CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2017-1732

    Last Modified: 21 Nov 2024

    IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 134913.

    Published: 17 Aug 2018
    8.8
    High

    CVE-2018-15356

    Last Modified: 21 Nov 2024

    An authenticated attacker can execute arbitrary code using command ejection in Eltex ESP-200 firmware version 1.2.0.

    Published: 17 Aug 2018
    6.5
    Medium

    CVE-2018-15357

    Last Modified: 21 Nov 2024

    An authenticated attacker with low privileges can extract password hash information for all users in Eltex ESP-200 firmware version 1.2.0.

    Published: 17 Aug 2018
    8.8
    High

    CVE-2018-15358

    Last Modified: 21 Nov 2024

    An authenticated attacker with low privileges can activate high privileged user and use it to expand attack surface in Eltex ESP-200 firmware version 1.2.0.

    Published: 17 Aug 2018
    8.8
    High

    CVE-2018-15359

    Last Modified: 21 Nov 2024

    An authenticated attacker with low privileges can use insecure sudo configuration to expand attack surface in Eltex ESP-200 firmware version 1.2.0.

    Published: 17 Aug 2018
    7.3
    High

    CVE-2018-15360

    Last Modified: 21 Nov 2024

    An attacker without authentication can login with default credentials for privileged users in Eltex ESP-200 firmware version 1.2.0.

    Published: 17 Aug 2018
    9.8
    Critical

    CVE-2018-15350

    Last Modified: 21 Nov 2024

    Router Default Credentials in Kraftway 24F2XG Router firmware version 3.5.30.1118 allow remote attackers to get privileged access to the router.

    Published: 17 Aug 2018
    6.5
    Medium

    CVE-2018-15351

    Last Modified: 21 Nov 2024

    Denial of service via crafting malicious link and sending it to a privileged user can cause Denial of Service in Kraftway 24F2XG Router firmware version 3.5.30.1118.

    Published: 17 Aug 2018
    6.5
    Medium

    CVE-2018-15352

    Last Modified: 21 Nov 2024

    An attacker with low privileges can cause denial of service in Kraftway 24F2XG Router firmware version 3.5.30.1118.

    Published: 17 Aug 2018
    9.8
    Critical

    CVE-2018-15353

    Last Modified: 21 Nov 2024

    A Buffer Overflow exploited through web interface by remote attacker can cause remote code execution in Kraftway 24F2XG Router firmware 3.5.30.1118.

    Published: 17 Aug 2018
    7.5
    High

    CVE-2018-15354

    Last Modified: 21 Nov 2024

    A Buffer Overflow exploited through web interface by remote attacker can cause denial of service in Kraftway 24F2XG Router firmware 3.5.30.1118.

    Published: 17 Aug 2018
    Unknown

    CVE-2018-8261

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA due to an erroneous publication. Notes: none

    Published: 17 Aug 2018
    5.9
    Medium

    CVE-2018-15355

    Last Modified: 21 Nov 2024

    Usage of SSLv2 and SSLv3 leads to transmitted data decryption in Kraftway 24F2XG Router firmware 3.5.30.1118.

    Published: 17 Aug 2018
    9.8
    Critical

    CVE-2018-3784

    Last Modified: 21 Nov 2024

    A code injection in cryo 0.0.6 allows an attacker to arbitrarily execute code due to insecure implementation of deserialization.

    Published: 17 Aug 2018
    9.8
    Critical

    CVE-2018-3785

    Last Modified: 21 Nov 2024

    A command injection in git-dummy-commit v1.3.0 allows os level commands to be executed due to an unescaped parameter.

    Published: 17 Aug 2018
    9.8
    Critical

    CVE-2018-3783

    Last Modified: 21 Nov 2024

    A privilege escalation detected in flintcms versions <= 1.1.9 allows account takeover due to blind MongoDB injection in password reset.

    Published: 17 Aug 2018
    7.8
    High

    CVE-2018-5547

    Last Modified: 21 Nov 2024

    Windows Logon Integration feature of F5 BIG-IP APM client prior to version 7.1.7.1 for Windows by default uses Legacy logon mode which uses a SYSTEM account to establish network access. This feature displays a certificate user interface dialog box which contains the link to the certificate policy. By clicking on the link, unprivileged users can open additional dialog boxes and get access to the local machine windows explorer which can be used to get administrator privilege. Windows Logon Integration is vulnerable when the APM client is installed by an administrator on a user machine. Users accessing the local machine can get administrator privileges

    Published: 17 Aug 2018
    7.8
    High

    CVE-2018-5546

    Last Modified: 21 Nov 2024

    The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or assume super-user privileges on the local client host.

    Published: 17 Aug 2018
    7.5
    High

    CVE-2018-15836

    Last Modified: 21 Nov 2024

    In verify_signed_hash() in lib/liboswkeys/signatures.c in Openswan before 2.6.50.1, the RSA implementation does not verify the value of padding string during PKCS#1 v1.5 signature verification. Consequently, a remote attacker can forge signatures when small public exponents are being used. IKEv2 signature verification is affected when RAW RSA keys are used.

    Published: 17 Aug 2018
    5.5
    Medium

    CVE-2018-16062

    Last Modified: 21 Nov 2024

    dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.

    Published: 17 Aug 2018
    8.8
    High

    CVE-2018-12256

    Last Modified: 21 Nov 2024

    admin/vqmods.app/vqmods.inc.php in LiteCart before 2.1.3 allows remote authenticated attackers to upload a malicious file (resulting in remote code execution) by using the text/xml or application/xml Content-Type in a public_html/admin/?app=vqmods&doc=vqmods request.

    Published: 16 Aug 2018
    7
    High

    CVE-2018-13435

    Last Modified: 21 Nov 2024

    An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method to disable passcode authentication. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes iOS devices on which a jailbreak has occurred

    Published: 16 Aug 2018
    9.8
    Critical

    CVE-2018-11509

    Last Modified: 21 Nov 2024

    ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell.

    Published: 16 Aug 2018
    9.8
    Critical

    CVE-2018-11511

    Last Modified: 21 Nov 2024

    The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI.

    Published: 16 Aug 2018
    6.3
    Medium

    CVE-2018-13434

    Last Modified: 21 Nov 2024

    An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection mechanism is not used. In other words, an attacker could authenticate with an arbitrary fingerprint. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes iOS devices on which a jailbreak has occurred

    Published: 16 Aug 2018
    7
    High

    CVE-2018-13446

    Last Modified: 21 Nov 2024

    An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred

    Published: 16 Aug 2018
    7.8
    High

    CVE-2018-15122

    Last Modified: 21 Nov 2024

    An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object (such as DLL or EXE) with an embedded resource file by clicking on the resource.

    Published: 16 Aug 2018
    8.6
    High

    CVE-2018-1712

    Last Modified: 21 Nov 2024

    IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input parameters can trick the server into making potentially malicious calls within the trusted network. IBM X-Force ID: 146370.

    Published: 16 Aug 2018
    6.1
    Medium

    CVE-2018-10139

    Last Modified: 21 Nov 2024

    The PAN-OS response for GlobalProtect Gateway in Palo Alto Networks PAN-OS 6.1.21 and earlier, PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and earlier may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML. PAN-OS 8.1 is NOT affected.

    Published: 16 Aug 2018
    4.3
    Medium

    CVE-2018-10140

    Last Modified: 21 Nov 2024

    The PAN-OS Management Web Interface in Palo Alto Networks PAN-OS 8.1.2 and earlier may allow an authenticated user to shut down all management sessions, resulting in all logged in users to be redirected to the login page. PAN-OS 6.1, PAN-OS 7.1 and PAN-OS 8.0 are NOT affected.

    Published: 16 Aug 2018
    5.5
    Medium

    CVE-2018-11771

    Last Modified: 21 Nov 2024

    When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the correct EOF indication after the end of the stream has been reached. When combined with a java.io.InputStreamReader this can lead to an infinite stream, which can be used to mount a denial of service attack against services that use Compress' zip package.

    Published: 16 Aug 2018
    5.4
    Medium

    CVE-2018-1715

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147003.

    Published: 16 Aug 2018
    5.3
    Medium

    CVE-2018-15473

    Last Modified: 17 Dec 2025

    OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.

    Published: 16 Aug 2018
    5.2
    Medium

    CVE-2018-10918

    Last Modified: 21 Nov 2024

    A null pointer dereference flaw was found in the way samba checked database outputs from the LDB database layer. An authenticated attacker could use this flaw to crash a samba server in an Active Directory Domain Controller configuration. Samba versions before 4.7.9 and 4.8.4 are vulnerable.

    Published: 16 Aug 2018
    7.4
    High

    CVE-2018-1656

    Last Modified: 21 Nov 2024

    The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files. IBM X-Force ID: 144882.

    Published: 16 Aug 2018
    8.3
    High

    CVE-2018-10873

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.

    Published: 16 Aug 2018
    5.9
    Medium

    CVE-2018-1517

    Last Modified: 21 Nov 2024

    A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data. IBM X-Force ID: 141681.

    Published: 16 Aug 2018
    4.3
    Medium

    CVE-2018-10858

    Last Modified: 21 Nov 2024

    A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.

    Published: 16 Aug 2018
    4.3
    Medium

    CVE-2018-10919

    Last Modified: 21 Nov 2024

    The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.

    Published: 16 Aug 2018
    8.1
    High

    CVE-2018-1139

    Last Modified: 21 Nov 2024

    A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.

    Published: 16 Aug 2018
    6.5
    Medium

    CVE-2018-1140

    Last Modified: 21 Nov 2024

    A missing input sanitization flaw was found in the implementation of LDP database used for the LDAP server. An attacker could use this flaw to cause a denial of service against a samba server, used as a Active Directory Domain Controller. All versions of Samba from 4.8.0 onwards are vulnerable

    Published: 16 Aug 2018
    8.4
    High

    CVE-2018-9363

    Last Modified: 21 Nov 2024

    In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of bounds write with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-65853588 References: Upstream kernel.

    Published: 16 Aug 2018
    7.5
    High

    CVE-2017-13101

    Last Modified: 21 Nov 2024

    Musical.ly Inc., musical.ly - your video social network, 6.1.6, 2017-10-03, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.

    Published: 15 Aug 2018
    7.5
    High

    CVE-2017-13108

    Last Modified: 21 Nov 2024

    DFNDR Security Antivirus, Anti-hacking & Cleaner, 5.0.9, 2017-11-01, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.

    Published: 15 Aug 2018
    7.5
    High

    CVE-2017-13100

    Last Modified: 21 Nov 2024

    DistinctDev, Inc., The Moron Test, 6.3.1, 2017-05-04, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.

    Published: 15 Aug 2018
    5.9
    Medium

    CVE-2017-13105

    Last Modified: 21 Nov 2024

    Hi Security Virus Cleaner - Antivirus, Booster, 3.7.1.1329, 2017-09-13, Android application accepts all SSL certificates during SSL communication. This opens the application up to a man-in-the-middle attack having all of its encrypted traffic intercepted and read by an attacker.

    Published: 15 Aug 2018
    7.5
    High

    CVE-2017-13107

    Last Modified: 21 Nov 2024

    Live.me - live stream video chat, 3.7.20, 2017-11-06, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.

    Published: 15 Aug 2018
    Unknown

    CVE-2017-13103

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 15 Aug 2018
    7.5
    High

    CVE-2017-13102

    Last Modified: 21 Nov 2024

    Gameloft Asphalt Xtreme: Offroad Rally Racing, 1.6.0, 2017-08-13, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.

    Published: 15 Aug 2018
    7.5
    High

    CVE-2017-13104

    Last Modified: 21 Nov 2024

    Uber Technologies, Inc. UberEATS: Uber for Food Delivery, 1.108.10001, 2017-11-02, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.

    Published: 15 Aug 2018