CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2017-2874

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A specially crafted request on port 10001 can allow for a user to retrieve sensitive information without authentication.

    Published: 17 Sept 2018
    6.5
    Medium

    CVE-2018-14320

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of PoDoFo. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within PdfEncoding::ParseToUnicode. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-5673.

    Published: 17 Sept 2018
    6.5
    Medium

    CVE-2017-14443

    Last Modified: 21 Nov 2024

    An exploitable information leak vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation incorrectly checks the number of GET parameters supplied, leading to an arbitrarily controlled information leak on the whole device memory. An attacker can send an authenticated HTTP request to trigger this vulnerability.

    Published: 17 Sept 2018
    8.8
    High

    CVE-2017-2777

    Last Modified: 21 Nov 2024

    An exploitable heap overflow vulnerability exists in the ipStringCreate function of Iceni Argus Version 6.6.05. A specially crafted pdf file can cause an integer overflow resulting in heap overflow. An attacker can send file to trigger this vulnerability.

    Published: 17 Sept 2018
    8.8
    High

    CVE-2018-1198

    Last Modified: 21 Nov 2024

    Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A malicious user with access to the logs could escalate their privileges using this password.

    Published: 17 Sept 2018
    8.8
    High

    CVE-2018-1223

    Last Modified: 21 Nov 2024

    Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs. A malicious user with the ability to read the application logs could use these credentials to escalate privileges.

    Published: 17 Sept 2018
    8.8
    High

    CVE-2018-11086

    Last Modified: 21 Nov 2024

    Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be able to access an artifact which contains the CF admin credential, allowing them to escalate to an admin role.

    Published: 17 Sept 2018
    8.8
    High

    CVE-2018-11088

    Last Modified: 21 Nov 2024

    Pivotal Applications Manager in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be able to access an artifact which contains the CF admin credential, allowing them to escalate to an admin role.

    Published: 17 Sept 2018
    8.8
    High

    CVE-2016-9045

    Last Modified: 21 Nov 2024

    A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter to trigger this vulnerability.

    Published: 17 Sept 2018
    7.5
    High

    CVE-2018-17143

    Last Modified: 21 Nov 2024

    The html package (aka x/net/html) through 2018-09-17 in Go mishandles <template><tBody><isindex/action=0>, leading to a "panic: runtime error" in inBodyIM in parse.go during an html.Parse call.

    Published: 17 Sept 2018
    7.5
    High

    CVE-2018-17142

    Last Modified: 21 Nov 2024

    The html package (aka x/net/html) through 2018-09-17 in Go mishandles <math><template><mo><template>, leading to a "panic: runtime error" in parseCurrentToken in parse.go during an html.Parse call.

    Published: 17 Sept 2018
    9.8
    Critical

    CVE-2018-17136

    Last Modified: 21 Nov 2024

    zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header.

    Published: 17 Sept 2018
    8.8
    High

    CVE-2018-17139

    Last Modified: 21 Nov 2024

    UltimatePOS 2.5 allows users to upload arbitrary files, which leads to remote command execution by posting to a /products URI with PHP code in a .php file with the image/jpeg content type.

    Published: 17 Sept 2018
    5.4
    Medium

    CVE-2018-17138

    Last Modified: 21 Nov 2024

    The Jibu Pro plugin through 1.7 for WordPress is prone to Stored XSS via the wp-content/plugins/jibu-pro/quiz_action.php name (aka Quiz Name) field.

    Published: 17 Sept 2018
    5.4
    Medium

    CVE-2018-17140

    Last Modified: 21 Nov 2024

    The Quizlord plugin through 2.0 for WordPress is prone to Stored XSS via the title parameter in a ql_insert action to wp-admin/admin.php.

    Published: 17 Sept 2018
    9.8
    Critical

    CVE-2018-17137

    Last Modified: 21 Nov 2024

    Prezi Next 1.3.101.11 has a documented purpose of creating HTML5 presentations but has SE_DEBUG_PRIVILEGE on Windows, which might allow attackers to bypass intended access restrictions.

    Published: 17 Sept 2018
    Unknown

    CVE-2018-16309

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 17 Sept 2018
    9.8
    Critical

    CVE-2018-17110

    Last Modified: 21 Nov 2024

    Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as demonstrated by products/get_products/1.

    Published: 17 Sept 2018
    6.1
    Medium

    CVE-2018-17113

    Last Modified: 21 Nov 2024

    App/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or movieName parameter, a related issue to CVE-2018-9173.

    Published: 17 Sept 2018
    9.8
    Critical

    CVE-2018-17126

    Last Modified: 21 Nov 2024

    CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.

    Published: 17 Sept 2018
    7.5
    High

    CVE-2018-17127

    Last Modified: 21 Nov 2024

    blocking_request.cgi on ASUS GT-AC5300 devices through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (NULL pointer dereference and device crash) via a request that lacks a timestap parameter.

    Published: 17 Sept 2018
    5.4
    Medium

    CVE-2018-17128

    Last Modified: 21 Nov 2024

    A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.

    Published: 17 Sept 2018
    4.9
    Medium

    CVE-2018-17129

    Last Modified: 21 Nov 2024

    MetInfo 6.1.0 has SQL injection in doexport() in app/system/feedback/admin/feedback_admin.class.php via the class1 field.

    Published: 17 Sept 2018
    7.2
    High

    CVE-2018-17131

    Last Modified: 21 Nov 2024

    admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field.

    Published: 17 Sept 2018
    7.2
    High

    CVE-2018-17133

    Last Modified: 21 Nov 2024

    admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting.

    Published: 17 Sept 2018
    7.5
    High

    CVE-2018-17125

    Last Modified: 21 Nov 2024

    CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php.

    Published: 17 Sept 2018
    5.4
    Medium

    CVE-2018-17130

    Last Modified: 21 Nov 2024

    PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header,

    Published: 17 Sept 2018
    7.2
    High

    CVE-2018-17132

    Last Modified: 21 Nov 2024

    admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter.

    Published: 17 Sept 2018
    7.2
    High

    CVE-2018-17134

    Last Modified: 21 Nov 2024

    admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field.

    Published: 17 Sept 2018
    7.8
    High

    CVE-2018-11781

    Last Modified: 21 Nov 2024

    Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.

    Published: 17 Sept 2018
    6.5
    Medium

    CVE-2018-17229

    Last Modified: 21 Nov 2024

    Exiv2::d2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.

    Published: 17 Sept 2018
    5.5
    Medium

    CVE-2018-17985

    Last Modified: 21 Nov 2024

    An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption problem caused by the cplus_demangle_type function making recursive calls to itself in certain scenarios involving many 'P' characters.

    Published: 17 Sept 2018
    5.3
    Medium

    CVE-2017-15705

    Last Modified: 21 Nov 2024

    A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags in emails that cause markup to be handled incorrectly leading to scan timeouts. In Apache SpamAssassin, using HTML::Parser, we setup an object and hook into the begin and end tag event handlers In both cases, the "open" event is immediately followed by a "close" event - even if the tag *does not* close in the HTML being parsed. Because of this, we are missing the "text" event to deal with the object normally. This can cause carefully crafted emails that might take more scan time than expected leading to a Denial of Service. The issue is possibly a bug or design decision in HTML::Parser that specifically impacts the way Apache SpamAssassin uses the module with poorly formed html. The exploit has been seen in the wild but not believed to have been purposefully part of a Denial of Service attempt. We are concerned that there may be attempts to abuse the vulnerability in the future.

    Published: 17 Sept 2018
    9.8
    Critical

    CVE-2018-11780

    Last Modified: 21 Nov 2024

    A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.

    Published: 17 Sept 2018
    6.5
    Medium

    CVE-2018-17230

    Last Modified: 21 Nov 2024

    Exiv2::ul2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.

    Published: 17 Sept 2018
    8.8
    High

    CVE-2018-17108

    Last Modified: 21 Nov 2024

    The SBIbuddy (aka com.sbi.erupee) application 1.41 and 1.42 for Android might allow attackers to perform Account Takeover attacks by intercepting a security-question response during the initial configuration of the application.

    Published: 16 Sept 2018
    6.5
    Medium

    CVE-2018-17096

    Last Modified: 21 Nov 2024

    The BPMDetect class in BPMDetect.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch.

    Published: 16 Sept 2018
    5.4
    Medium

    CVE-2018-17091

    Last Modified: 21 Nov 2024

    An issue was discovered in DonLinkage 6.6.8. It allows remote attackers to obtain potentially sensitive information via a direct request for files/temporary.txt.

    Published: 16 Sept 2018
    5.4
    Medium

    CVE-2018-17092

    Last Modified: 21 Nov 2024

    An issue was discovered in DonLinkage 6.6.8. SQL injection in /pages/proxy/php.php and /pages/proxy/add.php can be exploited via specially crafted input, allowing an attacker to obtain information from a database. The vulnerability can only be triggered by an authorized user.

    Published: 16 Sept 2018
    Unknown

    CVE-2018-17093

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11125. Reason: This candidate is a duplicate of CVE-2017-11125. Notes: All CVE users should reference CVE-2017-11125 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Sept 2018
    Unknown

    CVE-2018-17094

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11124. Reason: This candidate is a duplicate of CVE-2017-11124. Notes: All CVE users should reference CVE-2017-11124 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Sept 2018
    8.8
    High

    CVE-2018-17102

    Last Modified: 21 Nov 2024

    An issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2. A CSRF vulnerability can change the administrator password via the user/me URI.

    Published: 16 Sept 2018
    8.8
    High

    CVE-2018-17103

    Last Modified: 21 Nov 2024

    An issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's password via admin/settings.php. NOTE: The vendor reported that the PoC was sending a value for the nonce parameter

    Published: 16 Sept 2018
    7.5
    High

    CVE-2018-17106

    Last Modified: 21 Nov 2024

    In Tinyftp Tinyftpd 1.1, a buffer overflow exists in the text variable of the do_mkd function in the ftpproto.c file. An attacker can overwrite ebp via a long pathname.

    Published: 16 Sept 2018
    8.8
    High

    CVE-2018-17104

    Last Modified: 21 Nov 2024

    An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrative account via api/save_user.

    Published: 16 Sept 2018
    5.4
    Medium

    CVE-2018-17090

    Last Modified: 21 Nov 2024

    An issue was discovered in DonLinkage 6.6.8. The modules /pages/bazy/bazy_adresow.php and /pages/proxy/add.php are vulnerable to stored XSS that can be triggered by closing <textarea> followed by <script></script> tags.

    Published: 16 Sept 2018
    8.8
    High

    CVE-2018-17097

    Last Modified: 21 Nov 2024

    The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (double free) or possibly have unspecified other impact, as demonstrated by SoundStretch.

    Published: 16 Sept 2018
    8.8
    High

    CVE-2018-17098

    Last Modified: 21 Nov 2024

    The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch.

    Published: 16 Sept 2018
    6.1
    Medium

    CVE-2018-17062

    Last Modified: 21 Nov 2024

    An issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isunion, v_recycled, v_ismoney, or v_ispsd parameter.

    Published: 16 Sept 2018
    6.1
    Medium

    CVE-2018-17085

    Last Modified: 21 Nov 2024

    An issue was discovered in OTCMS 3.61. XSS exists in admin/users.php via these parameters: dataTypeCN dataMode dataModeStr.

    Published: 16 Sept 2018