CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2018-17282

    Last Modified: 21 Nov 2024

    An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.

    Published: 20 Sept 2018
    6.5
    Medium

    CVE-2018-17235

    Last Modified: 21 Nov 2024

    The function mp4v2::impl::MP4Track::FinishSdtp() in mp4track.cpp in libmp4v2 2.1.0 mishandles compatibleBrand while processing a crafted mp4 file, which leads to a heap-based buffer over-read, causing denial of service.

    Published: 20 Sept 2018
    6.5
    Medium

    CVE-2018-17236

    Last Modified: 21 Nov 2024

    The function MP4Free() in mp4property.cpp in libmp4v2 2.1.0 internally calls free() on a invalid pointer, raising a SIGABRT signal.

    Published: 20 Sept 2018
    6.5
    Medium

    CVE-2018-17234

    Last Modified: 21 Nov 2024

    Memory leak in the H5O__chunk_deserialize() function in H5Ocache.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.

    Published: 20 Sept 2018
    6.5
    Medium

    CVE-2018-5741

    Last Modified: 21 Nov 2024

    To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides a feature called update-policy. Various rules can be configured to limit the types of updates that can be performed by a client, depending on the key used when sending the update request. Unfortunately, some rule types were not initially documented, and when documentation for them was added to the Administrator Reference Manual (ARM) in change #3112, the language that was added to the ARM at that time incorrectly described the behavior of two rule types, krb5-subdomain and ms-subdomain. This incorrect documentation could mislead operators into believing that policies they had configured were more restrictive than they actually were. This affects BIND versions prior to BIND 9.11.5 and BIND 9.12.3.

    Published: 20 Sept 2018
    9.8
    Critical

    CVE-2018-14643

    Last Modified: 21 Nov 2024

    An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instances, in a highly privileged context.

    Published: 20 Sept 2018
    7.5
    High

    CVE-2018-17231

    Last Modified: 21 Nov 2024

    Telegram Desktop (aka tdesktop) 1.3.14 might allow attackers to cause a denial of service (assertion failure and application exit) via an "Edit color palette" search that triggers an "index out of range" condition. NOTE: this issue is disputed by multiple third parties because the described attack scenario does not cross a privilege boundary

    Published: 19 Sept 2018
    9.8
    Critical

    CVE-2018-17228

    Last Modified: 21 Nov 2024

    nmap4j 1.1.0 allows attackers to execute arbitrary commands via shell metacharacters in an includeHosts call.

    Published: 19 Sept 2018
    4.7
    Medium

    CVE-2018-8889

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability in the Connect Service of the BlackBerry Enterprise Mobility Server (BEMS) 2.8.17.29 and earlier could allow an attacker to retrieve arbitrary files in the context of a BEMS administrator account.

    Published: 19 Sept 2018
    5.4
    Medium

    CVE-2018-3823

    Last Modified: 21 Nov 2024

    X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. Users with manage_ml permissions could create jobs containing malicious data as part of their configuration that could allow the attacker to obtain sensitive information from or perform destructive actions on behalf of other ML users viewing the results of the jobs.

    Published: 19 Sept 2018
    6.5
    Medium

    CVE-2018-3826

    Last Modified: 21 Nov 2024

    In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users able to query the _snapshot API.

    Published: 19 Sept 2018
    8.1
    High

    CVE-2018-3827

    Last Modified: 21 Nov 2024

    A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azure plugin is set to log at TRACE level Azure credentials can be inadvertently logged.

    Published: 19 Sept 2018
    7.5
    High

    CVE-2018-3828

    Last Modified: 21 Nov 2024

    Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception conditions would result in encryption keys, passwords, and other security sensitive headers being leaked to the allocator logs. An attacker with access to the logging cluster may obtain leaked credentials and perform authenticated actions using these credentials.

    Published: 19 Sept 2018
    5.3
    Medium

    CVE-2018-3829

    Last Modified: 21 Nov 2024

    In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles token. An attacker with access to the previous runner ID and IP address of the coordinator-host could add a allocator to an existing ECE install to gain access to other clusters data.

    Published: 19 Sept 2018
    6.1
    Medium

    CVE-2018-3824

    Last Modified: 21 Nov 2024

    X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an index that has a ML job running against it, then when another user views the results of the ML job it could allow the attacker to obtain sensitive information from or perform destructive actions on behalf of that other ML user.

    Published: 19 Sept 2018
    5.9
    Medium

    CVE-2018-3825

    Last Modified: 21 Nov 2024

    In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, this master key is predictable across all ECE deployments. If an attacker can connect to ZooKeeper directly they would be able to access configuration information of other tenants if their cluster ID is known.

    Published: 19 Sept 2018
    7.2
    High

    CVE-2017-2873

    Last Modified: 21 Nov 2024

    An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during the SoftAP configuration resulting in command injection. An attacker can simply send an HTTP request to the device to trigger this vulnerability.

    Published: 19 Sept 2018
    7.5
    High

    CVE-2017-2876

    Last Modified: 21 Nov 2024

    An exploitable buffer overflow vulnerability exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A specially crafted request on port 10000 can cause a buffer overflow resulting in overwriting arbitrary data.

    Published: 19 Sept 2018
    9.8
    Critical

    CVE-2017-2877

    Last Modified: 21 Nov 2024

    A missing error check exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A specially crafted request on port 10001 could allow an attacker to reset the user accounts to factory defaults, without authentication.

    Published: 19 Sept 2018
    8.8
    High

    CVE-2018-17208

    Last Modified: 21 Nov 2024

    Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cgi-bin/zbtest2.cgi (scripts that can be discovered with binwalk on the firmware, but are not visible in the web interface). This occurs because shell metacharacters in the query string are mishandled by ShellExecute, as demonstrated by the zbtest.cgi?cmd=level&level= substring. This can also be exploited via CSRF.

    Published: 19 Sept 2018
    4.9
    Medium

    CVE-2018-17206

    Last Modified: 21 Nov 2024

    An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.

    Published: 19 Sept 2018
    8.1
    High

    CVE-2017-2855

    Last Modified: 21 Nov 2024

    An exploitable buffer overflow vulnerability exists in the DDNS client used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. On devices with DDNS enabled, an attacker who is able to intercept HTTP connections will be able to fully compromise the device by creating a rogue HTTP server.

    Published: 19 Sept 2018
    5.3
    Medium

    CVE-2017-2879

    Last Modified: 21 Nov 2024

    An exploitable buffer overflow vulnerability exists in the UPnP implementation used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A specially crafted UPnP discovery response can cause a buffer overflow resulting in overwriting arbitrary data. An attacker needs to be in the same subnetwork and reply to a discovery message to trigger this vulnerability.

    Published: 19 Sept 2018
    9.8
    Critical

    CVE-2018-17207

    Last Modified: 2 Feb 2026

    An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.

    Published: 19 Sept 2018
    9.1
    Critical

    CVE-2017-2875

    Last Modified: 21 Nov 2024

    An exploitable buffer overflow vulnerability exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A specially crafted request on port 10000 can cause a buffer overflow resulting in overwriting arbitrary data.

    Published: 19 Sept 2018
    7.5
    High

    CVE-2017-2878

    Last Modified: 21 Nov 2024

    An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A specially crafted HTTP request can cause a buffer overflow resulting in overwriting arbitrary data. An attacker can simply send an HTTP request to the device to trigger this vulnerability.

    Published: 19 Sept 2018
    4.3
    Medium

    CVE-2018-17204

    Last Modified: 21 Nov 2024

    An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. This causes an assertion failure (via OVS_NOT_REACHED). ovs-vswitchd does not enable support for OpenFlow 1.5 by default.

    Published: 19 Sept 2018
    7.5
    High

    CVE-2018-17205

    Last Modified: 21 Nov 2024

    An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit, flows that are added in a bundle are applied to ofproto in order. If a flow cannot be added (e.g., the flow action is a go-to for a group id that does not exist), OvS tries to revert back all previous flows that were successfully applied from the same bundle. This is possible since OvS maintains list of old flows that were replaced by flows from the bundle. While reinserting old flows, OvS has an assertion failure due to a check on rule state != RULE_INITIALIZED. This would work for new flows, but for an old flow the rule state is RULE_REMOVED. The assertion failure causes an OvS crash.

    Published: 19 Sept 2018
    9.8
    Critical

    CVE-2018-12242

    Last Modified: 21 Nov 2024

    The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially circumvent security mechanisms currently in place and gain access to the system or network.

    Published: 19 Sept 2018
    6.3
    Medium

    CVE-2018-14792

    Last Modified: 21 Nov 2024

    WECON PLC Editor version 1.3.3U may allow an attacker to execute code under the current process when processing project files.

    Published: 19 Sept 2018
    5.4
    Medium

    CVE-2018-16607

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the Orgs Page in Open-AudIT Professional edition in 2.2.7 allows remote attackers to inject arbitrary web script via the Orgs name field.

    Published: 19 Sept 2018
    8.8
    High

    CVE-2018-16785

    Last Modified: 21 Nov 2024

    XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, which can be utilized by attackers to create script file to obtain webshell

    Published: 19 Sept 2018
    6.5
    Medium

    CVE-2018-1782

    Last Modified: 21 Nov 2024

    IBM GPFS (IBM Spectrum Scale 5.0.1.0 and 5.0.1.1) allows a local, unprivileged user to cause a kernel panic on a node running GPFS by accessing a file that is stored on a GPFS file system with mmap, or by executing a crafted file stored on a GPFS file system. IBM X-Force ID: 148805.

    Published: 19 Sept 2018
    8.8
    High

    CVE-2018-12243

    Last Modified: 21 Nov 2024

    The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI schemes or relative paths in the system identifier to access files that should not normally be accessible.

    Published: 19 Sept 2018
    7.5
    High

    CVE-2017-1794

    Last Modified: 21 Nov 2024

    IBM Tivoli Monitoring 6.2.3 through 6.2.3.5 and 6.3.0 through 6.3.0.7 are vulnerable to both TEPS user privilege escalation and possible denial of service due to unconstrained memory growth. IBM X-Force ID: 137039.

    Published: 19 Sept 2018
    9.8
    Critical

    CVE-2018-1149

    Last Modified: 21 Nov 2024

    cgi_system in NUUO's NVRMini2 3.8.0 and below allows remote attackers to execute arbitrary code via crafted HTTP requests.

    Published: 19 Sept 2018
    7.3
    High

    CVE-2018-1150

    Last Modified: 21 Nov 2024

    NUUO's NVRMini2 3.8.0 and below contains a backdoor that would allow an unauthenticated remote attacker to take over user accounts if the file /tmp/moses exists.

    Published: 19 Sept 2018
    7.8
    High

    CVE-2018-11878

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, possibility of invalid memory access while processing driver command in WLAN function.

    Published: 19 Sept 2018
    7.8
    High

    CVE-2018-11883

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, in policy mgr unit test if mode parameter in wlan function is given an out of bound value it can cause an out of bound access while accessing the PCL table.

    Published: 19 Sept 2018
    7.8
    High

    CVE-2018-11889

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, when requesting rssi timeout, access invalid memory may occur since local variable 'context' stack data of wlan function is free.

    Published: 19 Sept 2018
    8.8
    High

    CVE-2018-11891

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check on the length of array while accessing can lead to an out of bound read in WLAN HOST function.

    Published: 19 Sept 2018
    7.8
    High

    CVE-2018-11895

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper length check Validation in WLAN function can lead to driver writes the default rsn capabilities to the memory not allocated to the frame.

    Published: 19 Sept 2018
    7.8
    High

    CVE-2018-11897

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing diag event after associating to a network out of bounds read occurs if ssid of the network joined is greater than max limit.

    Published: 19 Sept 2018
    7.8
    High

    CVE-2018-11904

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, asynchronous callbacks received a pointer to a callers local variable. Should the caller return early (e.g., timeout), the callback will dereference an invalid pointer.

    Published: 19 Sept 2018
    7.8
    High

    CVE-2018-3573

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while relocating kernel images with a specially crafted boot image, an out of bounds access can occur.

    Published: 19 Sept 2018
    7
    High

    CVE-2018-5905

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a race condition while accessing num of clients in DIAG services can lead to out of boundary access.

    Published: 19 Sept 2018
    7.8
    High

    CVE-2018-11886

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check while calculating the MPDU data length will cause an integer overflow and then to buffer overflow in WLAN function.

    Published: 19 Sept 2018
    7.8
    High

    CVE-2018-11893

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing vendor scan request, when input argument - length of request IEs is greater than maximum can lead to a buffer overflow.

    Published: 19 Sept 2018
    7.8
    High

    CVE-2018-11898

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing start bss request from upper layer, out of bounds read occurs if ssid length is greater than maximum.

    Published: 19 Sept 2018
    7.8
    High

    CVE-2018-11894

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing preferred network offload scan results integer overflow may lead to buffer overflow when large frame length is received from FW.

    Published: 19 Sept 2018