CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2018-15646

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Aug 2018
    Unknown

    CVE-2018-15651

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Aug 2018
    Unknown

    CVE-2018-15652

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Aug 2018
    Unknown

    CVE-2018-15653

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Aug 2018
    Unknown

    CVE-2018-15654

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Aug 2018
    7.8
    High

    CVE-2018-15908

    Last Modified: 21 Nov 2024

    In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.

    Published: 21 Aug 2018
    7.8
    High

    CVE-2018-15910

    Last Modified: 21 Nov 2024

    In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.

    Published: 21 Aug 2018
    7.8
    High

    CVE-2018-16513

    Last Modified: 21 Nov 2024

    In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.

    Published: 21 Aug 2018
    5.3
    Medium

    CVE-2019-1010299

    Last Modified: 21 Nov 2024

    The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impact is: Contents of uninitialized memory could be printed to string or to log file. The component is: Debug trait implementation for std::collections::vec_deque::Iter. The attack vector is: The program needs to invoke debug printing for iterator over an empty VecDeque. The fixed version is: 1.30.0, nightly versions after commit b85e4cc8fadaabd41da5b9645c08c68b8f89908d.

    Published: 21 Aug 2018
    5.9
    Medium

    CVE-2018-0501

    Last Modified: 21 Nov 2024

    The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verification for the InRelease file of a fallback mirror, aka mirrorfail.

    Published: 21 Aug 2018
    Unknown

    CVE-2018-15647

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Aug 2018
    Unknown

    CVE-2018-15648

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Aug 2018
    Unknown

    CVE-2018-15649

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 21 Aug 2018
    5.9
    Medium

    CVE-2018-10844

    Last Modified: 21 Nov 2024

    It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data using crafted packets.

    Published: 21 Aug 2018
    5.6
    Medium

    CVE-2018-10846

    Last Modified: 21 Nov 2024

    A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to recover plain text using crafted packets.

    Published: 21 Aug 2018
    7.5
    High

    CVE-2018-14598

    Last Modified: 21 Nov 2024

    An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overflows, causing a variable to be set to NULL that will be freed later on, leading to DoS (segmentation fault).

    Published: 21 Aug 2018
    9.8
    Critical

    CVE-2018-14599

    Last Modified: 21 Nov 2024

    An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact.

    Published: 21 Aug 2018
    6.5
    Medium

    CVE-2018-15607

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.

    Published: 21 Aug 2018
    7.8
    High

    CVE-2018-16509

    Last Modified: 21 Nov 2024

    An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.

    Published: 21 Aug 2018
    4
    Medium

    CVE-2018-14023

    Last Modified: 21 Nov 2024

    Open Whisper Signal (aka Signal-Desktop) before 1.15.0-beta.10 allows information leakage.

    Published: 20 Aug 2018
    8.1
    High

    CVE-2018-12579

    Last Modified: 21 Nov 2024

    An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Professional Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0; and Community Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0. An attacker could gain access to the admin panel or a customer account when using the password reset function. To do so, it is required to own a domain name similar to the one the victim uses for their e-mail accounts.

    Published: 20 Aug 2018
    5.3
    Medium

    CVE-2018-14020

    Last Modified: 21 Nov 2024

    An issue was discovered in the Paymorrow module 1.0.0 before 1.0.2 and 2.0.0 before 2.0.1 for OXID eShop. An attacker can bypass delivery-address change detection if the payment module doesn't use eShop's checkout procedure properly. To do so, the attacker must change the delivery address to one that is not verified by the Paymorrow module.

    Published: 20 Aug 2018
    9.8
    Critical

    CVE-2015-5243

    Last Modified: 21 Nov 2024

    phpWhois allows remote attackers to execute arbitrary code via a crafted whois record.

    Published: 20 Aug 2018
    7.2
    High

    CVE-2017-16744

    Last Modified: 21 Nov 2024

    A path traversal vulnerability in Tridium Niagara AX Versions 3.8 and prior and Niagara 4 systems Versions 4.4 and prior installed on Microsoft Windows Systems can be exploited by leveraging valid platform (administrator) credentials.

    Published: 20 Aug 2018
    9.8
    Critical

    CVE-2017-16748

    Last Modified: 21 Nov 2024

    An attacker can log into the local Niagara platform (Niagara AX Framework Versions 3.8 and prior or Niagara 4 Framework Versions 4.4 and prior) using a disabled account name and a blank password, granting the attacker administrator access to the Niagara system.

    Published: 20 Aug 2018
    5.4
    Medium

    CVE-2017-1753

    Last Modified: 21 Nov 2024

    Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 135655.

    Published: 20 Aug 2018
    5.4
    Medium

    CVE-2018-1394

    Last Modified: 21 Nov 2024

    Multiple IBM Rational products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138425.

    Published: 20 Aug 2018
    Unknown

    CVE-2018-1000212

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-1999022. Reason: This candidate is a reservation duplicate of CVE-2018-1999022. Notes: All CVE users should reference CVE-2018-1999022 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Aug 2018
    5.4
    Medium

    CVE-2018-1000218

    Last Modified: 21 Nov 2024

    OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'file' parameter in line #43 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.. This attack appear to be exploitable via The victim must visit on a specially crafted URL..

    Published: 20 Aug 2018
    Unknown

    CVE-2018-1000220

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-5462. Reason: This candidate is a reservation duplicate of CVE-2014-5462. Notes: All CVE users should reference CVE-2014-5462 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Aug 2018
    7.5
    High

    CVE-2018-14077

    Last Modified: 21 Nov 2024

    Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to backup the device configuration via a direct request to /Maintenance/configfile.cfg.

    Published: 20 Aug 2018
    Unknown

    CVE-2018-1000213

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-1999023. Reason: This candidate is a reservation duplicate of CVE-2018-1999023. Notes: All CVE users should reference CVE-2018-1999023 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Aug 2018
    7.5
    High

    CVE-2018-1000215

    Last Modified: 22 Jul 2025

    Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service (DoS). This attack appear to be exploitable via If the attacker can force the data to be printed and the system is in low memory it can force a leak of memory. This vulnerability appears to have been fixed in 1.7.7.

    Published: 20 Aug 2018
    5.4
    Medium

    CVE-2018-1000219

    Last Modified: 21 Nov 2024

    OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'scan' parameter in line #41 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.. This attack appear to be exploitable via The victim must visit on a specially crafted URL..

    Published: 20 Aug 2018
    9.8
    Critical

    CVE-2018-1000221

    Last Modified: 21 Nov 2024

    pkgconf version 1.5.0 to 1.5.2 contains a Buffer Overflow vulnerability in dequote() that can result in dequote() function returns 1-byte allocation if initial length is 0, leading to buffer overflow. This attack appear to be exploitable via specially crafted .pc file. This vulnerability appears to have been fixed in 1.5.3.

    Published: 20 Aug 2018
    7.5
    High

    CVE-2018-1000224

    Last Modified: 21 Nov 2024

    Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing padding initialization vulnerability in (De)Serialization functions (core/io/marshalls.cpp) that can result in DoS (packet of death), possible leak of uninitialized memory. This attack appear to be exploitable via A malformed packet is received over the network by a Godot application that uses built-in serialization (e.g. game server, or game client). Could be triggered by multiplayer opponent. This vulnerability appears to have been fixed in 2.1.5, 3.0.6, master branch after commit feaf03421dda0213382b51aff07bd5a96b29487b.

    Published: 20 Aug 2018
    8.8
    High

    CVE-2018-1000216

    Last Modified: 22 Jul 2025

    Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploitable via Attacker must be able to force victim to print JSON data, depending on how cJSON library is used this could be either local or over a network. This vulnerability appears to have been fixed in 1.7.3.

    Published: 20 Aug 2018
    Unknown

    CVE-2018-1000214

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-1999024. Reason: This candidate is a reservation duplicate of CVE-2018-1999024. Notes: All CVE users should reference CVE-2018-1999024 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Aug 2018
    9.8
    Critical

    CVE-2018-1000217

    Last Modified: 22 Jul 2025

    Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corruption of data or even RCE. This attack appear to be exploitable via Depends on how application uses cJSON library. If application provides network interface then can be exploited over a network, otherwise just local.. This vulnerability appears to have been fixed in 1.7.4.

    Published: 20 Aug 2018
    9.8
    Critical

    CVE-2018-14078

    Last Modified: 21 Nov 2024

    Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to reset the admin password via the /ConfigWizard/ChangePwd.esp?2admin URL (Attackers can login using the "admin" username with password "admin" after a successful attack).

    Published: 20 Aug 2018
    7.5
    High

    CVE-2018-14079

    Last Modified: 21 Nov 2024

    Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to obtain sensitive information via /Status/SystemStatusRpm.esp.

    Published: 20 Aug 2018
    7.2
    High

    CVE-2018-1000633

    Last Modified: 21 Nov 2024

    The Open Microscopy Environment OMERO.web version prior to 5.4.7 contains an Information Exposure Through Log Files vulnerability in the login form and change password form that can result in User's password being revealed. Attacker can log in as that user. This attack appear to be exploitable via an attacker reading the web server log. This vulnerability appears to have been fixed in 5.4.7.

    Published: 20 Aug 2018
    7.2
    High

    CVE-2018-1000634

    Last Modified: 21 Nov 2024

    The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains an Improper Access Control vulnerability in User management that can result in administrative user with privilege restrictions logging in as a more powerful administrator. This attack appear to be exploitable via Use user administration privilege to set the password of a more powerful administrator. This vulnerability appears to have been fixed in 5.4.7.

    Published: 20 Aug 2018
    6.7
    Medium

    CVE-2018-1000635

    Last Modified: 21 Nov 2024

    The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains a Information Exposure Through Sent Data vulnerability in OMERO.server that can result in an Attacker gaining full administrative access to server and may be able to disable it. This vulnerability appears to have been fixed in 5.4.7.

    Published: 20 Aug 2018
    6.1
    Medium

    CVE-2018-1000638

    Last Modified: 21 Nov 2024

    MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={payload} that can result in code injection.

    Published: 20 Aug 2018
    6.1
    Medium

    CVE-2018-1000640

    Last Modified: 21 Nov 2024

    OpenCart-Overclocked version <=1.11.1 contains a Cross Site Scripting (XSS) vulnerability in User input entered unsanitised within JS function in the template that can result in Unauthorised actions and access to data, stealing session information, denial of service. This attack appear to be exploitable via Malicious input passed in GET parameter.

    Published: 20 Aug 2018
    9.8
    Critical

    CVE-2018-1000641

    Last Modified: 21 Nov 2024

    YesWiki version <= cercopitheque beta 1 contains a PHP Object Injection vulnerability in Unserialising user entered parameter in i18n.inc.php that can result in execution of code, disclosure of information.

    Published: 20 Aug 2018
    8.8
    High

    CVE-2018-1000646

    Last Modified: 21 Nov 2024

    LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write files with malicious content and may lead to remote code execution.

    Published: 20 Aug 2018
    8.8
    High

    CVE-2018-1000649

    Last Modified: 21 Nov 2024

    LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write in letter.php (2) vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled input.

    Published: 20 Aug 2018
    8.8
    High

    CVE-2018-1000650

    Last Modified: 21 Nov 2024

    LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions that can result in Ability to perform malicious database queries. This attack appear to be exploitable via User controlled parameters.

    Published: 20 Aug 2018