CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-14423

    Last Modified: 21 Nov 2024

    Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).

    Published: 16 Jul 2018
    5.3
    Medium

    CVE-2018-14355

    Last Modified: 21 Nov 2024

    An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a mailbox name.

    Published: 16 Jul 2018
    7.5
    High

    CVE-2018-14073

    Last Modified: 24 Apr 2026

    libsixel 1.8.1 has a memory leak in sixel_allocator_new in allocator.c.

    Published: 15 Jul 2018
    7.5
    High

    CVE-2018-14072

    Last Modified: 24 Apr 2026

    libsixel 1.8.1 has a memory leak in sixel_decoder_decode in decoder.c, image_buffer_resize in fromsixel.c, and sixel_decode_raw in fromsixel.c.

    Published: 15 Jul 2018
    8.8
    High

    CVE-2018-14068

    Last Modified: 21 Nov 2024

    An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add an admin account via admin.php?m=Admin&c=manager&a=add.

    Published: 15 Jul 2018
    8.8
    High

    CVE-2018-14069

    Last Modified: 21 Nov 2024

    An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add a user account via admin.php?m=Admin&c=member&a=add.

    Published: 15 Jul 2018
    9.8
    Critical

    CVE-2018-14066

    Last Modified: 21 Nov 2024

    The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phones, allows SQL injection. One consequence is that an application without the READ_SMS permission can read SMS messages. This affects Infinix X571 phones, as well as various Lenovo phones (such as the A7020) that have since been fixed by Lenovo.

    Published: 15 Jul 2018
    9.8
    Critical

    CVE-2018-14063

    Last Modified: 21 Nov 2024

    The increaseApproval function of a smart contract implementation for Tracto (TRCT), an Ethereum ERC20 token, has an integer overflow.

    Published: 15 Jul 2018
    9.8
    Critical

    CVE-2018-14064

    Last Modified: 21 Nov 2024

    The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../../etc/passwd on TCP port 80.

    Published: 15 Jul 2018
    9.8
    Critical

    CVE-2018-14065

    Last Modified: 21 Nov 2024

    XMLReader.php in PHPOffice Common before 0.2.9 allows XXE.

    Published: 15 Jul 2018
    9.8
    Critical

    CVE-2018-14060

    Last Modified: 21 Nov 2024

    OS command injection in the AP mode settings feature in /cgi-bin/luci /api/misystem/set_router_wifiap on Xiaomi R3D before 2.26.4 devices allows an attacker to execute any command via crafted JSON data.

    Published: 15 Jul 2018
    9.8
    Critical

    CVE-2018-14010

    Last Modified: 21 Nov 2024

    OS command injection in the guest Wi-Fi settings feature in /cgi-bin/luci on Xiaomi R3P before 2.14.5, R3C before 2.12.15, R3 before 2.22.15, and R3D before 2.26.4 devices allows an attacker to execute any command via crafted JSON data.

    Published: 15 Jul 2018
    6.5
    Medium

    CVE-2018-14055

    Last Modified: 21 Nov 2024

    ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilege and inject rogue values into znc.conf.

    Published: 15 Jul 2018
    5.3
    Medium

    CVE-2018-14056

    Last Modified: 21 Nov 2024

    ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories.

    Published: 15 Jul 2018
    8.8
    High

    CVE-2018-1000222

    Last Modified: 21 Nov 2024

    Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This attack appear to be exploitable via Specially Crafted Jpeg Image can trigger double free. This vulnerability appears to have been fixed in after commit ac16bdf2d41724b5a65255d4c28fb0ec46bc42f5.

    Published: 15 Jul 2018
    8.1
    High

    CVE-2018-14338

    Last Modified: 21 Nov 2024

    samples/geotag.cpp in the example code of Exiv2 0.26 misuses the realpath function on POSIX platforms (other than Apple platforms) where glibc is not used, possibly leading to a buffer overflow.

    Published: 14 Jul 2018
    6.5
    Medium

    CVE-2019-6470

    Last Modified: 11 Apr 2025

    There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC contain copies of this, and other, BIND libraries in combinations that have been tested prior to release and are known to not present issues like this. Some third-party packagers of ISC software have modified the dhcpd source, BIND source, or version matchup in ways that create the crash potential. Based on reports available to ISC, the crash probability is large and no analysis has been done on how, or even if, the probability can be manipulated by an attacker. Affects: Builds of dhcpd versions prior to version 4.4.1 when using BIND versions 9.11.2 or later, or BIND versions with specific bug fixes backported to them. ISC does not have access to comprehensive version lists for all repackagings of dhcpd that are vulnerable. In particular, builds from other vendors may also be affected. Operators are advised to consult their vendor documentation.

    Published: 14 Jul 2018
    5.3
    Medium

    CVE-2013-0570

    Last Modified: 21 Nov 2024

    The Fibre Channel over Ethernet (FCoE) feature in IBM System Networking and Blade Network Technology (BNT) switches running IBM Networking Operating System (aka NOS, formerly BLADE Operating System) floods data frames with unknown MAC addresses out on all interfaces on the same VLAN, which might allow remote attackers to obtain sensitive information in opportunistic circumstances by eavesdropping on the broadcast domain. IBM X-Force ID: 83166.

    Published: 13 Jul 2018
    4.3
    Medium

    CVE-2016-6549

    Last Modified: 21 Nov 2024

    The Zizai Tech Nut device allows unauthenticated Bluetooth pairing, which enables unauthenticated connected applications to write data to the device name attribute.

    Published: 13 Jul 2018
    9.8
    Critical

    CVE-2016-6554

    Last Modified: 21 Nov 2024

    Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default credentials of: guest:(blank) and admin:(blank) . A remote network attacker can gain privileged access to a vulnerable device.

    Published: 13 Jul 2018
    7.8
    High

    CVE-2016-9485

    Last Modified: 21 Nov 2024

    On Windows endpoints, the SecureConnector agent must run under the local SYSTEM account or another administrator account in order to enable full functionality of the agent. The typical configuration is for the agent to run as a Windows service under the local SYSTEM account. The SecureConnector agent runs various plugin scripts and executables on the endpoint in order to gather and report information about the host to the CounterACT management appliance. The SecureConnector agent downloads these scripts and executables as needed from the CounterACT management appliance and runs them on the endpoint. The SecureConnector agent fails to set any permissions on downloaded file objects. This allows a malicious user to take ownership of any of these files and make modifications to it, regardless of where the files are saved. These files are then executed under SYSTEM privileges. A malicious unprivileged user can overwrite these executable files with malicious code before the SecureConnector agent executes them, causing the malicious code to be run under the SYSTEM account.

    Published: 13 Jul 2018
    8.8
    High

    CVE-2016-9489

    Last Modified: 21 Nov 2024

    In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher privileges like "ADMIN". A user is also able to change properties of another user, e.g. change another user's password.

    Published: 13 Jul 2018
    4.9
    Medium

    CVE-2016-9491

    Last Modified: 21 Nov 2024

    ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored private keys, etc. By default Application Manager is running with administrative privileges, therefore it is possible to access every directory on the underlying operating system.

    Published: 13 Jul 2018
    7.5
    High

    CVE-2016-9484

    Last Modified: 21 Nov 2024

    The generated PHP form code does not properly validate user input folder directories, allowing a remote unauthenticated attacker to perform a path traversal and access arbitrary files on the server. The PHP FormMail Generator website does not use version numbers and is updated continuously. Any PHP form code generated by this website prior to 2016-12-06 may be vulnerable.

    Published: 13 Jul 2018
    3.7
    Low

    CVE-2016-6542

    Last Modified: 21 Nov 2024

    The iTrack device tracking ID number, also called "LosserID" in the web API, can be obtained by being in the range of an iTrack device. The tracker ID is the device's BLE MAC address.

    Published: 13 Jul 2018
    5.9
    Medium

    CVE-2016-6543

    Last Modified: 21 Nov 2024

    A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS data, which can allow unauthenticated parties to track the device.

    Published: 13 Jul 2018
    9.8
    Critical

    CVE-2016-6545

    Last Modified: 21 Nov 2024

    Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password is passed as a POST parameter over HTTPS using a base64 encoded passwd field on every request. In this implementation, sessions can only be terminated when the user changes the associated password.

    Published: 13 Jul 2018
    9.8
    Critical

    CVE-2016-9482

    Last Modified: 21 Nov 2024

    Code generated by PHP FormMail Generator may allow a remote unauthenticated user to bypass authentication in the to access the administrator panel by navigating directly to /admin.php?mod=admin&func=panel

    Published: 13 Jul 2018
    7.5
    High

    CVE-2016-6544

    Last Modified: 21 Nov 2024

    getgps data in iTrack Easy can be modified without authentication by setting the data using the parametercmd:setothergps. This vulnerability can be exploited to alter the GPS data of a lost device.

    Published: 13 Jul 2018
    7.8
    High

    CVE-2016-6546

    Last Modified: 21 Nov 2024

    The iTrack Easy mobile application stores the account password used to authenticate to the cloud API in base64-encoding in the cache.db file. The base64 encoding format is considered equivalent to cleartext.

    Published: 13 Jul 2018
    7.8
    High

    CVE-2016-6547

    Last Modified: 21 Nov 2024

    The Zizai Tech Nut mobile app stores the account password used to authenticate to the cloud API in cleartext in the cache.db file.

    Published: 13 Jul 2018
    9.8
    Critical

    CVE-2016-6548

    Last Modified: 21 Nov 2024

    The Zizai Tech Nut mobile app makes requests via HTTP instead of HTTPS. These requests contain the user's authenticated session token with the URL. An attacker can capture these requests and reuse the session token to gain full access the user's account.

    Published: 13 Jul 2018
    9.8
    Critical

    CVE-2016-6553

    Last Modified: 21 Nov 2024

    Nuuo NT-4040 Titan, firmware NT-4040_01.07.0000.0015_1120, uses non-random default credentials of: admin:admin and localdisplay:111111. A remote network attacker can gain privileged access to a vulnerable device.

    Published: 13 Jul 2018
    7.5
    High

    CVE-2016-6565

    Last Modified: 21 Nov 2024

    The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user to read arbitrary files from the server, or execute arbitrary code on the server in some circumstances (dependent on server configuration).

    Published: 13 Jul 2018
    9.8
    Critical

    CVE-2016-9483

    Last Modified: 21 Nov 2024

    The PHP form code generated by PHP FormMail Generator deserializes untrusted input as part of the phpfmg_filman_download() function. A remote unauthenticated attacker may be able to use this vulnerability to inject PHP code, or along with CVE-2016-9484 to perform local file inclusion attacks and obtain files from the server.

    Published: 13 Jul 2018
    6.1
    Medium

    CVE-2016-9493

    Last Modified: 21 Nov 2024

    The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to stored cross-site scripting. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may lead to execution of the contained PHP code if the attacker can guess the uploaded filename. The form by default appends a short random string to the end of the filename.

    Published: 13 Jul 2018
    6.5
    Medium

    CVE-2016-9494

    Last Modified: 21 Nov 2024

    Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, are potentially vulnerable to improper input validation. The device's advanced status web page that is linked to from the basic status web page does not appear to properly parse malformed GET requests. This may lead to a denial of service.

    Published: 13 Jul 2018
    8.8
    High

    CVE-2016-9495

    Last Modified: 21 Nov 2024

    Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, uses hard coded credentials. Access to the device's default telnet port (23) can be obtained through using one of a few default credentials shared among all devices.

    Published: 13 Jul 2018
    9.8
    Critical

    CVE-2016-9498

    Last Modified: 21 Nov 2024

    ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to execute remote code compromising the application as well as the operating system. As Application Manager's RMI registry is running with privileges of system administrator, by exploiting this vulnerability an attacker gains highest privileges on the underlying operating system.

    Published: 13 Jul 2018
    5.3
    Medium

    CVE-2016-9499

    Last Modified: 21 Nov 2024

    Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.

    Published: 13 Jul 2018
    6.1
    Medium

    CVE-2016-9500

    Last Modified: 21 Nov 2024

    Accellion FTP server prior to version FTA_9_12_220 uses the Accusoft Prizm Content flash component, which contains multiple parameters (customTabCategoryName, customButton1Image) that are vulnerable to cross-site scripting.

    Published: 13 Jul 2018
    7.8
    High

    CVE-2017-13092

    Last Modified: 21 Nov 2024

    The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including improperly specified HDL syntax allows use of an EDA tool as a decryption oracle. The methods are flawed and, in the most egregious cases, enable attack vectors that allow recovery of the entire underlying plaintext IP. Implementations of IEEE P1735 may be weak to cryptographic attacks that allow an attacker to obtain plaintext intellectual property without the key, among other impacts.

    Published: 13 Jul 2018
    7.8
    High

    CVE-2017-13094

    Last Modified: 21 Nov 2024

    The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including modification of the encryption key and insertion of hardware trojans in any IP. The methods are flawed and, in the most egregious cases, enable attack vectors that allow recovery of the entire underlying plaintext IP. Implementations of IEEE P1735 may be weak to cryptographic attacks that allow an attacker to obtain plaintext intellectual property without the key, among other impacts.

    Published: 13 Jul 2018
    7.8
    High

    CVE-2017-13097

    Last Modified: 21 Nov 2024

    The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including modification of Rights Block to remove or relax license requirement. The methods are flawed and, in the most egregious cases, enable attack vectors that allow recovery of the entire underlying plaintext IP. Implementations of IEEE P1735 may be weak to cryptographic attacks that allow an attacker to obtain plaintext intellectual property without the key, among other impacts.

    Published: 13 Jul 2018
    9.8
    Critical

    CVE-2016-6551

    Last Modified: 21 Nov 2024

    Intellian Satellite TV antennas t-Series and v-Series, firmware version 1.07, uses non-random default credentials of: ftp/ftp or intellian:12345678. A remote network attacker can gain elevated access to a vulnerable device.

    Published: 13 Jul 2018
    9.8
    Critical

    CVE-2016-6552

    Last Modified: 21 Nov 2024

    Green Packet DX-350 uses non-random default credentials of: root:wimax. A remote network attacker can gain privileged access to a vulnerable device.

    Published: 13 Jul 2018
    8.8
    High

    CVE-2016-6557

    Last Modified: 21 Nov 2024

    In ASUS RP-AC52 access points with firmware version 1.0.1.1s and possibly earlier, the web interface, the web interface does not sufficiently verify whether a valid request was intentionally provided by the user. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request.

    Published: 13 Jul 2018
    9.8
    Critical

    CVE-2016-6558

    Last Modified: 21 Nov 2024

    A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface specifically in the action_script parameter. The action_script parameter specifies a script to be executed if the action_mode parameter does not contain a valid state. If the input provided by action_script does not match one of the hard coded options, then it will be executed as the argument of either a system() or an eval() call allowing arbitrary commands to be executed.

    Published: 13 Jul 2018
    9.8
    Critical

    CVE-2016-6559

    Last Modified: 21 Nov 2024

    Improper bounds checking of the obuf variable in the link_ntoa() function in linkaddr.c of the BSD libc library may allow an attacker to read or write from memory. The full impact and severity depends on the method of exploit and how the library is used by applications. According to analysis by FreeBSD developers, it is very unlikely that applications exist that utilize link_ntoa() in an exploitable manner, and the CERT/CC is not aware of any proof of concept. A blog post describes the functionality of link_ntoa() and points out that none of the base utilities use this function in an exploitable manner. For more information, please see FreeBSD Security Advisory SA-16:37.

    Published: 13 Jul 2018
    7.5
    High

    CVE-2016-6562

    Last Modified: 21 Nov 2024

    On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificates provided by HTTPS connections, which means that an attacker in the position to perform MITM attacks may be able to obtain sensitive account information such as login credentials.

    Published: 13 Jul 2018