CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-1000653

    Last Modified: 21 Nov 2024

    zzcms version 8.3 and earlier contains a SQL Injection vulnerability in zt/top.php line 5 that can result in could be attacked by sql injection in zzcms in nginx. This attack appear to be exploitable via running zzcms in nginx.

    Published: 20 Aug 2018
    7.8
    High

    CVE-2018-1000657

    Last Modified: 21 Nov 2024

    Rust Programming Language Rust standard library version Commit bfa0e1f58acf1c28d500c34ed258f09ae021893e and later; stable release 1.3.0 and later contains a Buffer Overflow vulnerability in std::collections::vec_deque::VecDeque::reserve() function that can result in Arbitrary code execution, but no proof-of-concept exploit is currently published.. This vulnerability appears to have been fixed in after commit fdfafb510b1a38f727e920dccbeeb638d39a8e60; stable release 1.22.0 and later.

    Published: 20 Aug 2018
    6.5
    Medium

    CVE-2018-1000655

    Last Modified: 21 Nov 2024

    Jsish version 2.4.65 contains a CWE-476: NULL Pointer Dereference vulnerability in Function jsi_ValueCopyMove from jsiValue.c:240 that can result in Crash due to segmentation fault. This attack appear to be exploitable via a crafted javascript code. This vulnerability appears to have been fixed in 2.4.67.

    Published: 20 Aug 2018
    9.6
    Critical

    CVE-2018-1000639

    Last Modified: 21 Nov 2024

    LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server side request forgery, port scanning, possible rce. This attack appear to be exploitable via Specially crafted SVG file.

    Published: 20 Aug 2018
    Unknown

    CVE-2018-1000643

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 20 Aug 2018
    10
    Critical

    CVE-2018-1000644

    Last Modified: 21 Nov 2024

    Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can result in the disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted RDF file.

    Published: 20 Aug 2018
    7.1
    High

    CVE-2018-1000647

    Last Modified: 21 Nov 2024

    LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial of service. This attack appear to be exploitable via User controlled parameter.

    Published: 20 Aug 2018
    6.5
    Medium

    CVE-2018-1000636

    Last Modified: 21 Nov 2024

    JerryScript version Tested on commit f86d7459d195c8ba58479d1861b0cc726c8b3793. Analysing history it seems that the issue has been present since commit 64a340ffeb8809b2b66bbe32fd443a8b79fdd860 contains a CWE-476: NULL Pointer Dereference vulnerability in Triggering undefined behavior at jerry-core/ecma/builtin-objects/typedarray/ecma-builtin-typedarray-prototype.c:598 (passing NULL to memcpy as 2nd argument) results in null pointer dereference (segfault) at jerry-core/jmem/jmem-heap.c:463 that can result in Crash due to segmentation fault. This attack appear to be exploitable via The victim must execute specially crafted javascript code. This vulnerability appears to have been fixed in after commit 87897849f6879df10e8ad68a41bf8cf507edf710.

    Published: 20 Aug 2018
    7.8
    High

    CVE-2018-1000637

    Last Modified: 21 Nov 2024

    zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary code execution. This attack appear to be exploitable via the victim openning a crafted compressed file. This vulnerability appears to have been fixed in 1.8-pre2.

    Published: 20 Aug 2018
    6.1
    Medium

    CVE-2018-1000642

    Last Modified: 21 Nov 2024

    FlightAirMap version <=v1.0-beta.21 contains a Cross Site Scripting (XSS) vulnerability in GET variable used within registration sub menu page that can result in unauthorised actions and access to data, stealing session information. This vulnerability appears to have been fixed in after commit 22b09a3.

    Published: 20 Aug 2018
    6.5
    Medium

    CVE-2018-1000645

    Last Modified: 21 Nov 2024

    LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authenticated Local File Disclosure vulnerability in Importing of templates allows local file disclosure that can result in Disclosure of sensitive files on the server. This attack appear to be exploitable via User controlled variable in import templates function.

    Published: 20 Aug 2018
    8.8
    High

    CVE-2018-1000648

    Last Modified: 21 Nov 2024

    LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled parameters.

    Published: 20 Aug 2018
    10
    Critical

    CVE-2018-1000651

    Last Modified: 21 Nov 2024

    Stroom version <5.4.5 contains a XML External Entity (XXE) vulnerability in XML Parser that can result in disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted XML file.

    Published: 20 Aug 2018
    10
    Critical

    CVE-2018-1000652

    Last Modified: 21 Nov 2024

    JabRef version <=4.3.1 contains a XML External Entity (XXE) vulnerability in MsBibImporter XML Parser that can result in disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted MsBib file. This vulnerability appears to have been fixed in after commit 89f855d.

    Published: 20 Aug 2018
    7.5
    High

    CVE-2018-5243

    Last Modified: 21 Nov 2024

    The Symantec Encryption Management Server (SEMS) product, prior to version 3.4.2 MP1, may be susceptible to a denial of service (DoS) exploit. A DoS attack is a type of attack whereby the perpetrator attempts to make a particular machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a specific host within a network.

    Published: 20 Aug 2018
    7.5
    High

    CVE-2011-2765

    Last Modified: 21 Nov 2024

    pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks.

    Published: 20 Aug 2018
    6.1
    Medium

    CVE-2018-15574

    Last Modified: 30 Apr 2025

    An issue was discovered in the license editor in Reprise License Manager (RLM) through 12.2BL2. It is a cross-site scripting vulnerability in the /goform/edit_lf_get_data lf parameter via GET or POST. NOTE: the vendor has stated "We do not consider this a vulnerability."

    Published: 20 Aug 2018
    8.8
    High

    CVE-2018-15573

    Last Modified: 30 Apr 2025

    An issue was discovered in Reprise License Manager (RLM) through 12.2BL2. Attackers can use the web interface to read and write data to any file on disk (as long as rlm.exe has access to it) via /goform/edit_lf_process with file content in the lfdata parameter and a pathname in the lf parameter. By default, the web interface is on port 5054, and does not require authentication. NOTE: the vendor has stated "We do not consider this a vulnerability.

    Published: 20 Aug 2018
    8.8
    High

    CVE-2018-15564

    Last Modified: 21 Nov 2024

    An issue was discovered in daveismyname simple-cms through 2014-03-11. There is a CSRF vulnerability that can delete any page via admin/?delpage=8.

    Published: 20 Aug 2018
    8.8
    High

    CVE-2018-15565

    Last Modified: 21 Nov 2024

    An issue was discovered in daveismyname simple-cms through 2014-03-11. admin/addpage.php does not require authentication for adding a page. This can also be exploited via CSRF.

    Published: 20 Aug 2018
    6.1
    Medium

    CVE-2018-15567

    Last Modified: 21 Nov 2024

    CMSUno before 1.5.3 has XSS via the title field.

    Published: 20 Aug 2018
    4.8
    Medium

    CVE-2018-15570

    Last Modified: 21 Nov 2024

    In waimai Super Cms 20150505, there is stored XSS via the /admin.php/Foodcat/editsave fcname parameter.

    Published: 20 Aug 2018
    8.8
    High

    CVE-2018-15568

    Last Modified: 21 Nov 2024

    tp5cms through 2017-05-25 has CSRF via admin.php/category/delete.html.

    Published: 20 Aug 2018
    6.5
    Medium

    CVE-2018-15569

    Last Modified: 21 Nov 2024

    my little forum 2.4.12 allows CSRF for deletion of users.

    Published: 20 Aug 2018
    6.1
    Medium

    CVE-2018-15566

    Last Modified: 21 Nov 2024

    tp5cms through 2017-05-25 has XSS via the admin.php/article/index.html q parameter.

    Published: 20 Aug 2018
    6.5
    Medium

    CVE-2018-15120

    Last Modified: 21 Nov 2024

    libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.

    Published: 20 Aug 2018
    8.8
    High

    CVE-2018-15553

    Last Modified: 21 Nov 2024

    fileshare.cmd on Telus Actiontec T2200H T2200H-31.128L.03 devices allows OS Command Injection via shell metacharacters in the smbdUserid or smbdPasswd field.

    Published: 20 Aug 2018
    6.1
    Medium

    CVE-2018-15559

    Last Modified: 21 Nov 2024

    The editor in Xiuno BBS 4.0.4 allows stored XSS.

    Published: 20 Aug 2018
    7.5
    High

    CVE-2018-15560

    Last Modified: 21 Nov 2024

    PyCryptodome before 3.6.6 has an integer overflow in the data_len variable in AESNI.c, related to the AESNI_encrypt and AESNI_decrypt functions, leading to the mishandling of messages shorter than 16 bytes.

    Published: 20 Aug 2018
    9.8
    Critical

    CVE-2018-25014

    Last Modified: 21 Nov 2024

    A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().

    Published: 20 Aug 2018
    9.1
    Critical

    CVE-2018-25013

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().

    Published: 20 Aug 2018
    8.8
    High

    CVE-2018-16413

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the MagickCore/quantum-private.h PushShortPixel function when called from the coders/psd.c ParseImageResourceBlocks function.

    Published: 19 Aug 2018
    8.8
    High

    CVE-2018-16412

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the coders/psd.c ParseImageResourceBlocks function.

    Published: 19 Aug 2018
    7.5
    High

    CVE-2018-15491

    Last Modified: 21 Nov 2024

    A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.3.602) allows an attacker to take control of the whitelisting feature (MyRules2.ini under %LOCALAPPDATA%\Zemana\ZALSDK) to permit execution of unauthorized applications (such as ones that record keystrokes).

    Published: 18 Aug 2018
    7.5
    High

    CVE-2018-15492

    Last Modified: 21 Nov 2024

    A vulnerability in the lservnt.exe component of Sentinel License Manager version 8.5.3.35 (fixed in 8.5.3.2403) causes UDP amplification.

    Published: 18 Aug 2018
    7.5
    High

    CVE-2018-15495

    Last Modified: 21 Nov 2024

    /filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url parameter is used directly in a curl_exec call, as demonstrated by a file:///etc/passwd value.

    Published: 18 Aug 2018
    7.5
    High

    CVE-2018-15503

    Last Modified: 21 Nov 2024

    The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process. An attacker can craft a serialized object to exploit this vulnerability and cause a SEGV.

    Published: 18 Aug 2018
    7.5
    High

    CVE-2018-15505

    Last Modified: 21 Nov 2024

    An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ']' character in an IPv6 address.

    Published: 18 Aug 2018
    6.5
    Medium

    CVE-2018-15671

    Last Modified: 21 Nov 2024

    An issue was discovered in the HDF HDF5 1.10.2 library. Excessive stack consumption has been detected in the function H5P__get_cb() in H5Pint.c during an attempted parse of a crafted HDF file. This results in denial of service.

    Published: 18 Aug 2018
    8.8
    High

    CVE-2018-19655

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.

    Published: 18 Aug 2018
    5.3
    Medium

    CVE-2018-15672

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11207. Reason: This candidate is a reservation duplicate of CVE-2018-11207. Notes: All CVE users should reference CVE-2018-11207 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 Aug 2018
    7.5
    High

    CVE-2018-15504

    Last Modified: 21 Nov 2024

    An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.

    Published: 18 Aug 2018
    9.8
    Critical

    CVE-2018-14981

    Last Modified: 21 Nov 2024

    Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for SystemUI application intents. The LG ID is LVE-SMP-180005.

    Published: 17 Aug 2018
    9.8
    Critical

    CVE-2018-14982

    Last Modified: 21 Nov 2024

    Certain LG devices based on Android 6.0 through 8.1 have incorrect access control in the GNSS application. The LG ID is LVE-SMP-180004.

    Published: 17 Aug 2018
    9.8
    Critical

    CVE-2018-15482

    Last Modified: 21 Nov 2024

    Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for MLT application intents. The LG ID is LVE-SMP-180006.

    Published: 17 Aug 2018
    8.8
    High

    CVE-2018-14057

    Last Modified: 21 Nov 2024

    Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / Roles" function.

    Published: 17 Aug 2018
    6.5
    Medium

    CVE-2018-14058

    Last Modified: 21 Nov 2024

    Pimcore before 5.3.0 allows SQL Injection via the REST web service API.

    Published: 17 Aug 2018
    7.1
    High

    CVE-2018-6622

    Last Modified: 21 Nov 2024

    An issue was discovered that affects all producers of BIOS firmware who make a certain realistic interpretation of an obscure portion of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2.0 specification. An abnormal case is not handled properly by this firmware while S3 sleep and can clear TPM 2.0. It allows local users to overwrite static PCRs of TPM and neutralize the security features of it, such as seal/unseal and remote attestation.

    Published: 17 Aug 2018
    Unknown

    CVE-2018-1236

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 17 Aug 2018
    Unknown

    CVE-2018-11085

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 17 Aug 2018