CVE Feed

    Dashboard / CVE

    7
    High

    CVE-2018-6257

    Last Modified: 21 Nov 2024

    NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameStream is enabled where improper access control may lead to a denial of service, escalation of privileges, or both.

    Published: 31 Aug 2018
    7.5
    High

    CVE-2018-11054

    Last Modified: 21 Nov 2024

    RSA BSAFE Micro Edition Suite, version 4.1.6, contains an integer overflow vulnerability. A remote attacker could use maliciously constructed ASN.1 data to potentially cause a Denial Of Service.

    Published: 31 Aug 2018
    5.5
    Medium

    CVE-2018-11055

    Last Modified: 21 Nov 2024

    RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper Clearing of Heap Memory Before Release ('Heap Inspection') vulnerability. Decoded PKCS #12 data in heap memory is not zeroized by MES before releasing the memory internally and a malicious local user could gain access to the unauthorized data by doing heap inspection.

    Published: 31 Aug 2018
    6.5
    Medium

    CVE-2018-11056

    Last Modified: 21 Nov 2024

    RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.3 (in 4.0.x) contain an Uncontrolled Resource Consumption ('Resource Exhaustion') vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would exhaust the stack, potentially causing a Denial Of Service.

    Published: 31 Aug 2018
    5.9
    Medium

    CVE-2018-11057

    Last Modified: 21 Nov 2024

    RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) contains a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be able to recover a RSA key.

    Published: 31 Aug 2018
    7.5
    High

    CVE-2018-3787

    Last Modified: 21 Nov 2024

    Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server.

    Published: 31 Aug 2018
    9.8
    Critical

    CVE-2018-16278

    Last Modified: 21 Nov 2024

    phpkaiyuancms PhpOpenSourceCMS (POSCMS) V3.2.0 allows an unauthenticated user to execute arbitrary SQL commands via the diy/module/member/controllers/Api.php ajax_save_draft function with the dir parameter.

    Published: 31 Aug 2018
    7.8
    High

    CVE-2018-7685

    Last Modified: 21 Nov 2024

    The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RPM warning and allow installation, a problem caused by malicious warnings only displayed during download.

    Published: 31 Aug 2018
    7.8
    High

    CVE-2018-16275

    Last Modified: 21 Nov 2024

    OPSWAT MetaDefender before v4.11.2 allows CSV injection.

    Published: 31 Aug 2018
    7.5
    High

    CVE-2018-14624

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly used when re-opening the log file in log__error_emergency(). An attacker could send a flood of modifications to a very large DN, which would cause slapd to crash.

    Published: 31 Aug 2018
    6.5
    Medium

    CVE-2018-19108

    Last Modified: 21 Nov 2024

    In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an integer overflow via a crafted PSD image file.

    Published: 31 Aug 2018
    7.5
    High

    CVE-2018-16231

    Last Modified: 21 Nov 2024

    Michael Roth Software Personal FTP Server (PFTP) through 8.4f allows remote attackers to cause a denial of service (daemon crash) via an unspecified sequence of FTP commands.

    Published: 30 Aug 2018
    6.1
    Medium

    CVE-2018-16233

    Last Modified: 21 Nov 2024

    MiniCMS V1.10 has XSS via the mc-admin/post-edit.php tags parameter.

    Published: 30 Aug 2018
    6.1
    Medium

    CVE-2018-16234

    Last Modified: 21 Nov 2024

    MorningStar WhatWeb 0.4.9 has XSS via JSON report files.

    Published: 30 Aug 2018
    2.7
    Low

    CVE-2018-16237

    Last Modified: 21 Nov 2024

    An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.php, as demonstrated by an admin.php?s=Tpl/Add/id/c:|windows|win.ini URI.

    Published: 30 Aug 2018
    9.8
    Critical

    CVE-2018-16239

    Last Modified: 21 Nov 2024

    An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to determine the cookie for an existing admin session via 10800 guesses.

    Published: 30 Aug 2018
    6.1
    Medium

    CVE-2018-16236

    Last Modified: 21 Nov 2024

    cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled during frontend/THEME/raw/index.html rendering.

    Published: 30 Aug 2018
    7.2
    High

    CVE-2018-16238

    Last Modified: 21 Nov 2024

    An issue was discovered in damiCMS V6.0.1. Remote code execution can occur via PHP code in a multipart/form-data POST to the admin.php?s=/Tpl/Update.html URI. For example, this can update the Web/Tpl/default/head.html file.

    Published: 30 Aug 2018
    8.8
    High

    CVE-2018-6498

    Last Modified: 21 Nov 2024

    Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Containerized Suite 2017.01 until 2018.05, Service Management Automation Suite 2017.11, 2018.02, 2018.05 and Network Operations Management (NOM) Suite CDF 2017.11, 2018.02, 2018.05 will allow Remote Code Execution.

    Published: 30 Aug 2018
    7.1
    High

    CVE-2018-6499

    Last Modified: 21 Nov 2024

    Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Containerized Suite 2017.01 until 2018.05, Service Management Automation Suite 2017.11, 2018.02, 2018.05, Service Virtualization (SV) with floating licenses using Any version using APLS older than 10.7, Unified Functional Testing (UFT) with floating licenses using Any version using APLS older than 10.7, Network Virtualization (NV) with floating licenses using Any version using APLS older than 10.7 and Network Operations Management (NOM) Suite CDF 2017.11, 2018.02, 2018.05 will allow Remote Code Execution.

    Published: 30 Aug 2018
    7.8
    High

    CVE-2018-10514

    Last Modified: 21 Nov 2024

    A Missing Impersonation Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.

    Published: 30 Aug 2018
    7.8
    High

    CVE-2018-15363

    Last Modified: 21 Nov 2024

    An Out-of-Bounds Read Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.

    Published: 30 Aug 2018
    4.7
    Medium

    CVE-2018-15364

    Last Modified: 21 Nov 2024

    A Named Pipe Request Processing Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro OfficeScan XG (12.0) could allow a local attacker to disclose sensitive information on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.

    Published: 30 Aug 2018
    7.8
    High

    CVE-2018-10513

    Last Modified: 21 Nov 2024

    A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.

    Published: 30 Aug 2018
    6.1
    Medium

    CVE-2018-14899

    Last Modified: 21 Nov 2024

    On the EPSON WF-2750 printer with firmware JP02I2, the Web interface AirPrint Setup page is vulnerable to HTML Injection that can redirect users to malicious sites.

    Published: 30 Aug 2018
    7.5
    High

    CVE-2018-14900

    Last Modified: 21 Nov 2024

    On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs. Remote attackers can send print jobs directly to the printer via TCP port 9100.

    Published: 30 Aug 2018
    7.5
    High

    CVE-2018-14903

    Last Modified: 21 Nov 2024

    EPSON WF-2750 printers with firmware JP02I2 do not properly validate files before running updates, which allows remote attackers to cause a printer malfunction or send malicious data to the printer.

    Published: 30 Aug 2018
    9.8
    Critical

    CVE-2018-15477

    Last Modified: 21 Nov 2024

    myStrom WiFi Switch V1 devices before 2.66 did not sanitize a parameter received from the cloud that was used in an OS command. Malicious servers were able to run operating system commands on the device.

    Published: 30 Aug 2018
    7.5
    High

    CVE-2018-15745

    Last Modified: 21 Nov 2024

    Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter.

    Published: 30 Aug 2018
    7.5
    High

    CVE-2018-14901

    Last Modified: 21 Nov 2024

    The EPSON iPrint application 6.6.3 for Android contains hard-coded API and Secret keys for the Dropbox, Box, Evernote and OneDrive services.

    Published: 30 Aug 2018
    8.1
    High

    CVE-2018-15478

    Last Modified: 21 Nov 2024

    An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The process of registering a device with a cloud account was based on an activation code derived from the device MAC address. By guessing valid MAC addresses or using MAC addresses printed on devices in shops and reverse engineering the protocol, an attacker would have been able to register previously unregistered devices to their account. When the rightful owner would have connected them after purchase to their WiFi network, the devices would not have registered with their account, would subsequently not have been controllable from the owner's mobile app, and would not have been visible in the owner's account. Instead, they would have been under control of the attacker.

    Published: 30 Aug 2018
    7.5
    High

    CVE-2018-14902

    Last Modified: 21 Nov 2024

    The ContentProvider in the EPSON iPrint application 6.6.3 for Android does not properly restrict data access. This allows an attacker's application to read scanned documents.

    Published: 30 Aug 2018
    8.1
    High

    CVE-2018-15476

    Last Modified: 21 Nov 2024

    An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The SSL/TLS server certificate in the device to cloud communication was not verified by the device. As a result, an attacker in control of the network traffic of a device could have taken control of a device by intercepting and modifying commands issued from the server to the device in a Man-in-the-Middle attack. This included the ability to inject firmware update commands into the communication and cause the device to install maliciously modified firmware.

    Published: 30 Aug 2018
    6.5
    Medium

    CVE-2018-15479

    Last Modified: 21 Nov 2024

    An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. Devices did not authenticate themselves to the cloud in device to cloud communication. This lack of device authentication allowed an attacker to impersonate any device by guessing or learning their MAC address.

    Published: 30 Aug 2018
    8.8
    High

    CVE-2018-15480

    Last Modified: 21 Nov 2024

    An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and WiFi Button Plus before 2.73. The cloud API had a hidden parameter, which allowed an authenticated user to reconfigure the server URL for a device registered to their account. In combination with an insecure device registration vulnerability, this allowed an attacker to reconfigure a maliciously registered device to their own rogue replica of the myStrom API and issue commands to the device, including firmware update commands.

    Published: 30 Aug 2018
    8.8
    High

    CVE-2018-11718

    Last Modified: 21 Nov 2024

    Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow CSRF.

    Published: 30 Aug 2018
    4.9
    Medium

    CVE-2018-11719

    Last Modified: 21 Nov 2024

    Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow XXE.

    Published: 30 Aug 2018
    7.5
    High

    CVE-2018-11720

    Last Modified: 21 Nov 2024

    Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow Directory Traversal.

    Published: 30 Aug 2018
    4
    Medium

    CVE-2016-0234

    Last Modified: 21 Nov 2024

    IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous user has logged out of the system but neglected to close their browser. IBM X-Force ID: 110303.

    Published: 30 Aug 2018
    3.1
    Low

    CVE-2016-0373

    Last Modified: 21 Nov 2024

    IBM UrbanCode Deploy 6.0 through 6.2.2.1 could allow an authenticated user to read sensitive information due to UCD REST endpoints not properly authorizing users when determining who can read data. IBM X-Force ID: 112119.

    Published: 30 Aug 2018
    3.3
    Low

    CVE-2016-0205

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in IBM Cloud Orchestrator 2.3, 2.3.0.1, 2.4, and 2.4.0.1 that could allow an attacker after authentication to enumerate valid users of the system. IBM X-Force ID: 109394.

    Published: 30 Aug 2018
    9.8
    Critical

    CVE-2018-16159

    Last Modified: 21 Nov 2024

    The Gift Vouchers plugin through 2.0.1 for WordPress allows SQL Injection via the template_id parameter in a wp-admin/admin-ajax.php wpgv_doajax_front_template request.

    Published: 30 Aug 2018
    7.5
    High

    CVE-2018-13819

    Last Modified: 21 Nov 2024

    A hardcoded secret key, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.

    Published: 30 Aug 2018
    7.5
    High

    CVE-2018-13820

    Last Modified: 21 Nov 2024

    A hardcoded passphrase, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.

    Published: 30 Aug 2018
    9.8
    Critical

    CVE-2018-13821

    Last Modified: 21 Nov 2024

    A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to conduct a variety of attacks, including file reading/writing.

    Published: 30 Aug 2018
    9.8
    Critical

    CVE-2018-13824

    Last Modified: 21 Nov 2024

    Insufficient input sanitization of two parameters in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to execute SQL injection attacks.

    Published: 30 Aug 2018
    9.1
    Critical

    CVE-2018-13826

    Last Modified: 21 Nov 2024

    An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to conduct server side request forgery attacks.

    Published: 30 Aug 2018
    9.8
    Critical

    CVE-2018-15691

    Last Modified: 21 Nov 2024

    Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code.

    Published: 30 Aug 2018
    7.5
    High

    CVE-2018-13822

    Last Modified: 21 Nov 2024

    Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows attackers to access sensitive information.

    Published: 30 Aug 2018
    7.5
    High

    CVE-2018-13823

    Last Modified: 21 Nov 2024

    An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to access sensitive information.

    Published: 30 Aug 2018