CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2018-9076

    Last Modified: 21 Nov 2024

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-9079

    Last Modified: 21 Nov 2024

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handlers to execute arbitrary JavaScript with the origin of the device.

    Published: 28 Sept 2018
    4.7
    Medium

    CVE-2018-9081

    Last Modified: 21 Nov 2024

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file name used for assets accessible through the Content Viewer application are vulnerable to self cross-site scripting self-XSS. As a result, adversaries can add files to shares accessible from the Content Viewer with a cross site scripting payload in its name, and wait for a user to try and rename the file for their payload to trigger.

    Published: 28 Sept 2018
    8.8
    High

    CVE-2018-9082

    Last Modified: 21 Nov 2024

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a result, attackers with access to the user's session tokens can change their password and retain access to the user's account

    Published: 28 Sept 2018
    6.5
    Medium

    CVE-2018-9074

    Last Modified: 21 Nov 2024

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user.

    Published: 28 Sept 2018
    8.1
    High

    CVE-2018-9077

    Last Modified: 21 Nov 2024

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the share : name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.

    Published: 28 Sept 2018
    8.8
    High

    CVE-2018-9078

    Last Modified: 21 Nov 2024

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to upload files to shares and this image was rendered in the browser in the device's origin instead of prompting to download the asset. The application does not prevent the user from uploading SVG images and returns these images within their origin. As a result, malicious users can upload SVG images that contain arbitrary JavaScript that is evaluated when the victim issues a request to download the file.

    Published: 28 Sept 2018
    5.9
    Medium

    CVE-2018-9080

    Last Modified: 21 Nov 2024

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allows an attacker who knows the cookie's value to compromise the user's session.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-15764

    Last Modified: 21 Nov 2024

    Dell EMC ESRS Policy Manager versions 6.8 and prior contain a remote code execution vulnerability due to improper configurations of triggered JMX services. A remote unauthenticated attacker may potentially exploit this vulnerability to execute arbitrary code in the server's JVM.

    Published: 28 Sept 2018
    6.5
    Medium

    CVE-2018-11073

    Last Modified: 21 Nov 2024

    RSA Authentication Manager versions prior to 8.3 P3 contain a stored cross-site scripting vulnerability in the Operations Console. A malicious Operations Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console administrators open the affected page, the injected scripts could potentially be executed in their browser.

    Published: 28 Sept 2018
    8.3
    High

    CVE-2018-1251

    Last Modified: 21 Nov 2024

    Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect Unity users to arbitrary web URLs by tricking the victim user to click on a maliciously crafted Unisphere URL. Attacker could potentially phish information, including Unisphere users' credentials, from the victim once they are redirected.

    Published: 28 Sept 2018
    6.5
    Medium

    CVE-2018-1250

    Last Modified: 21 Nov 2024

    Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote authenticated user could potentially exploit this vulnerability to read files in NAS server by directly interacting with certain APIs of Unity OE, bypassing Role-Based Authorization control implemented only in Unisphere GUI.

    Published: 28 Sept 2018
    6.1
    Medium

    CVE-2018-11074

    Last Modified: 21 Nov 2024

    RSA Authentication Manager versions prior to 8.3 P3 are affected by a DOM-based cross-site scripting vulnerability which exists in its embedded MadCap Flare Help files. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to the browser DOM, which code is then executed by the web browser in the context of the vulnerable web application.

    Published: 28 Sept 2018
    5.8
    Medium

    CVE-2018-11075

    Last Modified: 21 Nov 2024

    RSA Authentication Manager versions prior to 8.3 P3 contain a reflected cross-site scripting vulnerability in a Security Console page. A remote, unauthenticated malicious user, with the knowledge of a target user's anti-CSRF token, could potentially exploit this vulnerability by tricking a victim Security Console user to supply malicious HTML or JavaScript code to the vulnerable web application, which code is then executed by the victim's web browser in the context of the vulnerable web application.

    Published: 28 Sept 2018
    4.7
    Medium

    CVE-2018-1246

    Last Modified: 21 Nov 2024

    Dell EMC Unity and UnityVSA contains reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or Java Script code to Unisphere, which is then reflected back to the victim and executed by the web browser.

    Published: 28 Sept 2018
    5.4
    Medium

    CVE-2018-15365

    Last Modified: 21 Nov 2024

    A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable installations. An attacker must be an authenticated user in order to exploit the vulnerability.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-5393

    Last Modified: 21 Nov 2024

    The TP-LINK EAP Controller is TP-LINK's software for remotely controlling wireless access point devices. It utilizes a Java remote method invocation (RMI) service for remote control. The RMI interface does not require any authentication before use, so it lacks user authentication for RMI service commands in EAP controller versions 2.5.3 and earlier. Remote attackers can implement deserialization attacks through the RMI protocol. Successful attacks may allow a remote attacker to remotely control the target server and execute Java functions or bytecode.

    Published: 28 Sept 2018
    7.1
    High

    CVE-2018-1702

    Last Modified: 21 Nov 2024

    IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 146189.

    Published: 28 Sept 2018
    5.5
    Medium

    CVE-2018-17154

    Last Modified: 21 Nov 2024

    In FreeBSD before 11.2-STABLE(r338987), 11.2-RELEASE-p4, and 11.1-RELEASE-p15, due to insufficient memory checking in the freebsd4_getfsstat system call, a NULL pointer dereference can occur. Unprivileged authenticated local users may be able to cause a denial of service.

    Published: 28 Sept 2018
    5.5
    Medium

    CVE-2018-6925

    Last Modified: 21 Nov 2024

    In FreeBSD before 11.2-STABLE(r338986), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338985), and 10.4-RELEASE-p13, due to improper maintenance of IPv6 protocol control block flags through various failure paths, an unprivileged authenticated local user may be able to cause a NULL pointer dereference causing the kernel to crash.

    Published: 28 Sept 2018
    6.8
    Medium

    CVE-2018-1704

    Last Modified: 21 Nov 2024

    IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 146339.

    Published: 28 Sept 2018
    5.5
    Medium

    CVE-2018-17155

    Last Modified: 21 Nov 2024

    In FreeBSD before 11.2-STABLE(r338983), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338984), and 10.4-RELEASE-p13, due to insufficient initialization of memory copied to userland in the getcontext and swapcontext system calls, small amounts of kernel memory may be disclosed to userland processes. Unprivileged authenticated local users may be able to access small amounts privileged kernel data.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-17613

    Last Modified: 21 Nov 2024

    Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and application data in cleartext over the SOCKS5 protocol.

    Published: 28 Sept 2018
    5.4
    Medium

    CVE-2018-17574

    Last Modified: 21 Nov 2024

    An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-17575

    Last Modified: 21 Nov 2024

    SWA SWA.JACAD 3.1.37 Build 024 has SQL Injection via the /academico/aluno/esqueci-minha-senha/ studentId parameter.

    Published: 28 Sept 2018
    7.5
    High

    CVE-2018-17605

    Last Modified: 21 Nov 2024

    An issue was discovered in the Asset Pipeline plugin before 3.0.4 for Grails. An attacker can perform directory traversal via a crafted request when a servlet-based application is executed in Jetty, because there is a classloader vulnerability that can allow a reverse file traversal route in AssetPipelineFilter.groovy or AssetPipelineFilterCore.groovy.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-17609

    Last Modified: 21 Nov 2024

    Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-17610

    Last Modified: 21 Nov 2024

    Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-17608

    Last Modified: 21 Nov 2024

    Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-17611

    Last Modified: 21 Nov 2024

    Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.

    Published: 28 Sept 2018
    7.1
    High

    CVE-2018-17580

    Last Modified: 21 Nov 2024

    A heap-based buffer over-read exists in the function fast_edit_packet() in the file send_packets.c of Tcpreplay v4.3.0 beta1. This can lead to Denial of Service (DoS) and potentially Information Exposure when the application attempts to process a crafted pcap file.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-17607

    Last Modified: 21 Nov 2024

    Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.

    Published: 28 Sept 2018
    7.1
    High

    CVE-2018-17582

    Last Modified: 21 Nov 2024

    Tcpreplay v4.3.0 beta1 contains a heap-based buffer over-read. The get_next_packet() function in the send_packets.c file uses the memcpy() function unsafely to copy sequences from the source buffer pktdata to the destination (*prev_packet)->pktdata. This will result in a Denial of Service (DoS) and potentially Information Exposure when the application attempts to process a file.

    Published: 28 Sept 2018
    6.1
    Medium

    CVE-2018-17571

    Last Modified: 21 Nov 2024

    Vanilla before 2.6.1 allows XSS via the email field of a profile.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-17573

    Last Modified: 21 Nov 2024

    The Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configuration of FCKeditor under fckeditor/editor/filemanager/browser/default/browser.html, fckeditor/editor/filemanager/connectors/test.html, and fckeditor/editor/filemanager/connectors/uploadtest.html.

    Published: 28 Sept 2018
    6.1
    Medium

    CVE-2018-14037

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor v2018.1.221 allows remote attackers to inject arbitrary JavaScript into the DOM of the WYSIWYG editor because of the editorNS.Serializer toEditableHtml function in kendo.all.min.js. If the victim accesses the editor, the payload gets executed. Furthermore, if the payload is reflected at any other resource that does rely on the sanitisation of the editor itself, the JavaScript payload will be executed in the context of the application. This allows attackers (in the worst case) to take over user sessions.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-14956

    Last Modified: 21 Nov 2024

    CMS ISWEB 3.5.3 is vulnerable to multiple SQL injection flaws. An attacker can inject malicious queries into the application and obtain sensitive information.

    Published: 28 Sept 2018
    6.5
    Medium

    CVE-2018-16587

    Last Modified: 21 Nov 2024

    In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes deletions of arbitrary files that the OTRS web server user has write access to.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-16659

    Last Modified: 21 Nov 2024

    An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST parameter. Hypothetically, an attacker can utilize master..xp_cmdshell for the further privilege elevation.

    Published: 28 Sept 2018
    7.5
    High

    CVE-2018-17055

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-17378

    Last Modified: 21 Nov 2024

    SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-17379

    Last Modified: 21 Nov 2024

    SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-17380

    Last Modified: 21 Nov 2024

    SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-17383

    Last Modified: 21 Nov 2024

    SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-17384

    Last Modified: 21 Nov 2024

    SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-17385

    Last Modified: 21 Nov 2024

    SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-17394

    Last Modified: 21 Nov 2024

    SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.

    Published: 28 Sept 2018
    9.8
    Critical

    CVE-2018-17397

    Last Modified: 21 Nov 2024

    SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.

    Published: 28 Sept 2018
    7.5
    High

    CVE-2018-17567

    Last Modified: 21 Nov 2024

    Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specifying a symlink in the "include" key in the "_config.yml" file.

    Published: 28 Sept 2018
    6.1
    Medium

    CVE-2018-17056

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Sept 2018