CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-11902

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of length validation check for value received from firmware can lead to OOB access in WLAN HOST.

    Published: 19 Sept 2018
    7.8
    High

    CVE-2018-11903

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of length validation check for value received from caller function used as an array index for WMA interfaces can lead to OOB write in WLAN HOST.

    Published: 19 Sept 2018
    5.5
    Medium

    CVE-2018-3574

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, userspace can request ION cache maintenance on a secure ION buffer for which the ION_FLAG_SECURE ion flag is not set and cause the kernel to attempt to perform cache maintenance on memory which does not belong to HLOS.

    Published: 19 Sept 2018
    7.5
    High

    CVE-2018-17144

    Last Modified: 21 Nov 2024

    Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16.x before 0.16.3 allow a remote denial of service (application crash) exploitable by miners via duplicate input. An attacker can make bitcoind or Bitcoin-Qt crash.

    Published: 19 Sept 2018
    7.5
    High

    CVE-2018-11761

    Last Modified: 21 Nov 2024

    In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.

    Published: 19 Sept 2018
    5.9
    Medium

    CVE-2018-11762

    Last Modified: 21 Nov 2024

    In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.

    Published: 19 Sept 2018
    7.8
    High

    CVE-2018-17183

    Last Modified: 21 Nov 2024

    Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code.

    Published: 19 Sept 2018
    5.5
    Medium

    CVE-2018-17358

    Last Modified: 21 Nov 2024

    An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exists in _bfd_stab_section_find_nearest_line in syms.c. Attackers could leverage this vulnerability to cause a denial of service (application crash) via a crafted ELF file.

    Published: 19 Sept 2018
    5.5
    Medium

    CVE-2018-17359

    Last Modified: 21 Nov 2024

    An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exists in bfd_zalloc in opncls.c. Attackers could leverage this vulnerability to cause a denial of service (application crash) via a crafted ELF file.

    Published: 19 Sept 2018
    8.8
    High

    CVE-2018-17942

    Last Modified: 21 Nov 2024

    The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because memory is not allocated for a trailing '\0' character during %f processing.

    Published: 19 Sept 2018
    5.5
    Medium

    CVE-2018-8017

    Last Modified: 21 Nov 2024

    In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.

    Published: 19 Sept 2018
    6.5
    Medium

    CVE-2018-1000852

    Last Modified: 21 Nov 2024

    FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unknown vulnerability in channels/drdynvc/client/drdynvc_main.c, drdynvc_process_capability_request that can result in The RDP server can read the client's memory.. This attack appear to be exploitable via RDPClient must connect the rdp server with echo option. This vulnerability appears to have been fixed in after commit 205c612820dac644d665b5bb1cdf437dc5ca01e3.

    Published: 19 Sept 2018
    5.5
    Medium

    CVE-2018-17360

    Last Modified: 21 Nov 2024

    An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in bfd_getl32 in libbfd.c allows an attacker to cause a denial of service through a crafted PE file. This vulnerability can be triggered by the executable objdump.

    Published: 19 Sept 2018
    4.4
    Medium

    CVE-2017-3912

    Last Modified: 21 Nov 2024

    Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbitrary command execution via a command-line utility.

    Published: 18 Sept 2018
    7.1
    High

    CVE-2018-6690

    Last Modified: 21 Nov 2024

    Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 and earlier allows authenticated users to execute arbitrary code via file transfer from external system.

    Published: 18 Sept 2018
    5.3
    Medium

    CVE-2018-6693

    Last Modified: 21 Nov 2024

    An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specific scanning sequence, the unprivileged user is able to perform a privilege escalation to delete arbitrary files.

    Published: 18 Sept 2018
    8.8
    High

    CVE-2018-16515

    Last Modified: 21 Nov 2024

    Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.

    Published: 18 Sept 2018
    4.9
    Medium

    CVE-2018-16819

    Last Modified: 21 Nov 2024

    admin/index.php in Monstra CMS 3.0.4 allows arbitrary file deletion via id=filesmanager&path=uploads/.......//./.......//./&delete_file= requests.

    Published: 18 Sept 2018
    7.5
    High

    CVE-2018-16820

    Last Modified: 21 Nov 2024

    admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//./ requests.

    Published: 18 Sept 2018
    7.5
    High

    CVE-2018-13982

    Last Modified: 21 Nov 2024

    Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read arbitrary files.

    Published: 18 Sept 2018
    8.6
    High

    CVE-2018-16794

    Last Modified: 21 Nov 2024

    Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in /adfs/ls.

    Published: 18 Sept 2018
    7.5
    High

    CVE-2018-17071

    Last Modified: 21 Nov 2024

    The fallback function of a simple lottery smart contract implementation for Lucky9io, an Ethereum gambling game, generates a random value with the publicly readable variable entry_number. This variable is private, yet it is readable by eth.getStorageAt function. Also, attackers can purchase a ticket at a low price by directly calling the fallback function with small msg.value, because the developer set the currency unit incorrectly. Therefore, it allows attackers to always win and get rewards.

    Published: 18 Sept 2018
    9.8
    Critical

    CVE-2018-17111

    Last Modified: 21 Nov 2024

    The onlyOwner modifier of a smart contract implementation for Coinlancer (CL), an Ethereum ERC20 token, has a potential access control vulnerability. All contract users can access functions that use this onlyOwner modifier, because the comparison between msg.sender and owner is incorrect.

    Published: 18 Sept 2018
    7.5
    High

    CVE-2018-11071

    Last Modified: 21 Nov 2024

    Dell EMC Isilon OneFS versions 7.1.1.x, 7.2.1.x, 8.0.0.x, 8.0.1.x, 8.1.0.x and 8.1.x prior to 8.1.2 and Dell EMC IsilonSD Edge versions 8.0.0.x, 8.0.1.x, 8.1.0.x and 8.1.x prior to 8.1.2 contain a remote process crash vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to crash the isi_drive_d process by sending specially crafted input data to the affected system. This process will then be restarted.

    Published: 18 Sept 2018
    6.8
    Medium

    CVE-2018-11084

    Last Modified: 21 Nov 2024

    Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file attributes. A remote authenticated malicious user may create and delete apps with crafted file attributes to cause a denial of service for new app instances or scaling up of existing apps.

    Published: 18 Sept 2018
    6.1
    Medium

    CVE-2018-15546

    Last Modified: 21 Nov 2024

    Accusoft PrizmDoc version 13.3 and earlier contains a Stored Cross-Site Scripting issue through a crafted PDF file.

    Published: 18 Sept 2018
    6.5
    Medium

    CVE-2018-16225

    Last Modified: 21 Nov 2024

    The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam application through 1.0.5 for Android and the Swisscom Home application up to 10.7.2 for Android), which results in an attacker being able to reuse cookies to bypass authentication and disable the camera.

    Published: 18 Sept 2018
    Unknown

    CVE-2018-1222

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 18 Sept 2018
    5.3
    Medium

    CVE-2018-16668

    Last Modified: 21 Nov 2024

    An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /html/repository.

    Published: 18 Sept 2018
    9.8
    Critical

    CVE-2018-16669

    Last Modified: 21 Nov 2024

    An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to storage of credentials in XML files, an unprivileged user can look at /services/config/config.xml for the admin credentials of the ocpp and circarlife panels.

    Published: 18 Sept 2018
    5.3
    Medium

    CVE-2018-16671

    Last Modified: 21 Nov 2024

    An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is system software information disclosure due to lack of authentication for /html/device-id.

    Published: 18 Sept 2018
    5.3
    Medium

    CVE-2018-16670

    Last Modified: 21 Nov 2024

    An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html.

    Published: 18 Sept 2018
    6.1
    Medium

    CVE-2017-6913

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the Open-Xchange webmail before 7.6.3-rev28 allows remote attackers to inject arbitrary web script or HTML via the event attribute in a time tag.

    Published: 18 Sept 2018
    Unknown

    CVE-2018-11042

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 18 Sept 2018
    7.8
    High

    CVE-2018-11265

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, possible buffer overflow while incrementing the log_buf of type uint64_t in memcpy function, since the log_buf pointer can access the memory beyond the size to store the data after pointer increment.

    Published: 18 Sept 2018
    7.8
    High

    CVE-2018-11270

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, memory allocated with devm_kzalloc is automatically released by the kernel if the probe function fails with an error code. This may result in data corruption.

    Published: 18 Sept 2018
    7.8
    High

    CVE-2018-11274

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, buffer overflow may occur when payload size is extremely large.

    Published: 18 Sept 2018
    5.5
    Medium

    CVE-2018-11280

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing user-space there is no size validation of the NAT entry input. If the user input size of the NAT entry is greater than the max allowed size, memory exhaustion will occur.

    Published: 18 Sept 2018
    7.8
    High

    CVE-2018-11286

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while accessing global variable "debug_client" in multi-thread manner, Use after free issue occurs

    Published: 18 Sept 2018
    7.8
    High

    CVE-2018-11826

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check on integer overflow while calculating memory can lead to Buffer overflow in WLAN ext scan handler.

    Published: 18 Sept 2018
    7.8
    High

    CVE-2018-11832

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of input size validation before copying to buffer in PMIC function can lead to heap overflow.

    Published: 18 Sept 2018
    7.8
    High

    CVE-2018-11840

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing the WLAN driver command ioctl a temporary buffer used to construct the reply message may be freed twice.

    Published: 18 Sept 2018
    7.8
    High

    CVE-2018-11842

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, during wlan association, driver allocates memory. In case the mem allocation fails driver does a mem free though the memory was not allocated.

    Published: 18 Sept 2018
    7.8
    High

    CVE-2018-11851

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check on input received to calculate the buffer length can lead to out of bound write to kernel stack.

    Published: 18 Sept 2018
    7.8
    High

    CVE-2018-11852

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper check In the WMA API for the inputs received from the firmware and then fills the same to the host structure will lead to OOB write.

    Published: 18 Sept 2018
    7.8
    High

    CVE-2018-11860

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a potential buffer over flow could occur while processing the ndp event due to lack of check on the message length.

    Published: 18 Sept 2018
    7.8
    High

    CVE-2018-11863

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check of input received from firmware to calculate the length of WMA roam synch buffer can lead to buffer overwrite during memcpy.

    Published: 18 Sept 2018
    7.8
    High

    CVE-2018-11868

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of length validation check for value received from firmware can lead to buffer overflow in nan response event handler.

    Published: 18 Sept 2018
    7.8
    High

    CVE-2018-11869

    Last Modified: 21 Nov 2024

    In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of length validation check for value received from firmware can lead to buffer overflow in WMA handler.

    Published: 18 Sept 2018
    7.5
    High

    CVE-2018-17176

    Last Modified: 21 Nov 2024

    A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. There are no nonces, and timestamps are not checked at all.

    Published: 18 Sept 2018