CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-16836

    Last Modified: 21 Nov 2024

    Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /theme/default/img/%2e%2e/..//etc/passwd URI.

    Published: 11 Sept 2018
    6.1
    Medium

    CVE-2018-2452

    Last Modified: 21 Nov 2024

    The logon application of SAP NetWeaver AS Java 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50 does not sufficiently encode user-controlled inputs, resulting in a cross-site scripting (XSS) vulnerability.

    Published: 11 Sept 2018
    6.5
    Medium

    CVE-2018-2457

    Last Modified: 21 Nov 2024

    Under certain conditions SAP Adaptive Server Enterprise, version 16.0, allows some privileged users to access information which would otherwise be restricted.

    Published: 11 Sept 2018
    7.5
    High

    CVE-2018-2458

    Last Modified: 21 Nov 2024

    Under certain conditions, Crystal Report using SAP Business One, versions 9.2 and 9.3, connection type allows an attacker to access information which would otherwise be restricted.

    Published: 11 Sept 2018
    7.5
    High

    CVE-2018-2459

    Last Modified: 21 Nov 2024

    Users of an SAP Mobile Platform (version 3.0) Offline OData application, which uses Offline OData-supplied delta tokens (which is on by default), occasionally receive some data values of a different user.

    Published: 11 Sept 2018
    5.9
    Medium

    CVE-2018-2460

    Last Modified: 21 Nov 2024

    SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM attack.

    Published: 11 Sept 2018
    8.8
    High

    CVE-2018-2461

    Last Modified: 21 Nov 2024

    Missing authorization check in SAP HCM Fiori "People Profile" (GBX01 HR version 6.0) for an authenticated user which may result in an escalation of privileges.

    Published: 11 Sept 2018
    8.8
    High

    CVE-2018-2462

    Last Modified: 21 Nov 2024

    In certain cases, BEx Web Java Runtime Export Web Service in SAP NetWeaver BI 7.30, 7.31. 7.40, 7.41, 7.50, does not sufficiently validate an XML document accepted from an untrusted source.

    Published: 11 Sept 2018
    7.5
    High

    CVE-2018-2465

    Last Modified: 21 Nov 2024

    SAP HANA (versions 1.0 and 2.0) Extended Application Services classic model OData parser does not sufficiently validate XML. By exploiting, an unauthorized hacker can cause the database server to crash.

    Published: 11 Sept 2018
    8.8
    High

    CVE-2018-2455

    Last Modified: 21 Nov 2024

    SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_SEPA) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

    Published: 11 Sept 2018
    6.1
    Medium

    CVE-2018-2464

    Last Modified: 21 Nov 2024

    SAP WebDynpro Java, versions 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in a stored Cross-Site Scripting (XSS) vulnerability.

    Published: 11 Sept 2018
    8.8
    High

    CVE-2018-2454

    Last Modified: 21 Nov 2024

    SAP Enterprise Financial Services, versions 6.05, 6.06, 6.16, 6.17, 6.18, 8.0 (in business function EAFS_BCA_BUSOPR_2) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

    Published: 11 Sept 2018
    8.6
    High

    CVE-2018-2463

    Last Modified: 21 Nov 2024

    The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (SSRF) attacks. This is due to a misconfiguration of XML parser that is used in the server-side implementation of OCC.

    Published: 11 Sept 2018
    5.3
    Medium

    CVE-2018-6976

    Last Modified: 21 Nov 2024

    The VMware Content Locker for iOS prior to 4.14 contains a data protection vulnerability in the SQLite database. This vulnerability relates to unencrypted filenames and associated metadata in SQLite database for the Content Locker.

    Published: 11 Sept 2018
    5.5
    Medium

    CVE-2018-6975

    Last Modified: 21 Nov 2024

    The AirWatch Agent for iOS prior to 5.8.1 contains a data protection vulnerability whereby the files and keychain entries in the Agent are not encrypted.

    Published: 11 Sept 2018
    5.9
    Medium

    CVE-2018-16831

    Last Modified: 21 Nov 2024

    Smarty before 3.1.33-dev-4 allows attackers to bypass the trusted_dir protection mechanism via a file:./../ substring in an include statement.

    Published: 11 Sept 2018
    6.5
    Medium

    CVE-2018-16832

    Last Modified: 21 Nov 2024

    CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of the X-Forwarded-Host HTTP header.

    Published: 11 Sept 2018
    5.3
    Medium

    CVE-2016-7073

    Last Modified: 21 Nov 2024

    An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing check of the TSIG time and fudge values was found in AXFRRetriever, leading to a possible replay attack.

    Published: 11 Sept 2018
    5.3
    Medium

    CVE-2016-7074

    Last Modified: 21 Nov 2024

    An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing check that the TSIG record is the last one, leading to the possibility of parsing records that are not covered by the TSIG signature.

    Published: 11 Sept 2018
    5.3
    Medium

    CVE-2016-7068

    Last Modified: 21 Nov 2024

    An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacker to cause an abnormal CPU usage load on the PowerDNS server by sending crafted DNS queries, which might result in a partial denial of service if the system becomes overloaded. This issue is based on the fact that the PowerDNS server parses all records present in a query regardless of whether they are needed or even legitimate. A specially crafted query containing a large number of records can be used to take advantage of that behaviour.

    Published: 11 Sept 2018
    5.9
    Medium

    CVE-2016-7069

    Last Modified: 21 Nov 2024

    An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a backend. When dnsdist is configured to add EDNS Client Subnet to a query, the response may contain an EDNS0 OPT record that has to be removed before forwarding the response to the initial client. On a 32-bit system, the pointer arithmetic used when parsing the received response to remove that record might trigger an undefined behavior leading to a crash.

    Published: 11 Sept 2018
    8.8
    High

    CVE-2018-1571

    Last Modified: 21 Nov 2024

    IBM QRadar 7.2 and 7.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 143121.

    Published: 11 Sept 2018
    7.5
    High

    CVE-2018-16807

    Last Modified: 21 Nov 2024

    In Bro through 2.5.5, there is a memory leak potentially leading to DoS in scripts/base/protocols/krb/main.bro in the Kerberos protocol parser.

    Published: 11 Sept 2018
    8.1
    High

    CVE-2019-6251

    Last Modified: 21 Nov 2024

    WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.

    Published: 11 Sept 2018
    7.8
    High

    CVE-2018-16741

    Last Modified: 21 Nov 2024

    An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanitize shell metacharacters to prevent command injection. It is possible to use the ||, &&, or > characters within a file created by the "faxq-helper activate <jobid>" command.

    Published: 11 Sept 2018
    8.8
    High

    CVE-2018-17458

    Last Modified: 21 Nov 2024

    An improper update of the WebAssembly dispatch table in WebAssembly in Google Chrome prior to 69.0.3497.92 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

    Published: 11 Sept 2018
    7.5
    High

    CVE-2018-15967

    Last Modified: 21 Nov 2024

    Adobe Flash Player versions 30.0.0.154 and earlier have a privilege escalation vulnerability. Successful exploitation could lead to information disclosure.

    Published: 11 Sept 2018
    6.5
    Medium

    CVE-2018-17459

    Last Modified: 21 Nov 2024

    Incorrect handling of clicks in the omnibox in Navigation in Google Chrome prior to 69.0.3497.92 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 11 Sept 2018
    7.5
    High

    CVE-2018-8409

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.

    Published: 11 Sept 2018
    4.8
    Medium

    CVE-2018-16805

    Last Modified: 21 Nov 2024

    In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link JSON field, allows remote attackers to inject arbitrary Web scripts or HTML via a crafted site name provided by an administrator.

    Published: 10 Sept 2018
    6.5
    Medium

    CVE-2018-16806

    Last Modified: 21 Nov 2024

    A Pektron Passive Keyless Entry and Start (PKES) system, as used on the Tesla Model S and possibly other vehicles, relies on the DST40 cipher, which makes it easier for attackers to obtain access via an approach involving a 5.4 TB precomputation, followed by wake-frame reception and two challenge/response operations, to clone a key fob within a few seconds.

    Published: 10 Sept 2018
    9.9
    Critical

    CVE-2018-3875

    Last Modified: 21 Nov 2024

    An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. The strncpy overflows the destination buffer, which has a size of 2,000 bytes. An attacker can send an arbitrarily long "sessionToken" value in order to exploit this vulnerability.

    Published: 10 Sept 2018
    9.8
    Critical

    CVE-2018-16705

    Last Modified: 21 Nov 2024

    FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the system's usernames and passwords. This includes the Admin and Service user accounts and their unsalted MD5 hashes, as well as the SMS server password in cleartext.

    Published: 10 Sept 2018
    7.5
    High

    CVE-2018-12608

    Last Modified: 21 Nov 2024

    An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client with any domain validated certificate signed by a system-trusted root CA (as opposed to one signed by the configured CA root certificate) to authenticate.

    Published: 10 Sept 2018
    5.3
    Medium

    CVE-2016-7072

    Last Modified: 21 Nov 2024

    An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to cause a denial of service by opening a large number of TCP connections to the web server. If the web server runs out of file descriptors, it triggers an exception and terminates the whole PowerDNS process. While it's more complicated for an unauthorized attacker to make the web server run out of file descriptors since its connection will be closed just after being accepted, it might still be possible.

    Published: 10 Sept 2018
    9.8
    Critical

    CVE-2018-16591

    Last Modified: 21 Nov 2024

    FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_changepassword.cgi and /cgi-bin/sm_sms_changepasswd.cgi.

    Published: 10 Sept 2018
    7.4
    High

    CVE-2016-9048

    Last Modified: 21 Nov 2024

    Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain setups access the underlying operating system.

    Published: 10 Sept 2018
    7.8
    High

    CVE-2018-16802

    Last Modified: 21 Nov 2024

    An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. This is due to an incomplete fix for CVE-2018-16509.

    Published: 10 Sept 2018
    4.7
    Medium

    CVE-2018-14620

    Last Modified: 21 Nov 2024

    The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially allow an attacker to serve malicious code to the image builder and install in the resultant container image. Version of openstack-rabbitmq-container and openstack-containers as shipped with Red Hat Openstack 12, 13, 14 are believed to be vulnerable.

    Published: 10 Sept 2018
    8.8
    High

    CVE-2018-3897

    Last Modified: 21 Nov 2024

    An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub with Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. The strncpy call overflows the destination buffer, which has a size of 52 bytes. An attacker can send an arbitrarily long "callbackUrl" value in order to exploit this vulnerability.

    Published: 10 Sept 2018
    8.8
    High

    CVE-2018-3896

    Last Modified: 21 Nov 2024

    An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub with Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. The strncpy call overflows the destination buffer, which has a size of 52 bytes. An attacker can send an arbitrarily long "correlationId" value in order to exploit this vulnerability.

    Published: 10 Sept 2018
    6.5
    Medium

    CVE-2016-7067

    Last Modified: 21 Nov 2024

    Monit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an attacker to disable/enable all monitoring for a particular host or disable/enable monitoring for a specific service.

    Published: 10 Sept 2018
    5.5
    Medium

    CVE-2017-1679

    Last Modified: 21 Nov 2024

    IBM OpenPages GRC Platform 7.2, 7.3, 7.4, and 8.0 could allow an attacker to obtain sensitive information from error log files. IBM X-Force ID: 134001.

    Published: 10 Sept 2018
    8.8
    High

    CVE-2018-16608

    Last Modified: 21 Nov 2024

    In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&action=edit&user_id=1, Insecure Direct Object Reference (IDOR).

    Published: 10 Sept 2018
    7.2
    High

    CVE-2018-15886

    Last Modified: 21 Nov 2024

    Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippet&filename=google-analytics URI, which allows attackers to execute arbitrary PHP code by placing this code after a <?php substring.

    Published: 10 Sept 2018
    7.8
    High

    CVE-2018-16797

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow in PotPlayerMini.exe in PotPlayer 1.7.8556 allows remote attackers to execute arbitrary code via a .wav file with large BytesPerSec and SamplesPerSec values, and a small Data_Chunk_Size value.

    Published: 10 Sept 2018
    8.1
    High

    CVE-2018-16790

    Last Modified: 3 Nov 2025

    _bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read via a crafted bson buffer.

    Published: 10 Sept 2018
    8.8
    High

    CVE-2018-16764

    Last Modified: 21 Nov 2024

    In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an IR::FunctionValidationContext::catch_all heap-based buffer over-read.

    Published: 10 Sept 2018
    8.8
    High

    CVE-2018-16765

    Last Modified: 21 Nov 2024

    In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an unspecified "heap-buffer-overflow" condition in FunctionValidationContext::else_.

    Published: 10 Sept 2018
    8.8
    High

    CVE-2018-16768

    Last Modified: 21 Nov 2024

    In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an unspecified "heap-buffer-overflow" condition in IR::FunctionValidationContext::end.

    Published: 10 Sept 2018