CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2018-16431

    Last Modified: 21 Nov 2024

    admin/admin/adminsave.html in YFCMF v3.0 allows CSRF to add an administrator account.

    Published: 4 Sept 2018
    9.8
    Critical

    CVE-2018-16432

    Last Modified: 21 Nov 2024

    BlueCMS 1.6 allows SQL Injection via the user_name parameter to uploads/user.php?act=index_login.

    Published: 4 Sept 2018
    5.5
    Medium

    CVE-2018-6554

    Last Modified: 21 Nov 2024

    Memory leak in the irda_bind function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (memory consumption) by repeatedly binding an AF_IRDA socket.

    Published: 4 Sept 2018
    9.8
    Critical

    CVE-2018-0502

    Last Modified: 21 Nov 2024

    An issue was discovered in zsh before 5.6. The beginning of a #! script file was mishandled, potentially leading to an execve call to a program named on the second line.

    Published: 4 Sept 2018
    8.8
    High

    CVE-2018-16065

    Last Modified: 21 Nov 2024

    A Javascript reentrancy issues that caused a use-after-free in V8 in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

    Published: 4 Sept 2018
    6.5
    Medium

    CVE-2018-16069

    Last Modified: 21 Nov 2024

    Unintended floating-point error accumulation in SwiftShader in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 4 Sept 2018
    5.3
    Medium

    CVE-2018-16075

    Last Modified: 21 Nov 2024

    Insufficient file type enforcement in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to obtain local file data via a crafted HTML page.

    Published: 4 Sept 2018
    6.5
    Medium

    CVE-2018-16080

    Last Modified: 21 Nov 2024

    A missing check for popup window handling in Fullscreen in Google Chrome on macOS prior to 69.0.3497.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 4 Sept 2018
    6.6
    Medium

    CVE-2018-16419

    Last Modified: 21 Nov 2024

    Several buffer overflows when handling responses from a Cryptoflex card in read_public_key in tools/cryptoflex-tool.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 4 Sept 2018
    7.5
    High

    CVE-2018-16429

    Last Modified: 21 Nov 2024

    GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().

    Published: 4 Sept 2018
    7.6
    High

    CVE-2018-16861

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create entries using the Hosts, Monitor, Infrastructure, or Administer Menus is able to execute a XSS attacks against other users, possibly leading to malicious code execution and extraction of the anti-CSRF token of higher privileged users. Foreman before 1.18.3, 1.19.1, and 1.20.0 are vulnerable.

    Published: 4 Sept 2018
    9.8
    Critical

    CVE-2018-13259

    Last Modified: 21 Nov 2024

    An issue was discovered in zsh before 5.6. Shebang lines exceeding 64 characters were truncated, potentially leading to an execve call to a program name that is a substring of the intended one.

    Published: 4 Sept 2018
    7.8
    High

    CVE-2018-6555

    Last Modified: 21 Nov 2024

    The irda_setsockopt function in net/irda/af_irda.c and later in drivers/staging/irda/net/af_irda.c in the Linux kernel before 4.17 allows local users to cause a denial of service (ias_object use-after-free and system crash) or possibly have unspecified other impact via an AF_IRDA socket.

    Published: 4 Sept 2018
    6.5
    Medium

    CVE-2018-16067

    Last Modified: 21 Nov 2024

    A use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 4 Sept 2018
    6.5
    Medium

    CVE-2018-16077

    Last Modified: 21 Nov 2024

    Object lifecycle issue in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass content security policy via a crafted HTML page.

    Published: 4 Sept 2018
    6.5
    Medium

    CVE-2018-16078

    Last Modified: 21 Nov 2024

    Unsafe handling of credit card details in Autofill in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 4 Sept 2018
    5.3
    Medium

    CVE-2018-16079

    Last Modified: 21 Nov 2024

    A race condition between permission prompts and navigations in Prompts in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 4 Sept 2018
    7.4
    High

    CVE-2018-16081

    Last Modified: 21 Nov 2024

    Allowing the chrome.debugger API to run on file:// URLs in DevTools in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system without file access permission via a crafted Chrome Extension.

    Published: 4 Sept 2018
    6.5
    Medium

    CVE-2018-16082

    Last Modified: 21 Nov 2024

    An out of bounds read in Swiftshader in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

    Published: 4 Sept 2018
    6.1
    Medium

    CVE-2018-16084

    Last Modified: 21 Nov 2024

    The default selected dialog button in CustomHandlers in Google Chrome prior to 69.0.3497.81 allowed a remote attacker who convinced the user to perform certain operations to open external programs via a crafted HTML page.

    Published: 4 Sept 2018
    5.4
    Medium

    CVE-2018-16086

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in extensions API in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

    Published: 4 Sept 2018
    4.3
    Medium

    CVE-2018-16087

    Last Modified: 21 Nov 2024

    Lack of proper state tracking in Permissions in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 4 Sept 2018
    6.6
    Medium

    CVE-2018-16418

    Last Modified: 21 Nov 2024

    A buffer overflow when handling string concatenation in util_acl_to_str in tools/util.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 4 Sept 2018
    6.6
    Medium

    CVE-2018-16422

    Last Modified: 21 Nov 2024

    A single byte buffer overflow when handling responses from an esteid Card in sc_pkcs15emu_esteid_init in libopensc/pkcs15-esteid.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 4 Sept 2018
    6.6
    Medium

    CVE-2018-16423

    Last Modified: 21 Nov 2024

    A double free when handling responses from a smartcard in sc_file_set_sec_attr in libopensc/sc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 4 Sept 2018
    7.5
    High

    CVE-2018-16398

    Last Modified: 21 Nov 2024

    In Twistlock AuthZ Broker 0.1, regular expressions are mishandled, as demonstrated by containers/aa/pause?aaa=\/start to bypass a policy in which "docker start" is allowed but "docker pause" is not allowed.

    Published: 3 Sept 2018
    6.1
    Medium

    CVE-2018-16405

    Last Modified: 21 Nov 2024

    An issue was discovered in Mayan EDMS before 3.0.2. The Appearance app sets window.location directly, leading to XSS.

    Published: 3 Sept 2018
    6.1
    Medium

    CVE-2018-16406

    Last Modified: 21 Nov 2024

    An issue was discovered in Mayan EDMS before 3.0.2. The Cabinets app has XSS via a crafted cabinet label.

    Published: 3 Sept 2018
    6.1
    Medium

    CVE-2018-16407

    Last Modified: 21 Nov 2024

    An issue was discovered in Mayan EDMS before 3.0.3. The Tags app has XSS because tag label values are mishandled.

    Published: 3 Sept 2018
    7.2
    High

    CVE-2018-16408

    Last Modified: 21 Nov 2024

    D-Link DIR-846 devices with firmware 100.26 allow remote attackers to execute arbitrary code as root via a SetNetworkTomographySettings request by leveraging admin access.

    Published: 3 Sept 2018
    8.6
    High

    CVE-2018-16409

    Last Modified: 21 Nov 2024

    In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.

    Published: 3 Sept 2018
    8.8
    High

    CVE-2018-16416

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administrator's password.

    Published: 3 Sept 2018
    6.5
    Medium

    CVE-2018-16410

    Last Modified: 21 Nov 2024

    Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/class.invitationmodel.php and applications/dashboard/controllers/class.profilecontroller.php.

    Published: 3 Sept 2018
    4.9
    Medium

    CVE-2018-16397

    Last Modified: 21 Nov 2024

    In LimeSurvey before 3.14.7, an admin user can leverage a "file upload" question to read an arbitrary file,

    Published: 3 Sept 2018
    6.8
    Medium

    CVE-2018-16392

    Last Modified: 21 Nov 2024

    Several buffer overflows when handling responses from a TCOS Card in tcos_select_file in libopensc/card-tcos.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 3 Sept 2018
    6.8
    Medium

    CVE-2018-16393

    Last Modified: 21 Nov 2024

    Several buffer overflows when handling responses from a Gemsafe V1 Smartcard in gemsafe_get_cert_len in libopensc/pkcs15-gemsafeV1.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 3 Sept 2018
    6.8
    Medium

    CVE-2018-16391

    Last Modified: 21 Nov 2024

    Several buffer overflows when handling responses from a Muscle Card in muscle_list_files in libopensc/card-muscle.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 3 Sept 2018
    9.8
    Critical

    CVE-2018-16385

    Last Modified: 21 Nov 2024

    ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.

    Published: 3 Sept 2018
    8.8
    High

    CVE-2018-16387

    Last Modified: 21 Nov 2024

    An issue was discovered in Elefant CMS before 2.0.5. There is a CSRF vulnerability that can add an account via user/add.

    Published: 3 Sept 2018
    5.9
    Medium

    CVE-2018-12384

    Last Modified: 21 Nov 2024

    When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.

    Published: 3 Sept 2018
    5.5
    Medium

    CVE-2018-16369

    Last Modified: 21 Nov 2024

    XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, related to AcroForm::scanField, as demonstrated by pdftohtml. NOTE: this might overlap CVE-2018-7453.

    Published: 3 Sept 2018
    6.1
    Medium

    CVE-2018-16372

    Last Modified: 21 Nov 2024

    The issue was discovered in IdeaCMS through 2016-04-30. There is reflected XSS via the index.php?c=content&a=search kw parameter. NOTE: this product is discontinued.

    Published: 3 Sept 2018
    4.9
    Medium

    CVE-2018-16373

    Last Modified: 21 Nov 2024

    Frog CMS 0.9.5 has an Upload vulnerability that can create files via /admin/?/plugin/file_manager/save.

    Published: 3 Sept 2018
    4.8
    Medium

    CVE-2018-16374

    Last Modified: 21 Nov 2024

    Frog CMS 0.9.5 has stored XSS via /admin/?/plugin/comment/settings.

    Published: 3 Sept 2018
    8.8
    High

    CVE-2018-16380

    Last Modified: 21 Nov 2024

    An issue was discovered in Ogma CMS 0.4 Beta. There is a CSRF vulnerability in users.php?action=createnew that can add an admin account.

    Published: 3 Sept 2018
    5.5
    Medium

    CVE-2018-16368

    Last Modified: 21 Nov 2024

    SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted pdf file, as demonstrated by pdftoppm.

    Published: 3 Sept 2018
    9.8
    Critical

    CVE-2018-16370

    Last Modified: 21 Nov 2024

    In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a ZIP archive.

    Published: 3 Sept 2018
    8.8
    High

    CVE-2018-16375

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenJPEG 2.3.0. Missing checks for header_info.height and header_info.width in the function pnmtoimage in bin/jpwl/convert.c can lead to a heap-based buffer overflow.

    Published: 3 Sept 2018
    7.5
    High

    CVE-2018-16384

    Last Modified: 21 Nov 2024

    A SQL injection bypass (aka PL1 bypass) exists in OWASP ModSecurity Core Rule Set (owasp-modsecurity-crs) through v3.1.0-rc3 via {`a`b} where a is a special function name (such as "if") and b is the SQL statement to be executed.

    Published: 3 Sept 2018
    6.1
    Medium

    CVE-2018-16371

    Last Modified: 21 Nov 2024

    PESCMS Team 2.2.1 has multiple reflected XSS via the keyword parameter: g=Team&m=User&a=index&keyword=, g=Team&m=User_group&a=index&keyword=, g=Team&m=Department&a=index&keyword=, and g=Team&m=Bulletin&a=index&keyword=.

    Published: 3 Sept 2018