CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2018-14513

    Last Modified: 21 Nov 2024

    An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[content] parameter to the index.php?m=feedback&f=index&v=contact URI.

    Published: 23 Jul 2018
    8.8
    High

    CVE-2018-14522

    Last Modified: 21 Nov 2024

    An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_pitch_set_unit in pitch/pitch.c, as demonstrated by aubionotes.

    Published: 23 Jul 2018
    9.8
    Critical

    CVE-2018-14531

    Last Modified: 21 Nov 2024

    An issue was discovered in Bento4 1.5.1-624. There is an unspecified "heap-buffer-overflow" crash in the AP4_HvccAtom class in Core/Ap4HvccAtom.cpp.

    Published: 23 Jul 2018
    9.8
    Critical

    CVE-2018-14532

    Last Modified: 21 Nov 2024

    An issue was discovered in Bento4 1.5.1-624. There is a heap-based buffer over-read in AP4_Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp after a call from Mp42Hls.cpp, a related issue to CVE-2018-13846.

    Published: 23 Jul 2018
    8.8
    High

    CVE-2018-14523

    Last Modified: 21 Nov 2024

    An issue was discovered in aubio 0.4.6. A buffer over-read can occur in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstrated by aubionotes.

    Published: 23 Jul 2018
    6.1
    Medium

    CVE-2018-14512

    Last Modified: 5 May 2025

    An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[nickname] parameter to the index.php?m=core&f=set&v=sendmail URI. When the administrator accesses the "system settings - mail server" screen, the XSS payload is triggered.

    Published: 23 Jul 2018
    9.8
    Critical

    CVE-2018-14514

    Last Modified: 21 Nov 2024

    An SSRF vulnerability was discovered in idreamsoft iCMS V7.0.9 that allows attackers to read sensitive files, access an intranet, or possibly have unspecified other impact.

    Published: 23 Jul 2018
    5.5
    Medium

    CVE-2018-14543

    Last Modified: 21 Nov 2024

    There exists one NULL pointer dereference vulnerability in AP4_JsonInspector::AddField in Ap4Atom.cpp in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp4dump.

    Published: 23 Jul 2018
    5.5
    Medium

    CVE-2018-15858

    Last Modified: 21 Nov 2024

    Unchecked NULL pointer usage when handling invalid aliases in CopyKeyAliasesToKeymap in xkbcomp/keycodes.c in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file.

    Published: 23 Jul 2018
    6.5
    Medium

    CVE-2018-14335

    Last Modified: 21 Nov 2024

    An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.

    Published: 23 Jul 2018
    9.8
    Critical

    CVE-2018-16328

    Last Modified: 21 Nov 2024

    In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c.

    Published: 23 Jul 2018
    9.8
    Critical

    CVE-2018-16329

    Last Modified: 21 Nov 2024

    In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the GetMagickProperty function in MagickCore/property.c.

    Published: 23 Jul 2018
    6.8
    Medium

    CVE-2018-5383

    Last Modified: 5 Mar 2026

    Bluetooth firmware or operating system software drivers in macOS versions before 10.13, High Sierra and iOS versions before 11.4, and Android versions before the 2018-06-05 patch may not sufficiently validate elliptic curve parameters used to generate public keys during a Diffie-Hellman key exchange, which may allow a remote attacker to obtain the encryption key used by the device.

    Published: 23 Jul 2018
    6.5
    Medium

    CVE-2018-13988

    Last Modified: 21 Nov 2024

    Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file.

    Published: 23 Jul 2018
    8.8
    High

    CVE-2018-14505

    Last Modified: 21 Nov 2024

    mitmweb in mitmproxy v4.0.3 allows DNS Rebinding attacks, related to tools/web/app.py.

    Published: 22 Jul 2018
    9.8
    Critical

    CVE-2018-14501

    Last Modified: 21 Nov 2024

    manager/admin_ajax.php in joyplus-cms 1.6.0 has SQL Injection, as demonstrated by crafted POST data beginning with an "m_id=1 AND SLEEP(5)" substring.

    Published: 22 Jul 2018
    6.1
    Medium

    CVE-2018-14500

    Last Modified: 21 Nov 2024

    joyplus-cms 1.6.0 has XSS via the manager/collect/collect_vod_zhuiju.php keyword parameter.

    Published: 22 Jul 2018
    6.5
    Medium

    CVE-2018-10935

    Last Modified: 21 Nov 2024

    A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.

    Published: 22 Jul 2018
    6.5
    Medium

    CVE-2018-5815

    Last Modified: 21 Nov 2024

    An integer overflow error within the "parse_qt()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.12 can be exploited to trigger an infinite loop via a specially crafted Apple QuickTime file.

    Published: 22 Jul 2018
    6.5
    Medium

    CVE-2018-5816

    Last Modified: 21 Nov 2024

    An integer overflow error within the "identify()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.12 can be exploited to trigger a division by zero via specially crafted NOKIARAW file (Note: This vulnerability is caused due to an incomplete fix of CVE-2018-5804).

    Published: 22 Jul 2018
    7.5
    High

    CVE-2018-1336

    Last Modified: 21 Nov 2024

    An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

    Published: 22 Jul 2018
    7.5
    High

    CVE-2018-8034

    Last Modified: 21 Nov 2024

    The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.

    Published: 22 Jul 2018
    5.9
    Medium

    CVE-2018-8037

    Last Modified: 21 Nov 2024

    If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async request was completed by the application and timed out by the container at the same time. This could also result in a user seeing a response intended for another user. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31.

    Published: 22 Jul 2018
    7.5
    High

    CVE-2018-14492

    Last Modified: 21 Nov 2024

    Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_CN devices have a Stack-based Buffer Overflow via a long limitSpeed or limitSpeedup parameter to an unspecified /goform URI.

    Published: 21 Jul 2018
    7.4
    High

    CVE-2018-8019

    Last Modified: 21 Nov 2024

    When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for revoked client certificates to be incorrectly identified. It was therefore possible for users to authenticate with revoked certificates when using mutual TLS. Users not using OCSP checks are not affected by this vulnerability.

    Published: 21 Jul 2018
    8.8
    High

    CVE-2018-14550

    Last Modified: 21 Nov 2024

    An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow in the function get_token in pnm2png.c in pnm2png.

    Published: 21 Jul 2018
    7.4
    High

    CVE-2018-8020

    Last Modified: 21 Nov 2024

    Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequently, revoked client certificates may not be properly identified, allowing for users to authenticate with revoked certificates to connections that require mutual TLS. Users not using OCSP checks are not affected by this vulnerability.

    Published: 21 Jul 2018
    5.5
    Medium

    CVE-2018-3770

    Last Modified: 21 Nov 2024

    A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the local files.

    Published: 20 Jul 2018
    6.1
    Medium

    CVE-2018-3771

    Last Modified: 21 Nov 2024

    An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browser.

    Published: 20 Jul 2018
    7.8
    High

    CVE-2018-10905

    Last Modified: 21 Nov 2024

    CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an unprivileged local shell could use this flaw to execute commands as a high privileged user.

    Published: 20 Jul 2018
    9.8
    Critical

    CVE-2018-12754

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 20 Jul 2018
    9.8
    Critical

    CVE-2018-12755

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 20 Jul 2018
    9.8
    Critical

    CVE-2018-12756

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 20 Jul 2018
    7.5
    High

    CVE-2018-12757

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 20 Jul 2018
    9.8
    Critical

    CVE-2018-12760

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 20 Jul 2018
    6.5
    Medium

    CVE-2018-12761

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 20 Jul 2018
    7.5
    High

    CVE-2018-12762

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 20 Jul 2018
    6.5
    Medium

    CVE-2018-12764

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 20 Jul 2018
    7.5
    High

    CVE-2018-12765

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 20 Jul 2018
    7.5
    High

    CVE-2018-12766

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 20 Jul 2018
    7.5
    High

    CVE-2018-12767

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 20 Jul 2018
    8.8
    High

    CVE-2018-12771

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 20 Jul 2018
    8.8
    High

    CVE-2018-12772

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 20 Jul 2018
    8.8
    High

    CVE-2018-12773

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 20 Jul 2018
    6.5
    Medium

    CVE-2018-12774

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 20 Jul 2018
    6.5
    Medium

    CVE-2018-12777

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 20 Jul 2018
    6.5
    Medium

    CVE-2018-12779

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 20 Jul 2018
    6.5
    Medium

    CVE-2018-12780

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 20 Jul 2018
    9.8
    Critical

    CVE-2018-12784

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Buffer Errors vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 20 Jul 2018
    8.8
    High

    CVE-2018-12788

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 20 Jul 2018