CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-7937

    Last Modified: 21 Nov 2024

    In Huawei HiRouter-CD20-10 with the versions before 1.9.6 and WS5200-10 with the versions before 1.9.6, there is a plug-in signature bypass vulnerability due to insufficient plug-in verification. An attacker may tamper with a legitimate plug-in to build a malicious plug-in and trick users into installing it. Successful exploit could allow the attacker to obtain the root permission of the device and take full control over the device.

    Published: 4 Sept 2018
    3.3
    Low

    CVE-2018-7938

    Last Modified: 21 Nov 2024

    P10 Huawei smartphones with the versions before Victoria-AL00AC00B217 have an information leak vulnerability due to the lack of permission validation. An attacker tricks a user into installing a malicious application on the smart phone, and the application can read some hardware serial number, which may cause sensitive information leak.

    Published: 4 Sept 2018
    4.6
    Medium

    CVE-2018-7990

    Last Modified: 21 Nov 2024

    Mate10 Pro Huawei smart phones with the versions before 8.1.0.326(C00) have a FRP bypass vulnerability. During the mobile phone reseting process, an attacker could bypass "Find My Phone" protect after a series of voice and keyboard operations. Successful exploit could allow an attacker to bypass FRP.

    Published: 4 Sept 2018
    7.8
    High

    CVE-2018-11262

    Last Modified: 21 Nov 2024

    In Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel while trying to find out total number of partition via a non zero check, there could be possibility where the 'TotalPart' could cross 'GptHeader->MaxPtCnt' and which could result in OOB write in patching GPT.

    Published: 4 Sept 2018
    4.6
    Medium

    CVE-2018-7936

    Last Modified: 21 Nov 2024

    Mate 10 Pro Huawei smart phones with the versions before BLA-L29 8.0.0.148(C432) have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can connect the phone with PC and send special instructions to install third party desktop and disable the boot wizard. As a result, the FRP function is bypassed.

    Published: 4 Sept 2018
    7.8
    High

    CVE-2018-0656

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in The installer of Digital Paper App version 1.4.0.16050 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 4 Sept 2018
    9.8
    Critical

    CVE-2018-0664

    Last Modified: 21 Nov 2024

    A vulnerability in NoMachine App for Android 5.0.63 and earlier allows attackers to alter environment variables via unspecified vectors.

    Published: 4 Sept 2018
    6.1
    Medium

    CVE-2018-0672

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Movable Type versions prior to Ver. 6.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Sept 2018
    7.8
    High

    CVE-2018-0646

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in Explzh v.7.58 and earlier allows an attacker to read arbitrary files via unspecified vectors.

    Published: 4 Sept 2018
    7.8
    High

    CVE-2018-0674

    Last Modified: 21 Nov 2024

    AttacheCase ver.2.8.4.0 and earlier allows an arbitrary script execution via unspecified vectors.

    Published: 4 Sept 2018
    7.8
    High

    CVE-2018-0675

    Last Modified: 21 Nov 2024

    AttacheCase ver.3.3.0.0 and earlier allows an arbitrary script execution via unspecified vectors.

    Published: 4 Sept 2018
    6.5
    Medium

    CVE-2018-16458

    Last Modified: 21 Nov 2024

    An issue was discovered in baigo CMS v2.1.1. There is an index.php?m=article&c=request CSRF that can cause publication of any article.

    Published: 4 Sept 2018
    8.8
    High

    CVE-2018-10904

    Last Modified: 21 Nov 2024

    It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exploit this attacker would require sufficient access to modify the extended attributes of files on a gluster volume.

    Published: 4 Sept 2018
    6.5
    Medium

    CVE-2018-10913

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.

    Published: 4 Sept 2018
    8.1
    High

    CVE-2018-10923

    Last Modified: 21 Nov 2024

    It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs server node.

    Published: 4 Sept 2018
    8.1
    High

    CVE-2018-10927

    Last Modified: 21 Nov 2024

    A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by crashing gluster brick process.

    Published: 4 Sept 2018
    8.8
    High

    CVE-2018-10907

    Last Modified: 21 Nov 2024

    It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume and sending a string longer that the fixed buffer size to cause crash or potential code execution.

    Published: 4 Sept 2018
    7.5
    High

    CVE-2018-10911

    Last Modified: 21 Nov 2024

    A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.

    Published: 4 Sept 2018
    6.5
    Medium

    CVE-2018-10914

    Last Modified: 21 Nov 2024

    It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks and gluster volumes.

    Published: 4 Sept 2018
    5.3
    Medium

    CVE-2018-10924

    Last Modified: 21 Nov 2024

    It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.

    Published: 4 Sept 2018
    8.8
    High

    CVE-2018-10926

    Last Modified: 21 Nov 2024

    A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execute arbitrary code on a glusterfs server node.

    Published: 4 Sept 2018
    8.8
    High

    CVE-2018-10928

    Last Modified: 21 Nov 2024

    A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.

    Published: 4 Sept 2018
    8.8
    High

    CVE-2018-10929

    Last Modified: 21 Nov 2024

    A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw to create arbitrary files and execute arbitrary code on glusterfs server nodes.

    Published: 4 Sept 2018
    6.5
    Medium

    CVE-2018-10930

    Last Modified: 21 Nov 2024

    A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume.

    Published: 4 Sept 2018
    9.1
    Critical

    CVE-2018-16444

    Last Modified: 21 Nov 2024

    An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter.

    Published: 4 Sept 2018
    9.8
    Critical

    CVE-2018-16445

    Last Modified: 21 Nov 2024

    An issue was discovered in SeaCMS through 6.61. SQL injection exists via the tid parameter in an adm1n/admin_topic_vod.php request.

    Published: 4 Sept 2018
    7.5
    High

    CVE-2018-16446

    Last Modified: 21 Nov 2024

    An issue was discovered in SeaCMS through 6.61. adm1n/admin_database.php allows remote attackers to delete arbitrary files via directory traversal sequences in the bakfiles parameter. This can allow the product to be reinstalled by deleting install_lock.txt.

    Published: 4 Sept 2018
    8.8
    High

    CVE-2018-16448

    Last Modified: 21 Nov 2024

    Cscms 4 allows CSRF for creating a member via upload/admin.php/user/save, authenticating vip members via upload/admin.php/user/init/tid and upload/admin.php/user/init/rzid, and creating a super administrator and web editor via upload/admin.php/sys/save.

    Published: 4 Sept 2018
    6.5
    Medium

    CVE-2018-16449

    Last Modified: 21 Nov 2024

    OneThink 1.1.141212 allows CSRF for adding a page via admin.php?s=/Channel/add.html, adding a blog via admin.php?s=/Article/update.html, and setting the audit state via admin.php?s=/Article/setStatus/status/1.html.

    Published: 4 Sept 2018
    6.1
    Medium

    CVE-2018-16450

    Last Modified: 21 Nov 2024

    CraftedWeb through 2013-09-24 has reflected XSS via the p parameter.

    Published: 4 Sept 2018
    8.8
    High

    CVE-2018-16447

    Last Modified: 21 Nov 2024

    Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF.

    Published: 4 Sept 2018
    6.5
    Medium

    CVE-2018-16066

    Last Modified: 21 Nov 2024

    A use after free in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Sept 2018
    9.6
    Critical

    CVE-2018-16068

    Last Modified: 21 Nov 2024

    Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

    Published: 4 Sept 2018
    8.8
    High

    CVE-2018-16070

    Last Modified: 21 Nov 2024

    Integer overflows in Skia in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Sept 2018
    8.8
    High

    CVE-2018-16071

    Last Modified: 21 Nov 2024

    A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.

    Published: 4 Sept 2018
    6.5
    Medium

    CVE-2018-16072

    Last Modified: 21 Nov 2024

    A missing origin check related to HLS manifests in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

    Published: 4 Sept 2018
    6.5
    Medium

    CVE-2018-16073

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a crafted HTML page.

    Published: 4 Sept 2018
    6.5
    Medium

    CVE-2018-16074

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a crafted HTML page.

    Published: 4 Sept 2018
    8.8
    High

    CVE-2018-16076

    Last Modified: 21 Nov 2024

    Missing bounds check in PDFium in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.

    Published: 4 Sept 2018
    8.8
    High

    CVE-2018-16083

    Last Modified: 21 Nov 2024

    An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 4 Sept 2018
    8.8
    High

    CVE-2018-16085

    Last Modified: 21 Nov 2024

    A use after free in ResourceCoordinator in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Sept 2018
    6.5
    Medium

    CVE-2018-16088

    Last Modified: 21 Nov 2024

    A missing check for JS-simulated input events in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to download arbitrary files with no user input via a crafted HTML page.

    Published: 4 Sept 2018
    6.6
    Medium

    CVE-2018-16420

    Last Modified: 21 Nov 2024

    Several buffer overflows when handling responses from an ePass 2003 Card in decrypt_response in libopensc/card-epass2003.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 4 Sept 2018
    6.6
    Medium

    CVE-2018-16421

    Last Modified: 21 Nov 2024

    Several buffer overflows when handling responses from a CAC Card in cac_get_serial_nr_from_CUID in libopensc/card-cac.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 4 Sept 2018
    6.6
    Medium

    CVE-2018-16424

    Last Modified: 21 Nov 2024

    A double free when handling responses in read_file in tools/egk-tool.c (aka the eGK card tool) in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 4 Sept 2018
    6.6
    Medium

    CVE-2018-16425

    Last Modified: 21 Nov 2024

    A double free when handling responses from an HSM Card in sc_pkcs15emu_sc_hsm_init in libopensc/pkcs15-sc-hsm.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 4 Sept 2018
    4.3
    Medium

    CVE-2018-16426

    Last Modified: 21 Nov 2024

    Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs.

    Published: 4 Sept 2018
    4.3
    Medium

    CVE-2018-16427

    Last Modified: 21 Nov 2024

    Various out of bounds reads when handling responses in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to potentially crash the opensc library using programs.

    Published: 4 Sept 2018
    9.8
    Critical

    CVE-2018-16428

    Last Modified: 21 Nov 2024

    In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.

    Published: 4 Sept 2018
    8.8
    High

    CVE-2018-16430

    Last Modified: 21 Nov 2024

    GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.

    Published: 4 Sept 2018