CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-19543

    Last Modified: 21 Nov 2024

    An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.

    Published: 13 Jul 2018
    6.5
    Medium

    CVE-2018-14036

    Last Modified: 21 Nov 2024

    Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c.

    Published: 13 Jul 2018
    9.8
    Critical

    CVE-2018-14352

    Last Modified: 21 Nov 2024

    An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote characters, leading to a stack-based buffer overflow.

    Published: 13 Jul 2018
    8.8
    High

    CVE-2018-19540

    Last Modified: 21 Nov 2024

    An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.0.15, 2.0.16. There is a heap-based buffer overflow of size 1 in the function jas_icctxtdesc_input in libjasper/base/jas_icc.c.

    Published: 13 Jul 2018
    6.5
    Medium

    CVE-2018-19542

    Last Modified: 21 Nov 2024

    An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.

    Published: 13 Jul 2018
    5.5
    Medium

    CVE-2018-14016

    Last Modified: 21 Nov 2024

    The r_bin_mdmp_init_directory_entry function in mdmp.c in radare2 2.7.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Mini Crash Dump file.

    Published: 12 Jul 2018
    5.5
    Medium

    CVE-2018-14017

    Last Modified: 21 Nov 2024

    The r_bin_java_annotation_new function in shlr/java/class.c in radare2 2.7.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted .class file because of missing input validation in r_bin_java_line_number_table_attr_new.

    Published: 12 Jul 2018
    5.5
    Medium

    CVE-2018-14015

    Last Modified: 18 Mar 2025

    The sdb_set_internal function in sdb.c in radare2 2.7.0 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file because of missing input validation in r_bin_dwarf_parse_comp_unit in libr/bin/dwarf.c.

    Published: 12 Jul 2018
    9.8
    Critical

    CVE-2018-14012

    Last Modified: 21 Nov 2024

    WolfSight CMS 3.2 allows SQL injection via the PATH_INFO to the default URI.

    Published: 12 Jul 2018
    8.8
    High

    CVE-2018-14014

    Last Modified: 21 Nov 2024

    In waimai Super Cms 20150505, there is a CSRF vulnerability that can add an admin account via admin.php?m=Member&a=adminadd.

    Published: 12 Jul 2018
    6.5
    Medium

    CVE-2018-12979

    Last Modified: 21 Nov 2024

    An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions allow an authenticated user to overwrite critical files by abusing the unrestricted file upload in the WBM.

    Published: 12 Jul 2018
    5.4
    Medium

    CVE-2018-12981

    Last Modified: 21 Nov 2024

    An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability can be exploited by authenticated and unauthenticated users by sending special crafted requests to the web server allowing injecting code within the WBM. The code will be rendered and/or executed in the browser of the user's browser.

    Published: 12 Jul 2018
    5.5
    Medium

    CVE-2018-13441

    Last Modified: 21 Nov 2024

    qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.

    Published: 12 Jul 2018
    5.5
    Medium

    CVE-2018-13457

    Last Modified: 21 Nov 2024

    qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.

    Published: 12 Jul 2018
    5.5
    Medium

    CVE-2018-13458

    Last Modified: 21 Nov 2024

    qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.

    Published: 12 Jul 2018
    7.8
    High

    CVE-2018-5529

    Last Modified: 21 Nov 2024

    The svpn component of the F5 BIG-IP APM client prior to version 7.1.7 for Linux and Mac OS X runs as a privileged process and can allow an unprivileged user to assume super-user privileges on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or disrupt service.

    Published: 12 Jul 2018
    6.5
    Medium

    CVE-2018-13796

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site.

    Published: 12 Jul 2018
    8.8
    High

    CVE-2018-12980

    Last Modified: 21 Nov 2024

    An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated user to upload arbitrary files to the file system with the permissions of the web server.

    Published: 12 Jul 2018
    9.8
    Critical

    CVE-2018-14009

    Last Modified: 21 Nov 2024

    Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.

    Published: 12 Jul 2018
    5.9
    Medium

    CVE-2017-14710

    Last Modified: 21 Nov 2024

    The Shein Group Ltd. "SHEIN - Fashion Shopping" app -- aka shein fashion-shopping/id878577184 -- for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 12 Jul 2018
    5.9
    Medium

    CVE-2017-14612

    Last Modified: 21 Nov 2024

    "Shpock Boot Sale & Classifieds" app before 3.17.0 -- aka shpock-boot-sale-classifieds/id557153158 -- for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 12 Jul 2018
    7.4
    High

    CVE-2017-14709

    Last Modified: 21 Nov 2024

    The komoot GmbH "Komoot - Cycling & Hiking Maps" app before 9.3.2 -- aka komoot-cycling-hiking-maps/id447374873 -- for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 12 Jul 2018
    9.8
    Critical

    CVE-2018-12463

    Last Modified: 21 Nov 2024

    An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

    Published: 12 Jul 2018
    7.5
    High

    CVE-2018-13836

    Last Modified: 21 Nov 2024

    An integer overflow vulnerability exists in the function multiTransfer of Rocket Coin (XRC), an Ethereum token smart contract. An attacker could use it to set any user's balance.

    Published: 12 Jul 2018
    7.5
    High

    CVE-2018-14001

    Last Modified: 21 Nov 2024

    An integer overflow vulnerability exists in the function batchTransfer of SHARKTECH (SKT), an Ethereum token smart contract. An attacker could use it to set any user's balance.

    Published: 12 Jul 2018
    7.5
    High

    CVE-2018-14002

    Last Modified: 21 Nov 2024

    An integer overflow vulnerability exists in the function distribute of MP3 Coin (MP3), an Ethereum token smart contract. An attacker could use it to set any user's balance.

    Published: 12 Jul 2018
    7.5
    High

    CVE-2018-14003

    Last Modified: 21 Nov 2024

    An integer overflow vulnerability exists in the function batchTransfer of WeMediaChain (WMC), an Ethereum token smart contract. An attacker could use it to set any user's balance.

    Published: 12 Jul 2018
    7.5
    High

    CVE-2018-14004

    Last Modified: 21 Nov 2024

    An integer overflow vulnerability exists in the function transfer_tokens_after_ICO of GlobeCoin (GLB), an Ethereum token smart contract. An attacker could use it to set any user's balance.

    Published: 12 Jul 2018
    7.5
    High

    CVE-2018-14005

    Last Modified: 21 Nov 2024

    An integer overflow vulnerability exists in the function transferAny of Malaysia coins (Xmc), an Ethereum token smart contract. An attacker could use it to set any user's balance.

    Published: 12 Jul 2018
    7.5
    High

    CVE-2018-14006

    Last Modified: 21 Nov 2024

    An integer overflow vulnerability exists in the function multipleTransfer of Neo Genesis Token (NGT), an Ethereum token smart contract. An attacker could use it to set any user's balance.

    Published: 12 Jul 2018
    7.8
    High

    CVE-2017-18155

    Last Modified: 21 Nov 2024

    While playing HEVC content using HD DMB in Snapdragon Automobile and Snapdragon Mobile in version MSM8996AU, SD 450, SD 625, SD 820, SD 820A, SD 835, an uninitialized variable can be used leading to a kernel fault.

    Published: 12 Jul 2018
    4.7
    Medium

    CVE-2018-1334

    Last Modified: 21 Nov 2024

    In Apache Spark 1.0.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, when using PySpark or SparkR, it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application.

    Published: 12 Jul 2018
    5.4
    Medium

    CVE-2018-8024

    Last Modified: 21 Nov 2024

    In Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark cluster's UI's job and stage info pages, and if a user can be tricked into accessing the URL, can be used to cause script to execute and expose information from the user's view of the Spark UI. While some browsers like recent versions of Chrome and Safari are able to block this type of attack, current versions of Firefox (and possibly others) do not.

    Published: 12 Jul 2018
    7.5
    High

    CVE-2018-13997

    Last Modified: 21 Nov 2024

    Genann through 2018-07-08 has a SEGV in genann_run in genann.c.

    Published: 12 Jul 2018
    4.8
    Medium

    CVE-2018-13999

    Last Modified: 21 Nov 2024

    Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administrator).

    Published: 12 Jul 2018
    9.3
    Critical

    CVE-2018-10895

    Last Modified: 21 Nov 2024

    qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious website could exploit this to load a 'qute://settings/set' URL, which then sets 'editor.command' to a bash script, resulting in arbitrary code execution.

    Published: 12 Jul 2018
    9.8
    Critical

    CVE-2018-13996

    Last Modified: 21 Nov 2024

    Genann through 2018-07-08 has a stack-based buffer over-read in genann_train in genann.c.

    Published: 12 Jul 2018
    4.8
    Medium

    CVE-2018-13998

    Last Modified: 21 Nov 2024

    ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users.

    Published: 12 Jul 2018
    8.8
    High

    CVE-2018-12540

    Last Modified: 21 Nov 2024

    In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are not expired yet.

    Published: 12 Jul 2018
    4.7
    Medium

    CVE-2018-14038

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-7642. Reason: This candidate is a reservation duplicate of CVE-2018-7642. Notes: All CVE users should reference CVE-2018-7642 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 12 Jul 2018
    9.8
    Critical

    CVE-2018-15494

    Last Modified: 21 Nov 2024

    In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.

    Published: 12 Jul 2018
    6.5
    Medium

    CVE-2018-16641

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-6 has a memory leak vulnerability in the TIFFWritePhotoshopLayers function in coders/tiff.c.

    Published: 12 Jul 2018
    6.5
    Medium

    CVE-2018-14048

    Last Modified: 21 Nov 2024

    An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image.

    Published: 12 Jul 2018
    5.9
    Medium

    CVE-2016-0708

    Last Modified: 21 Nov 2024

    Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limited to environment variables and bound service details. For applications to be vulnerable, they must have been staged using automatic buildpack detection, passed through the Java Buildpack detection script, and allow the serving of static content from within the deployed artifact. The default Apache Tomcat configuration in the affected java buildpack versions for some basic web application archive (WAR) packaged applications are vulnerable to this issue.

    Published: 11 Jul 2018
    5.9
    Medium

    CVE-2018-11045

    Last Modified: 21 Nov 2024

    Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image. An attacker with knowledge of the exact version and IaaS of a running OpsManager could get the contents of the corresponding seed from the published image and therefore infer the initial state of the LRNG.

    Published: 11 Jul 2018
    7.3
    High

    CVE-2018-11049

    Last Modified: 21 Nov 2024

    RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A local authenticated malicious user could trick the root user to run malicious code on the targeted system.

    Published: 11 Jul 2018
    7.8
    High

    CVE-2018-0024

    Last Modified: 21 Nov 2024

    An Improper Privilege Management vulnerability in a shell session of Juniper Networks Junos OS allows an authenticated unprivileged attacker to gain full control of the system. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D45 on SRX Series; 12.3X48 versions prior to 12.3X48-D20 on SRX Series; 12.3 versions prior to 12.3R11 on EX Series; 14.1X53 versions prior to 14.1X53-D30 on EX2200/VC, EX3200, EX3300/VC, EX4200, EX4300, EX4550/VC, EX4600, EX6200, EX8200/VC (XRE), QFX3500, QFX3600, QFX5100;; 15.1X49 versions prior to 15.1X49-D20 on SRX Series.

    Published: 11 Jul 2018
    7.5
    High

    CVE-2018-0027

    Last Modified: 21 Nov 2024

    Receipt of a crafted or malformed RSVP PATH message may cause the routing protocol daemon (RPD) to hang or crash. When RPD is unavailable, routing updates cannot be processed which can lead to an extended network outage. If RSVP is not enabled on an interface, then the issue cannot be triggered via that interface. This issue only affects Juniper Networks Junos OS 16.1 versions prior to 16.1R3. This issue does not affect Junos releases prior to 16.1R1.

    Published: 11 Jul 2018
    5.7
    Medium

    CVE-2018-0029

    Last Modified: 21 Nov 2024

    While experiencing a broadcast storm, placing the fxp0 interface into promiscuous mode via the 'monitor traffic interface fxp0' can cause the system to crash and restart (vmcore). This issue only affects Junos OS 15.1 and later releases, and affects both single core and multi-core REs. Releases prior to Junos OS 15.1 are unaffected by this vulnerability. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1F6-S11, 15.1R4-S9, 15.1R6-S6, 15.1R7; 15.1X49 versions prior to 15.1X49-D140; 15.1X53 versions prior to 15.1X53-D59 on EX2300/EX3400; 15.1X53 versions prior to 15.1X53-D67 on QFX10K; 15.1X53 versions prior to 15.1X53-D233 on QFX5200/QFX5110; 15.1X53 versions prior to 15.1X53-D471, 15.1X53-D490 on NFX; 16.1 versions prior to 16.1R3-S8, 16.1R5-S4, 16.1R6-S1, 16.1R7; 16.2 versions prior to 16.2R1-S6, 16.2R2-S5, 16.2R3; 17.1 versions prior to 17.1R1-S7, 17.1R2-S7, 17.1R3; 17.2 versions prior to 17.2R1-S6, 17.2R2-S4, 17.2R3; 17.2X75 versions prior to 17.2X75-D90, 17.2X75-D110; 17.3 versions prior to 17.3R1-S4, 17.3R2; 17.4 versions prior to 17.4R1-S3, 17.4R2.

    Published: 11 Jul 2018
    5.3
    Medium

    CVE-2018-0034

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in the Juniper Networks Junos OS JDHCPD daemon which allows an attacker to core the JDHCPD daemon by sending a crafted IPv6 packet to the system. This issue is limited to systems which receives IPv6 DHCP packets on a system configured for DHCP processing using the JDHCPD daemon. This issue does not affect IPv4 DHCP packet processing. Affected releases are Juniper Networks Junos OS: 12.3 versions prior to 12.3R12-S10 on EX Series; 12.3X48 versions prior to 12.3X48-D70 on SRX Series; 14.1X53 versions prior to 14.1X53-D47 on EX2200/VC, EX3200, EX3300/VC, EX4200, EX4300, EX4550/VC, EX4600, EX6200, EX8200/VC (XRE), QFX3500, QFX3600, QFX5100; 14.1X53 versions prior to 14.1X53-D130 on QFabric; 15.1 versions prior to 15.1R4-S9, 15.1R6-S6, 15.1R7; 15.1X49 versions prior to 15.1X49-D140 on SRX Series; 15.1X53 versions prior to 15.1X53-D67 on QFX10000 Series; 15.1X53 versions prior to 15.1X53-D233 on QFX5110, QFX5200; 15.1X53 versions prior to 15.1X53-D471 on NFX 150, NFX 250; 16.1 versions prior to 16.1R3-S9, 16.1R4-S8, 16.1R5-S4, 16.1R6-S3, 16.1R7; 16.2 versions prior to 16.2R2-S5, 16.2R3; 17.1 versions prior to 17.1R1-S7, 17.1R2-S7, 17.1R3; 17.2 versions prior to 17.2R1-S6, 17.2R2-S4, 17.2R3; 17.3 versions prior to 17.3R1-S4, 17.3R2-S2, 17.3R3; 17.4 versions prior to 17.4R1-S3, 17.4R2.

    Published: 11 Jul 2018