CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2017-17708

    Last Modified: 21 Nov 2024

    Because of insufficient authorization checks it is possible for any authenticated user to change profile data of other users in Pleasant Password Server before 7.8.3.

    Published: 31 Jul 2018
    7.5
    High

    CVE-2018-7994

    Last Modified: 21 Nov 2024

    Some Huawei products IPS Module V500R001C50; NGFW Module V500R001C50; V500R002C10; NIP6300 V500R001C50; NIP6600 V500R001C50; NIP6800 V500R001C50; Secospace USG6600 V500R001C50; USG9500 V500R001C50 have a memory leak vulnerability. The software does not release allocated memory properly when processing Protal questionnaire. A remote attacker could send a lot questionnaires to the device, successful exploit could cause the device to reboot since running out of memory.

    Published: 31 Jul 2018
    7.5
    High

    CVE-2018-11338

    Last Modified: 21 Nov 2024

    Intuit Lacerte 2017 for Windows in a client/server environment transfers the entire customer list in cleartext over SMB, which allows attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (MITM) attacks via unspecified vectors. The customer list contains each customer's full name, social security number (SSN), address, job title, phone number, Email address, spouse's phone/Email address, and other sensitive information. After the client software authenticates to the server database, the server sends the customer list. There is no need for further exploitation as all sensitive data is exposed. This vulnerability was validated on Intuit Lacerte 2017, however older versions of Lacerte may be vulnerable.

    Published: 31 Jul 2018
    6.5
    Medium

    CVE-2018-12939

    Last Modified: 21 Nov 2024

    A directory traversal flaw in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows an authenticated attacker to write to (or potentially delete) arbitrary files via a .. (dot dot) in the "op/op.UploadChunks.php" "qquuid" parameter. NOTE: this can be leveraged to execute arbitrary code by using CVE-2018-12940.

    Published: 31 Jul 2018
    8.8
    High

    CVE-2018-12941

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 by adding a system command at the end of the "cacheDir" path and following usage of the "Clear Cache" functionality. This allows an authenticated attacker, with permission to the Settings functionality, to inject arbitrary system commands within the application by manipulating the "Cache directory" path. An attacker can use it to perform malicious tasks such as to extract, change, or delete sensitive information or run system commands on the underlying operating system.

    Published: 31 Jul 2018
    6.1
    Medium

    CVE-2018-12943

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) vulnerability in every page that includes the "action" URL parameter in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Published: 31 Jul 2018
    7.8
    High

    CVE-2018-14581

    Last Modified: 21 Nov 2024

    Redgate .NET Reflector before 10.0.7.774 and SmartAssembly before 6.12.5 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific embedded resource file.

    Published: 31 Jul 2018
    3.9
    Low

    CVE-2018-7947

    Last Modified: 21 Nov 2024

    Huawei mobile phones with versions earlier before Emily-AL00A 8.1.0.153(C00) have an authentication bypass vulnerability. An attacker could trick the user to connect to a malicious device. In the debug mode, the malicious software in the device may exploit the vulnerability to bypass some specific function. Successful exploit may cause some malicious applications to be installed in the mobile phones.

    Published: 31 Jul 2018
    5.5
    Medium

    CVE-2018-7992

    Last Modified: 21 Nov 2024

    Mdapt Driver of Huawei MediaPad M3 BTV-W09C128B353CUSTC128D001; Mate 9 Pro versions earlier than 8.0.0.356(C00); P10 Plus versions earlier than 8.0.0.357(C00) has a buffer overflow vulnerability. The driver does not sufficiently validate the input, an attacker could trick the user to install a malicious application which would send crafted parameters to the driver. Successful exploit could cause a denial of service condition.

    Published: 31 Jul 2018
    5.4
    Medium

    CVE-2018-1718

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 5.2.0.1 - 5.2.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147166.

    Published: 31 Jul 2018
    5.9
    Medium

    CVE-2018-1638

    Last Modified: 21 Nov 2024

    IBM API Connect 5.0.0.0-5.0.8.3 Developer Portal does not enforce Two Factor Authentication (TFA) while resetting a user password but enforces it for all other login scenarios. IBM X-Force ID: 144483.

    Published: 31 Jul 2018
    9.8
    Critical

    CVE-2018-14767

    Last Modified: 21 Nov 2024

    In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault and crash. The reason is missing input validation in the "build_res_buf_from_sip_req" core function. This could result in denial of service and potentially the execution of arbitrary code.

    Published: 31 Jul 2018
    9.8
    Critical

    CVE-2018-8027

    Last Modified: 21 Nov 2024

    Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.

    Published: 31 Jul 2018
    2.5
    Low

    CVE-2017-18869

    Last Modified: 21 Nov 2024

    A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.

    Published: 31 Jul 2018
    9.8
    Critical

    CVE-2018-3772

    Last Modified: 21 Nov 2024

    Concatenating unsanitized user input in the `whereis` npm module < 0.4.1 allowed an attacker to execute arbitrary commands. The `whereis` module is deprecated and it is recommended to use the `which` npm module instead.

    Published: 30 Jul 2018
    6.1
    Medium

    CVE-2018-3773

    Last Modified: 21 Nov 2024

    There is a stored Cross-Site Scripting vulnerability in Open Graph meta properties read by the `metascrape` npm module <= 3.9.2.

    Published: 30 Jul 2018
    4.2
    Medium

    CVE-2018-10847

    Last Modified: 21 Nov 2024

    prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts. A user may authenticate to XMPP host A and migrate their authenticated session to XMPP host B of the same Prosody instance.

    Published: 30 Jul 2018
    8.8
    High

    CVE-2018-9066

    Last Modified: 21 Nov 2024

    In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user can, under specific circumstances, inject additional parameters into a specific web API call which can result in privileged command execution within LXCA's underlying operating system.

    Published: 30 Jul 2018
    8.8
    High

    CVE-2018-9064

    Last Modified: 21 Nov 2024

    In Lenovo xClarity Administrator versions earlier than 2.1.0, an authenticated LXCA user may abuse a web API debug call to retrieve the credentials for the System Manager user.

    Published: 30 Jul 2018
    7.5
    High

    CVE-2018-9065

    Last Modified: 21 Nov 2024

    In Lenovo xClarity Administrator versions earlier than 2.1.0, an attacker that gains access to the underlying LXCA file system user may be able to retrieve a credential store containing the service processor user names and passwords for servers previously managed by that LXCA instance, and potentially decrypt those credentials more easily than intended.

    Published: 30 Jul 2018
    7.4
    High

    CVE-2018-13280

    Last Modified: 14 Jan 2025

    Use of insufficiently random values vulnerability in SYNO.Encryption.GenRandomKey in Synology DiskStation Manager (DSM) before 6.2-23739 allows man-in-the-middle attackers to compromise non-HTTPS sessions via unspecified vectors.

    Published: 30 Jul 2018
    5.3
    Medium

    CVE-2018-14625

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux Kernel where an attacker may be able to have an uncontrolled read to kernel-memory from within a vm guest. A race condition between connect() and close() function may allow an attacker using the AF_VSOCK protocol to gather a 4 byte information leak or possibly intercept or corrupt AF_VSOCK messages destined to other clients.

    Published: 30 Jul 2018
    9.1
    Critical

    CVE-2018-25010

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().

    Published: 30 Jul 2018
    9.8
    Critical

    CVE-2018-25011

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().

    Published: 30 Jul 2018
    6.5
    Medium

    CVE-2018-19869

    Last Modified: 21 Nov 2024

    An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp.

    Published: 30 Jul 2018
    7.8
    High

    CVE-2018-15857

    Last Modified: 21 Nov 2024

    An invalid free in ExprAppendMultiKeysymList in xkbcomp/ast-build.c in xkbcommon before 0.8.1 could be used by local attackers to crash xkbcommon keymap parsers or possibly have unspecified other impact by supplying a crafted keymap file.

    Published: 30 Jul 2018
    8.8
    High

    CVE-2018-1999040

    Last Modified: 21 Nov 2024

    An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.

    Published: 30 Jul 2018
    10
    Critical

    CVE-2018-3774

    Last Modified: 21 Nov 2024

    Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.

    Published: 30 Jul 2018
    7.5
    High

    CVE-2018-14736

    Last Modified: 21 Nov 2024

    An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A buffer over-read can occur in pbc_wmessage_string in wmessage.c for PTYPE_ENUM.

    Published: 29 Jul 2018
    7.5
    High

    CVE-2018-14740

    Last Modified: 21 Nov 2024

    An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in set_field_one in bootstrap.c while making a query.

    Published: 29 Jul 2018
    7.5
    High

    CVE-2018-14741

    Last Modified: 21 Nov 2024

    An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in pbc_pattern_pack in pattern.c.

    Published: 29 Jul 2018
    7.5
    High

    CVE-2018-14742

    Last Modified: 21 Nov 2024

    An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in set_field_one in bootstrap.c during a memcpy.

    Published: 29 Jul 2018
    7.5
    High

    CVE-2018-14743

    Last Modified: 21 Nov 2024

    An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in wiretype_decode in context.c.

    Published: 29 Jul 2018
    9.8
    Critical

    CVE-2018-14744

    Last Modified: 21 Nov 2024

    An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A use-after-free can occur in _pbcM_sp_query in map.c.

    Published: 29 Jul 2018
    7.5
    High

    CVE-2018-14737

    Last Modified: 21 Nov 2024

    An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A NULL pointer dereference can occur in pbc_wmessage_string in wmessage.c.

    Published: 29 Jul 2018
    7.5
    High

    CVE-2018-14738

    Last Modified: 21 Nov 2024

    An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in pbc_rmessage_message in rmessage.c.

    Published: 29 Jul 2018
    7.5
    High

    CVE-2018-14739

    Last Modified: 21 Nov 2024

    An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in pbc_pattern_set_default in pattern.c.

    Published: 29 Jul 2018
    7.5
    High

    CVE-2018-15173

    Last Modified: 21 Nov 2024

    Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted TCP-based service.

    Published: 29 Jul 2018
    9.8
    Critical

    CVE-2018-14685

    Last Modified: 21 Nov 2024

    The add function in www/Lib/Lib/Action/Admin/TplAction.class.php in Gxlcms v1.1.4 allows remote attackers to read arbitrary files via a crafted index.php?s=Admin-Tpl-ADD-id request, related to Lib/Common/Admin/function.php.

    Published: 28 Jul 2018
    6.1
    Medium

    CVE-2018-14686

    Last Modified: 21 Nov 2024

    system/edit_book.php in XYCMS 1.7 has stored XSS via a crafted add_do.php request, related to add_book.php.

    Published: 28 Jul 2018
    5.9
    Medium

    CVE-2018-0497

    Last Modified: 21 Nov 2024

    ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuite) via a timing-based side-channel attack. This vulnerability exists because of an incorrect fix (with a wrong SHA-384 calculation) for CVE-2013-0169.

    Published: 28 Jul 2018
    4.7
    Medium

    CVE-2018-0498

    Last Modified: 21 Nov 2024

    ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack.

    Published: 28 Jul 2018
    8.1
    High

    CVE-2017-2649

    Last Modified: 21 Nov 2024

    It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.

    Published: 27 Jul 2018
    8.5
    High

    CVE-2017-2650

    Last Modified: 21 Nov 2024

    It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commit access, as well as users with e.g. Job/Configure permission in Jenkins.

    Published: 27 Jul 2018
    8.8
    High

    CVE-2017-2652

    Last Modified: 21 Nov 2024

    It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission, allowing anyone with that permission to run arbitrary shell commands on all connected nodes.

    Published: 27 Jul 2018
    6.8
    Medium

    CVE-2017-2648

    Last Modified: 21 Nov 2024

    It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks.

    Published: 27 Jul 2018
    8.2
    High

    CVE-2017-2663

    Last Modified: 21 Nov 2024

    It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and com.redhat.RHSM1.Config.Set methods. An unprivileged local attacker could use these methods to gain access to private information, or launch a privilege escalation attack.

    Published: 27 Jul 2018
    7.5
    High

    CVE-2017-15120

    Last Modified: 21 Nov 2024

    An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing a specially crafted answer containing a CNAME of a different class than IN. An unauthenticated remote attacker could cause a denial of service.

    Published: 27 Jul 2018
    6.6
    Medium

    CVE-2018-6686

    Last Modified: 21 Nov 2024

    Authentication Bypass vulnerability in TPM autoboot in McAfee Drive Encryption (MDE) 7.1.0 and above allows physically proximate attackers to bypass local security protection via specific set of circumstances.

    Published: 27 Jul 2018
    7.5
    High

    CVE-2018-14601

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.2. A Denial of Service can occur because Markdown rendering times are slow.

    Published: 27 Jul 2018