical

    CVE-2018-17983

    Last Modified: 21 Nov 2024

    cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsing of a malformed manifest entry.

    Published: 1 Oct 2018
    4.9
    Medium

    CVE-2018-16984

    Last Modified: 21 Nov 2024

    An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes.

    Published: 1 Oct 2018
    7.5
    High

    CVE-2018-17846

    Last Modified: 21 Nov 2024

    The html package (aka x/net/html) through 2018-09-25 in Go mishandles <table><math><select><mi><select></table>, leading to an infinite loop during an html.Parse call because inSelectIM and inSelectInTableIM do not comply with a specification.

    Published: 1 Oct 2018
    7.5
    High

    CVE-2018-17847

    Last Modified: 21 Nov 2024

    The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a "panic: runtime error" (index out of range) in (*nodeStack).pop in node.go, called from (*parser).clearActiveFormattingElements, during an html.Parse call.

    Published: 1 Oct 2018
    7.5
    High

    CVE-2018-17848

    Last Modified: 21 Nov 2024

    The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "panic: runtime error" (index out of range) in (*insertionModeStack).pop in node.go, called from inHeadIM, during an html.Parse call.

    Published: 1 Oct 2018
    8.8
    High

    CVE-2018-17795

    Last Modified: 21 Nov 2024

    The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, a similar issue to CVE-2017-9935.

    Published: 30 Sept 2018
    6.5
    Medium

    CVE-2018-17797

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 8.3. user/zssave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

    Published: 30 Sept 2018
    6.5
    Medium

    CVE-2018-17798

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 8.3. user/ztconfig.php allows remote attackers to delete arbitrary files via an absolute pathname in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

    Published: 30 Sept 2018
    6.5
    Medium

    CVE-2018-17794

    Last Modified: 21 Nov 2024

    An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_to_from when called from iterate_demangle_function.

    Published: 30 Sept 2018
    9.8
    Critical

    CVE-2018-17796

    Last Modified: 21 Nov 2024

    An issue was discovered in MRCMS (aka mushroom) through 3.1.2. The WebParam.java file directly accepts the FIELD_T parameter in a request and uses it as a hash of SQL statements without filtering, resulting in a SQL injection vulnerability in getChannel() in the ChannelService.java file.

    Published: 30 Sept 2018
    Unknown

    CVE-2018-17793

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 30 Sept 2018
    7.5
    High

    CVE-2018-17785

    Last Modified: 21 Nov 2024

    In blynk-server in Blynk before 0.39.7, Directory Traversal exists via a ../ in a URI that has /static or /static/js at the beginning, as demonstrated by reading the /etc/passwd file.

    Published: 30 Sept 2018
    6.5
    Medium

    CVE-2018-17780

    Last Modified: 21 Nov 2024

    Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call because of an unsafe default behavior in which P2P connections are accepted from clients outside of the My Contacts list.

    Published: 29 Sept 2018
    7.5
    High

    CVE-2018-17781

    Last Modified: 21 Nov 2024

    Foxit PhantomPDF and Reader before 9.3 allow remote attackers to trigger Uninitialized Object Information Disclosure because creation of ArrayBuffer and DataView objects is mishandled.

    Published: 29 Sept 2018
    7.8
    High

    CVE-2018-17776

    Last Modified: 21 Nov 2024

    PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users to gain privileges by replacing an executable file with a Trojan horse.

    Published: 28 Sept 2018
    8.1
    High

    CVE-2018-9075

    Last Modified: 21 Nov 2024

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a command injection payload using backtick "``" characters in the client:password parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.

    Published: 28 Sept 2018