CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-8421

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0.

    Published: 13 Sept 2018
    6.5
    Medium

    CVE-2018-8422

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8424.

    Published: 13 Sept 2018
    5.4
    Medium

    CVE-2018-8426

    Last Modified: 21 Nov 2024

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint.

    Published: 13 Sept 2018
    5.5
    Medium

    CVE-2018-8429

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.

    Published: 13 Sept 2018
    4.7
    Medium

    CVE-2018-8433

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory, aka "Microsoft Graphics Component Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

    Published: 13 Sept 2018
    6.8
    Medium

    CVE-2018-8438

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8436, CVE-2018-8437.

    Published: 13 Sept 2018
    5.9
    Medium

    CVE-2018-8444

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka "Windows SMB Information Disclosure Vulnerability." This affects Windows Server 2012, Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012 R2.

    Published: 13 Sept 2018
    4.3
    Medium

    CVE-2018-8452

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft browsers, aka "Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge.

    Published: 13 Sept 2018
    7.4
    High

    CVE-2018-8469

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8463.

    Published: 13 Sept 2018
    7.5
    High

    CVE-2018-8456

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8354, CVE-2018-8391, CVE-2018-8457, CVE-2018-8459.

    Published: 13 Sept 2018
    7.5
    High

    CVE-2018-8457

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-8354, CVE-2018-8391, CVE-2018-8456, CVE-2018-8459.

    Published: 13 Sept 2018
    7.4
    High

    CVE-2018-8463

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8469.

    Published: 13 Sept 2018
    7.5
    High

    CVE-2018-8464

    Last Modified: 21 Nov 2024

    An remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka "Microsoft Edge PDF Remote Code Execution Vulnerability." This affects Microsoft Edge.

    Published: 13 Sept 2018
    7.5
    High

    CVE-2018-8465

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8367, CVE-2018-8466, CVE-2018-8467.

    Published: 13 Sept 2018
    6.1
    Medium

    CVE-2018-8470

    Last Modified: 21 Nov 2024

    A security feature bypass vulnerability exists in Internet Explorer due to how scripts are handled that allows a universal cross-site scripting (UXSS) condition, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11.

    Published: 13 Sept 2018
    5.3
    Medium

    CVE-2018-16977

    Last Modified: 21 Nov 2024

    Monstra CMS V3.0.4 has an information leakage risk (e.g., PATH, DOCUMENT_ROOT, and SERVER_ADMIN) in libraries/Gelato/ErrorHandler/Resources/Views/Errors/exception.php.

    Published: 12 Sept 2018
    6.1
    Medium

    CVE-2018-16979

    Last Modified: 21 Nov 2024

    Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-2943.

    Published: 12 Sept 2018
    6.1
    Medium

    CVE-2018-16980

    Last Modified: 21 Nov 2024

    dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters.

    Published: 12 Sept 2018
    6.1
    Medium

    CVE-2018-16978

    Last Modified: 21 Nov 2024

    Monstra CMS V3.0.4 has XSS when ones tries to register an account with a crafted password parameter to users/registration, a different vulnerability than CVE-2018-11473.

    Published: 12 Sept 2018
    8.1
    High

    CVE-2018-16976

    Last Modified: 21 Nov 2024

    Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access.

    Published: 12 Sept 2018
    9.8
    Critical

    CVE-2018-16974

    Last Modified: 21 Nov 2024

    An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in apps/filemanager/upload/drop.php by using /filemanager/api/rm/.htaccess to remove the .htaccess file, and then using a filename that ends in .php followed by space characters (for bypassing the blacklist).

    Published: 12 Sept 2018
    9.8
    Critical

    CVE-2018-16975

    Last Modified: 21 Nov 2024

    An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Name field in conjunction with <?php content, because of insufficient input validation in apps/designer/handlers/csspreview.php.

    Published: 12 Sept 2018
    7.3
    High

    CVE-2018-15610

    Last Modified: 21 Nov 2024

    A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Office include 9.1 through 9.1 SP12, 10.0 through 10.0 SP7, and 10.1 through 10.1 SP2.

    Published: 12 Sept 2018
    7.8
    High

    CVE-2018-16962

    Last Modified: 21 Nov 2024

    Webroot SecureAnywhere before 9.0.8.34 on macOS mishandles access to the driver by a process that lacks root privileges.

    Published: 12 Sept 2018
    4.3
    Medium

    CVE-2018-16970

    Last Modified: 21 Nov 2024

    Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to download non-purchased course files via a modified id parameter.

    Published: 12 Sept 2018
    4.3
    Medium

    CVE-2018-16971

    Last Modified: 21 Nov 2024

    Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to access non-purchased course contents (quiz / test) via a modified id parameter.

    Published: 12 Sept 2018
    7.8
    High

    CVE-2018-12148

    Last Modified: 21 Nov 2024

    Privilege escalation in file permissions in Intel Driver and Support Assistant before 3.5.0.1 may allow an authenticated user to potentially execute code as administrator via local access.

    Published: 12 Sept 2018
    5.5
    Medium

    CVE-2018-12149

    Last Modified: 21 Nov 2024

    Buffer overflow in input handling in Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially deny service to the application via local access.

    Published: 12 Sept 2018
    6.7
    Medium

    CVE-2018-12150

    Last Modified: 21 Nov 2024

    Escalation of privilege in Installer for Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially execute code or disclose information as administrator via local access.

    Published: 12 Sept 2018
    5.5
    Medium

    CVE-2018-12151

    Last Modified: 21 Nov 2024

    Buffer overflow in installer for Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially cause a buffer overflow potentially leading to a denial of service via local access.

    Published: 12 Sept 2018
    5.3
    Medium

    CVE-2018-12160

    Last Modified: 21 Nov 2024

    DLL injection vulnerability in software installer for Intel Data Center Migration Center Software v3.1 and before may allow an authenticated user to potentially execute code using default directory permissions via local access.

    Published: 12 Sept 2018
    7.8
    High

    CVE-2018-12162

    Last Modified: 21 Nov 2024

    Directory permissions in the Intel OpenVINO Toolkit for Windows before version 2018.1.265 may allow an authenticated user to potentially execute code using default directory permissions via local access.

    Published: 12 Sept 2018
    4.8
    Medium

    CVE-2018-12163

    Last Modified: 21 Nov 2024

    A DLL injection vulnerability in the Intel IoT Developers Kit 4.0 installer may allow an authenticated user to potentially escalate privileges using file modification via local access.

    Published: 12 Sept 2018
    7.8
    High

    CVE-2018-12168

    Last Modified: 21 Nov 2024

    Privilege escalation in file permissions in Intel Computing Improvement Program before version 2.2.0.03942 may allow an authenticated user to potentially execute code as administrator via local access.

    Published: 12 Sept 2018
    7.8
    High

    CVE-2018-12175

    Last Modified: 21 Nov 2024

    Default install directory permissions in Intel Distribution for Python (IDP) version 2018 may allow an unprivileged user to escalate privileges via local access.

    Published: 12 Sept 2018
    7.5
    High

    CVE-2018-3669

    Last Modified: 21 Nov 2024

    A STOP error (BSoD) in the ibtfltcoex.sys driver for Intel Centrino Wireless N and Intel Centrino Advanced N adapters may allow an unauthenticated user to potentially send a malformed L2CAP Connection Request is sent to the Intel Bluetooth device via the network.

    Published: 12 Sept 2018
    6.7
    Medium

    CVE-2018-3686

    Last Modified: 21 Nov 2024

    Code injection vulnerability in INTEL-SA-00086 Detection Tool before version 1.2.7.0 may allow a privileged user to potentially execute arbitrary code via local access.

    Published: 12 Sept 2018
    9.6
    Critical

    CVE-2018-3679

    Last Modified: 21 Nov 2024

    Escalation of privilege in Reference UI in Intel Data Center Manager SDK 5.0 and before may allow an unauthorized remote unauthenticated user to potentially execute code via administrator privileges.

    Published: 12 Sept 2018
    9.8
    Critical

    CVE-2018-12171

    Last Modified: 21 Nov 2024

    Privilege escalation in Intel Baseboard Management Controller (BMC) firmware before version 1.43.91f76955 may allow an unprivileged user to potentially execute arbitrary code or perform denial of service over the network.

    Published: 12 Sept 2018
    8.2
    High

    CVE-2018-12176

    Last Modified: 21 Nov 2024

    Improper input validation in firmware for Intel NUC Kits may allow a privileged user to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access.

    Published: 12 Sept 2018
    5.9
    Medium

    CVE-2018-3616

    Last Modified: 21 Nov 2024

    Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to potentially obtain the TLS session key via the network.

    Published: 12 Sept 2018
    8.2
    High

    CVE-2018-3643

    Last Modified: 21 Nov 2024

    A vulnerability in Power Management Controller firmware in systems using specific Intel(R) Converged Security and Management Engine (CSME) before version 11.8.55, 11.11.55, 11.21.55, 12.0.6 or Intel(R) Server Platform Services firmware before version 4.x.04 may allow an attacker with administrative privileges to uncover certain platform secrets via local access or to potentially execute arbitrary code.

    Published: 12 Sept 2018
    7.3
    High

    CVE-2018-3655

    Last Modified: 21 Nov 2024

    A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services before version 4.0 and Intel Trusted Execution Engine Firmware before version 3.1.55 may allow an unauthenticated user to potentially modify or disclose information via physical access.

    Published: 12 Sept 2018
    6.7
    Medium

    CVE-2018-3657

    Last Modified: 21 Nov 2024

    Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execution privilege via local access.

    Published: 12 Sept 2018
    5.3
    Medium

    CVE-2018-3658

    Last Modified: 21 Nov 2024

    Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access.

    Published: 12 Sept 2018
    6.8
    Medium

    CVE-2018-3659

    Last Modified: 21 Nov 2024

    A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access.

    Published: 12 Sept 2018
    7.8
    High

    CVE-2018-13412

    Last Modified: 21 Nov 2024

    An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version.

    Published: 12 Sept 2018
    7.5
    High

    CVE-2018-15502

    Last Modified: 21 Nov 2024

    Insecure permissions in Lone Wolf Technologies loadingDOCS 2018-08-13 allow remote attackers to download any confidential files via https requests for predictable URLs.

    Published: 12 Sept 2018
    6.5
    Medium

    CVE-2018-16389

    Last Modified: 21 Nov 2024

    e107_admin/banlist.php in e107 2.1.8 allows SQL injection via the old_ip parameter.

    Published: 12 Sept 2018
    5.4
    Medium

    CVE-2018-16605

    Last Modified: 21 Nov 2024

    D-Link DIR-600M devices allow XSS via the Hostname and Username fields in the Dynamic DNS Configuration page.

    Published: 12 Sept 2018