CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-17281

    Last Modified: 21 Nov 2024

    There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a specially crafted HTTP request to upgrade the connection to a websocket.

    Published: 24 Sept 2018
    7.5
    High

    CVE-2018-12975

    Last Modified: 21 Nov 2024

    The random() function of the smart contract implementation for CryptoSaga, an Ethereum game, generates a random value with publicly readable variables such as timestamp, the current block's blockhash, and a private variable (which can be read with a getStorageAt call). Therefore, attackers can precompute the random number and manipulate the game (e.g., get powerful characters or get critical damages).

    Published: 24 Sept 2018
    5.8
    Medium

    CVE-2018-14825

    Last Modified: 21 Nov 2024

    On Honeywell Mobile Computers (CT60 running Android OS 7.1, CN80 running Android OS 7.1, CT40 running Android OS 7.1, CK75 running Android OS 6.0, CN75 running Android OS 6.0, CN75e running Android OS 6.0, CT50 running Android OS 6.0, D75e running Android OS 6.0, CT50 running Android OS 4.4, D75e running Android OS 4.4, CN51 running Android OS 6.0, EDA50k running Android 4.4, EDA50 running Android OS 7.1, EDA50k running Android OS 7.1, EDA70 running Android OS 7.1, EDA60k running Android OS 7.1, and EDA51 running Android OS 8.1), a skilled attacker with advanced knowledge of the target system could exploit this vulnerability by creating an application that would successfully bind to the service and gain elevated system privileges. This could enable the attacker to obtain access to keystrokes, passwords, personal identifiable information, photos, emails, or business-critical documents.

    Published: 24 Sept 2018
    9.8
    Critical

    CVE-2015-8298

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities in the login page in RXTEC RXAdmin UPDATE 06 / 2012 allow remote attackers to execute arbitrary SQL commands via the (1) loginpassword, (2) loginusername, (3) zusatzlicher, or (4) groupid parameter to index.htm, or the (5) rxtec cookie to index.htm.

    Published: 24 Sept 2018
    Unknown

    CVE-2017-5639

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 24 Sept 2018
    7.8
    High

    CVE-2018-6700

    Last Modified: 21 Nov 2024

    DLL Search Order Hijacking vulnerability in Microsoft Windows Client in McAfee True Key (TK) before 5.1.165 allows local users to execute arbitrary code via specially crafted malware.

    Published: 24 Sept 2018
    7.2
    High

    CVE-2018-15615

    Last Modified: 21 Nov 2024

    A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract sensitive information from users connecting to a remote CMS host. Affected versions of CMS Supervisor include R17.0.x and R18.0.x.

    Published: 24 Sept 2018
    6.1
    Medium

    CVE-2018-6682

    Last Modified: 21 Nov 2024

    Cross Site Scripting Exposure in McAfee True Key (TK) 4.0.0.0 and earlier allows local users to expose confidential data via a crafted web site.

    Published: 24 Sept 2018
    6.5
    Medium

    CVE-2018-17438

    Last Modified: 21 Nov 2024

    A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.

    Published: 24 Sept 2018
    6.5
    Medium

    CVE-2018-17433

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow in ReadGifImageDesc() in gifread.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.

    Published: 24 Sept 2018
    7
    High

    CVE-2018-14633

    Last Modified: 21 Nov 2024

    A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a way an authentication request from an ISCSI initiator is processed. An unauthenticated remote attacker can cause a stack buffer overflow and smash up to 17 bytes of the stack. The attack requires the iSCSI target to be enabled on the victim host. Depending on how the target's code was built (i.e. depending on a compiler, compile flags and hardware architecture) an attack may lead to a system crash and thus to a denial-of-service or possibly to a non-authorized access to data exported by an iSCSI target. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is highly unlikely. Kernel versions 4.18.x, 4.14.x and 3.10.x are believed to be vulnerable.

    Published: 24 Sept 2018
    6.5
    Medium

    CVE-2018-0504

    Last Modified: 21 Nov 2024

    Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid

    Published: 24 Sept 2018
    7.5
    High

    CVE-2018-16152

    Last Modified: 3 Dec 2025

    In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field during PKCS#1 v1.5 signature verification. Consequently, a remote attacker can forge signatures when small public exponents are being used, which could lead to impersonation when only an RSA signature is used for IKEv2 authentication. This is a variant of CVE-2006-4790 and CVE-2014-1568.

    Published: 24 Sept 2018
    6.5
    Medium

    CVE-2018-17432

    Last Modified: 21 Nov 2024

    A NULL pointer dereference in H5O_sdspace_encode() in H5Osdspace.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file.

    Published: 24 Sept 2018
    6.5
    Medium

    CVE-2018-17434

    Last Modified: 21 Nov 2024

    A SIGFPE signal is raised in the function apply_filters() of h5repack_filters.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.

    Published: 24 Sept 2018
    6.5
    Medium

    CVE-2018-17435

    Last Modified: 21 Nov 2024

    A heap-based buffer over-read in H5O_attr_decode() in H5Oattr.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while converting an HDF file to GIF file.

    Published: 24 Sept 2018
    6.5
    Medium

    CVE-2018-17439

    Last Modified: 21 Nov 2024

    An issue was discovered in the HDF HDF5 1.10.3 library. There is a stack-based buffer overflow in the function H5S_extent_get_dims() in H5S.c. Specifically, this issue occurs while converting an HDF5 file to a GIF file.

    Published: 24 Sept 2018
    7.5
    High

    CVE-2018-16151

    Last Modified: 3 Dec 2025

    In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data after the encoded algorithm OID during PKCS#1 v1.5 signature verification. Similar to the flaw in the same version of strongSwan regarding digestAlgorithm.parameters, a remote attacker can forge signatures when small public exponents are being used, which could lead to impersonation when only an RSA signature is used for IKEv2 authentication.

    Published: 24 Sept 2018
    4.3
    Medium

    CVE-2018-0503

    Last Modified: 21 Nov 2024

    Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimits entry for 'user' overrides that for 'newbie'.

    Published: 24 Sept 2018
    6.5
    Medium

    CVE-2018-0505

    Last Modified: 21 Nov 2024

    Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock

    Published: 24 Sept 2018
    9.8
    Critical

    CVE-2018-1000810

    Last Modified: 21 Nov 2024

    The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integer Overflow to Buffer Overflow vulnerability in standard library that can result in buffer overflow. This attack appear to be exploitable via str::repeat, passed a large number, can overflow an internal buffer. This vulnerability appears to have been fixed in 1.29.1.

    Published: 24 Sept 2018
    9.8
    Critical

    CVE-2018-14649

    Last Modified: 21 Nov 2024

    It was found that ceph-isci-cli package as shipped by Red Hat Ceph Storage 2 and 3 is using python-werkzeug in debug shell mode. This is done by setting debug=True in file /usr/bin/rbd-target-api provided by ceph-isci-cli package. This allows unauthenticated attackers to access this debug shell and escalate privileges. Once an attacker has successfully connected to this debug shell they will be able to execute arbitrary commands remotely. These commands will run with the same privileges as of user executing the application which is using python-werkzeug with debug shell mode enabled. In - Red Hat Ceph Storage 2 and 3, ceph-isci-cli package runs python-werkzeug library with root level permissions.

    Published: 24 Sept 2018
    6.5
    Medium

    CVE-2018-17436

    Last Modified: 21 Nov 2024

    ReadCode() in decompress.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (invalid write access) via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.

    Published: 24 Sept 2018
    6.5
    Medium

    CVE-2018-17437

    Last Modified: 21 Nov 2024

    Memory leak in the H5O_dtype_decode_helper() function in H5Odtype.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.

    Published: 24 Sept 2018
    5.3
    Medium

    CVE-2018-17368

    Last Modified: 21 Nov 2024

    An issue was discovered in PublicCMS V4.0.180825. For an invalid login attempt, the response length is different depending on whether the username is valid, which makes it easier to conduct brute-force attacks.

    Published: 23 Sept 2018
    4.8
    Medium

    CVE-2018-17369

    Last Modified: 21 Nov 2024

    An issue was discovered in springboot_authority through 2017-03-06. There is stored XSS via the admin/role/edit roleKey, name, or description parameter.

    Published: 23 Sept 2018
    5.3
    Medium

    CVE-2018-17402

    Last Modified: 21 Nov 2024

    The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to discover the Credit/Debit card number, expiration date, and CVV number. NOTE: the vendor says that, to exploit this, the user has to explicitly install a malicious app and provide accessibility permission to the malicious app, that the Android platform provides fair warnings to the users before turning on accessibility for any application, and that it believes it is similar to installing malicious keyboards, or malicious apps taking screenshots

    Published: 23 Sept 2018
    8.8
    High

    CVE-2018-17403

    Last Modified: 21 Nov 2024

    The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to impersonate a user and set up their account without their knowledge. NOTE: the vendor says that, to exploit this, the user has to explicitly install a malicious app and provide accessibility permission to the malicious app, that the Android platform provides fair warnings to the users before turning on accessibility for any application, and that it believes it is similar to installing malicious keyboards, or malicious apps taking screenshots

    Published: 23 Sept 2018
    5.3
    Medium

    CVE-2018-17404

    Last Modified: 21 Nov 2024

    The SBIbuddy (aka com.sbi.erupee) application 1.41 and 1.42 for Android might allow an attacker to sniff private information such as mobile number, PAN number (from a government-issued ID), and date of birth.

    Published: 23 Sept 2018
    7
    High

    CVE-2018-17400

    Last Modified: 21 Nov 2024

    The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to perform Account Takeover attacks by intercepting the user name and PIN during the initial configuration of the application. NOTE: the vendor says that, to exploit this, the user has to explicitly install a malicious app and provide accessibility permission to the malicious app, that the Android platform provides fair warnings to the users before turning on accessibility for any application, and that it believes it is similar to installing malicious keyboards, or malicious apps taking screenshots

    Published: 23 Sept 2018
    8.8
    High

    CVE-2018-17401

    Last Modified: 21 Nov 2024

    The PhonePe wallet (aka com.PhonePe.app) application 3.0.6 through 3.3.26 for Android might allow attackers to perform Account Takeover attacks by exploiting its Forgot Password feature. NOTE: the vendor says that, to exploit this, the user has to explicitly install a malicious app and provide accessibility permission to the malicious app, that the Android platform provides fair warnings to the users before turning on accessibility for any application, and that it believes it is similar to installing malicious keyboards, or malicious apps taking screenshots

    Published: 23 Sept 2018
    8.8
    High

    CVE-2018-17366

    Last Modified: 19 Feb 2026

    An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.

    Published: 23 Sept 2018
    6.1
    Medium

    CVE-2018-17361

    Last Modified: 21 Nov 2024

    Multiple XSS vulnerabilities in WeaselCMS v0.3.6 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php because $_SERVER['PHP_SELF'] is mishandled.

    Published: 23 Sept 2018
    8.1
    High

    CVE-2018-17364

    Last Modified: 21 Nov 2024

    OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter.

    Published: 23 Sept 2018
    7.8
    High

    CVE-2018-17338

    Last Modified: 21 Nov 2024

    An issue has been found in pdfalto through 0.2. It is a heap-based buffer overflow in the function TextPage::dump in XmlAltoOutputDev.cc.

    Published: 23 Sept 2018
    8.1
    High

    CVE-2018-17341

    Last Modified: 21 Nov 2024

    BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, as demonstrated by a launch.php?bigtree_htaccess_url=admin/images/..\ URI.

    Published: 23 Sept 2018
    7.5
    High

    CVE-2018-21035

    Last Modified: 21 Nov 2024

    In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).

    Published: 23 Sept 2018
    7.8
    High

    CVE-2018-17407

    Last Modified: 21 Nov 2024

    An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution when a malicious font is loaded by one of the vulnerable tools: pdflatex, pdftex, dvips, or luatex.

    Published: 23 Sept 2018
    9.8
    Critical

    CVE-2018-19198

    Last Modified: 21 Nov 2024

    An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.

    Published: 23 Sept 2018
    7.5
    High

    CVE-2018-19200

    Last Modified: 21 Nov 2024

    An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetUri* function.

    Published: 23 Sept 2018
    9.8
    Critical

    CVE-2018-19199

    Last Modified: 21 Nov 2024

    An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.

    Published: 23 Sept 2018
    9.8
    Critical

    CVE-2018-17333

    Last Modified: 21 Nov 2024

    An issue was discovered in libsvg2 through 2012-10-19. A stack-based buffer overflow in svgStringToLength in svg_types.c allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because sscanf is misused.

    Published: 22 Sept 2018
    9.8
    Critical

    CVE-2018-17334

    Last Modified: 21 Nov 2024

    An issue was discovered in libsvg2 through 2012-10-19. A stack-based buffer overflow in the svgGetNextPathField function in svg_string.c allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because a strncpy copy limit is miscalculated.

    Published: 22 Sept 2018
    7.5
    High

    CVE-2018-17332

    Last Modified: 21 Nov 2024

    An issue was discovered in libsvg2 through 2012-10-19. The svgGetNextPathField function in svg_string.c returns its input pointer in certain circumstances, which might result in a memory leak caused by wasteful malloc calls.

    Published: 22 Sept 2018
    6.1
    Medium

    CVE-2018-17322

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in index.php/index/category/index in YUNUCMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the area parameter.

    Published: 22 Sept 2018
    6.1
    Medium

    CVE-2018-17321

    Last Modified: 21 Nov 2024

    An issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorandomset action.

    Published: 22 Sept 2018
    7.5
    High

    CVE-2018-14647

    Last Modified: 21 Nov 2024

    Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5.0 through 3.5.6, 3.4.0 through 3.4.9, 2.7.0 through 2.7.15.

    Published: 22 Sept 2018
    7.8
    High

    CVE-2018-17336

    Last Modified: 21 Nov 2024

    UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c, allowing attackers to obtain sensitive information (stack contents), cause a denial of service (memory corruption), or possibly have unspecified other impact via a malformed filesystem label, as demonstrated by %d or %n substrings.

    Published: 22 Sept 2018
    7.8
    High

    CVE-2018-14891

    Last Modified: 21 Nov 2024

    Management Console in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local privilege escalation vulnerability.

    Published: 21 Sept 2018
    7.8
    High

    CVE-2018-14889

    Last Modified: 21 Nov 2024

    CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability.

    Published: 21 Sept 2018