CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-14602

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. Information Disclosure can occur because the Prometheus metrics feature discloses private project pathnames.

    Published: 27 Jul 2018
    5.4
    Medium

    CVE-2018-14605

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the branch name during a Web IDE file commit.

    Published: 27 Jul 2018
    5.4
    Medium

    CVE-2018-14606

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur via a Milestone name during a promotion.

    Published: 27 Jul 2018
    8.8
    High

    CVE-2018-14603

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. CSRF can occur in the Test feature of the System Hooks component.

    Published: 27 Jul 2018
    6.1
    Medium

    CVE-2018-14604

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the tooltip of the job inside the CI/CD pipeline.

    Published: 27 Jul 2018
    9.8
    Critical

    CVE-2018-14720

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.

    Published: 27 Jul 2018
    9.8
    Critical

    CVE-2018-14718

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.

    Published: 27 Jul 2018
    9.8
    Critical

    CVE-2018-14719

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.

    Published: 27 Jul 2018
    10
    Critical

    CVE-2018-14721

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.

    Published: 27 Jul 2018
    7.5
    High

    CVE-2018-14607

    Last Modified: 21 Nov 2024

    Thomson Reuters UltraTax CS 2017 on Windows, in a client/server configuration, transfers customer records and bank account numbers in cleartext over SMBv2, which allows attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (MITM) attacks via unspecified vectors. The customer record transferred in cleartext contains: Client ID, Full Name, Spouse's Full Name, Social Security Number, Spouse's Social Security Number, Occupation, Spouse's Occupation, Daytime Phone, Home Phone, Tax Preparer, Federal and State Taxes to File, Bank Name, Bank Account Number, and possibly other sensitive information.

    Published: 26 Jul 2018
    7.5
    High

    CVE-2018-14608

    Last Modified: 21 Nov 2024

    Thomson Reuters UltraTax CS 2017 on Windows has a password protection option; however, the level of protection might be inconsistent with some customers' expectations because the data is directly accessible in cleartext. Specifically, it stores customer data in unique directories (%install_path%\WinCSI\UT17DATA\client_ID\file_name.XX17) that can be bypassed without authentication by examining the strings of the .XX17 file. The strings stored in the .XX17 file contain each customer's: Full Name, Spouse's Name, Social Security Number, Date of Birth, Occupation, Home Address, Daytime Phone Number, Home Phone Number, Spouse's Address, Spouse's Daytime Phone Number, Spouse's Social Security Number, Spouse's Home Phone Number, Spouse's Occupation, Spouse's Date of Birth, and Spouse's Filing Status.

    Published: 26 Jul 2018
    Unknown

    CVE-2016-7473

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 26 Jul 2018
    Unknown

    CVE-2016-9255

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 26 Jul 2018
    Unknown

    CVE-2017-6173

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 26 Jul 2018
    Unknown

    CVE-2017-6171

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 26 Jul 2018
    Unknown

    CVE-2016-7471

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 26 Jul 2018
    Unknown

    CVE-2016-9246

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 26 Jul 2018
    Unknown

    CVE-2016-9248

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 26 Jul 2018
    Unknown

    CVE-2016-9254

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 26 Jul 2018
    Unknown

    CVE-2016-9258

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 26 Jul 2018
    Unknown

    CVE-2017-6174

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 26 Jul 2018
    Unknown

    CVE-2017-6175

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 26 Jul 2018
    Unknown

    CVE-2017-6176

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 26 Jul 2018
    Unknown

    CVE-2017-6177

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 26 Jul 2018
    Unknown

    CVE-2017-6149

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 26 Jul 2018
    Unknown

    CVE-2017-6170

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 26 Jul 2018
    Unknown

    CVE-2016-7470

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 26 Jul 2018
    Unknown

    CVE-2017-6146

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA due to an erroneous publication. Notes: none

    Published: 26 Jul 2018
    Unknown

    CVE-2017-6172

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 26 Jul 2018
    7.5
    High

    CVE-2018-9068

    Last Modified: 21 Nov 2024

    The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on the IMM2 management network interface. In versions earlier than 4.90 for Lenovo System x and earlier than 6.80 for IBM System x, the credentials to access the SFTP server are hard-coded and described in the IMM2 documentation, allowing an attacker with management network access to obtain the collected FFDC data. After applying the update, the IMM2 will create random SFTP credentials for use with OneCLI.

    Published: 26 Jul 2018
    7.8
    High

    CVE-2018-0619

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in the installer of Glarysoft Glary Utilities (Glary Utilities 5.99 and earlier and Glary Utilities Pro 5.99 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 26 Jul 2018
    7.8
    High

    CVE-2018-0620

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 26 Jul 2018
    7.8
    High

    CVE-2018-0621

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 26 Jul 2018
    7.4
    High

    CVE-2018-0622

    Last Modified: 21 Nov 2024

    The DHC Online Shop App for Android version 3.2.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 26 Jul 2018
    8.8
    High

    CVE-2018-0607

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the Notifications application in the Cybozu Garoon 3.5.0 to 4.6.2 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 26 Jul 2018
    8.8
    High

    CVE-2018-0613

    Last Modified: 21 Nov 2024

    NEC Platforms Calsos CSDX and CSDJ series products (CSDX 1.37210411 and earlier, CSDX(P) 4.37210411 and earlier, CSDX(D) 3.37210411 and earlier, CSDX(S) 2.37210411 and earlier, CSDJ-B 01.03.00 and earlier, CSDJ-H 01.03.00 and earlier, CSDJ-D 01.03.00 and earlier, CSDJ-A 03.00.00) allows remote authenticated attackers to bypass access restriction to conduct arbitrary operations with administrative privilege via unspecified vectors.

    Published: 26 Jul 2018
    6.1
    Medium

    CVE-2018-0614

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in NEC Platforms Calsos CSDX and CSDJ series products (CSDX 1.37210411 and earlier, CSDX(P) 4.37210411 and earlier, CSDX(D) 3.37210411 and earlier, CSDX(S) 2.37210411 and earlier, CSDJ-B 01.03.00 and earlier, CSDJ-H 01.03.00 and earlier, CSDJ-D 01.03.00 and earlier, CSDJ-A 03.00.00) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Jul 2018
    7.5
    High

    CVE-2018-0617

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in ChamaNet MemoCGI v2.1800 to v2.2200 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 26 Jul 2018
    7.8
    High

    CVE-2018-10900

    Last Modified: 21 Nov 2024

    Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.

    Published: 26 Jul 2018
    6.1
    Medium

    CVE-2018-14955

    Last Modified: 21 Nov 2024

    The mail message display page in SquirrelMail through 1.4.22 has XSS via SVG animations (animate to attribute).

    Published: 26 Jul 2018
    6.1
    Medium

    CVE-2018-14950

    Last Modified: 21 Nov 2024

    The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack.

    Published: 26 Jul 2018
    6.1
    Medium

    CVE-2018-14951

    Last Modified: 21 Nov 2024

    The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack.

    Published: 26 Jul 2018
    6.1
    Medium

    CVE-2018-14952

    Last Modified: 21 Nov 2024

    The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math><maction xlink:href=" attack.

    Published: 26 Jul 2018
    6.1
    Medium

    CVE-2018-14953

    Last Modified: 21 Nov 2024

    The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.

    Published: 26 Jul 2018
    6.1
    Medium

    CVE-2018-14954

    Last Modified: 21 Nov 2024

    The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute.

    Published: 26 Jul 2018
    6.8
    Medium

    CVE-2017-12610

    Last Modified: 21 Nov 2024

    In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol message with SASL/PLAIN or SASL/SCRAM authentication when using the built-in PLAIN or SCRAM server implementations in Apache Kafka.

    Published: 26 Jul 2018
    5.4
    Medium

    CVE-2018-1288

    Last Modified: 21 Nov 2024

    In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.

    Published: 26 Jul 2018
    7.5
    High

    CVE-2018-14083

    Last Modified: 21 Nov 2024

    LICA miniCMTS E8K(u/i/...) devices allow remote attackers to obtain sensitive information via a direct POST request for the inc/user.ini file, leading to discovery of a password hash.

    Published: 25 Jul 2018
    6.1
    Medium

    CVE-2018-14430

    Last Modified: 21 Nov 2024

    The Mondula Multi Step Form plugin through 1.2.5 for WordPress allows XSS via the fw_data [id][1], fw_data [id][2], fw_data [id][3], fw_data [id][4], or email field of the contact form, exploitable with an fw_send_email action to wp-admin/admin-ajax.php.

    Published: 25 Jul 2018
    7.8
    High

    CVE-2018-8090

    Last Modified: 21 Nov 2024

    Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe), (QHTSFT32.exe) - Version 10.0.1.38; Quick Heal Internet Security 64 bit 17.00 (QHIS64.exe), (QHISFT64.exe) - Version 10.0.0.37; Quick Heal Internet Security 32 bit 17.00 (QHIS32.exe), (QHISFT32.exe) - Version 10.0.0.37; Quick Heal AntiVirus Pro 64 bit 17.00 (QHAV64.exe), (QHAVFT64.exe) - Version 10.0.0.37; and Quick Heal AntiVirus Pro 32 bit 17.00 (QHAV32.exe), (QHAVFT32.exe) - Version 10.0.0.37 allow DLL Hijacking because of Insecure Library Loading.

    Published: 25 Jul 2018