CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-3688

    Last Modified: 21 Nov 2024

    Unquoted service paths in Intel Quartus Prime Programmer and Tools in versions 15.1 - 18.0 allow a local attacker to potentially execute arbitrary code.

    Published: 10 Jul 2018
    6.7
    Medium

    CVE-2018-3632

    Last Modified: 21 Nov 2024

    Memory corruption in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 6.x / 7.x / 8.x / 9.x / 10.x / 11.0 / 11.5 / 11.6 / 11.7 / 11.10 / 11.20 could be triggered by an attacker with local administrator permission on the system.

    Published: 10 Jul 2018
    6.1
    Medium

    CVE-2018-13865

    Last Modified: 21 Nov 2024

    An issue was discovered in idreamsoft iCMS 7.0.9. XSS exists via the callback parameter in a public/api.php uploadpic request, bypassing the iWAF protection mechanism.

    Published: 10 Jul 2018
    4.8
    Medium

    CVE-2018-12462

    Last Modified: 21 Nov 2024

    NetIQ iManager 3.1.1 addresses potential XSS vulnerabilities.

    Published: 10 Jul 2018
    4.3
    Medium

    CVE-2018-10890

    Last Modified: 21 Nov 2024

    A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories.

    Published: 10 Jul 2018
    3.5
    Low

    CVE-2018-12461

    Last Modified: 21 Nov 2024

    Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation.

    Published: 10 Jul 2018
    7.5
    High

    CVE-2018-13843

    Last Modified: 21 Nov 2024

    An issue has been found in HTSlib 1.8. It is a memory leak in bgzf_getline in bgzf.c. NOTE: the software maintainer's position is that the "failure to free memory" can be fixed in applications that use the HTSlib library (such as test/test_bgzf.c in the original report) and is not a library issue

    Published: 10 Jul 2018
    9.8
    Critical

    CVE-2018-13845

    Last Modified: 21 Nov 2024

    An issue has been found in HTSlib 1.8. It is a buffer over-read in sam_parse1 in sam.c.

    Published: 10 Jul 2018
    7.5
    High

    CVE-2018-13848

    Last Modified: 21 Nov 2024

    An issue has been found in Bento4 1.5.1-624. It is a SEGV in AP4_StszAtom::GetSampleSize in Core/Ap4StszAtom.cpp.

    Published: 10 Jul 2018
    6.1
    Medium

    CVE-2018-13849

    Last Modified: 21 Nov 2024

    edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequate XSS protection mechanism based on preg_replace.

    Published: 10 Jul 2018
    9.8
    Critical

    CVE-2018-13850

    Last Modified: 21 Nov 2024

    The "Firebase Cloud Messaging (FCM) + Advance Admin Panel" component supporting Firebase Push Notification on iOS (through 2017-10-26) allows SQL injection via the /advance_push/public/login username parameter.

    Published: 10 Jul 2018
    8.8
    High

    CVE-2018-2427

    Last Modified: 21 Nov 2024

    SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.

    Published: 10 Jul 2018
    6.1
    Medium

    CVE-2018-2431

    Last Modified: 21 Nov 2024

    SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

    Published: 10 Jul 2018
    5.4
    Medium

    CVE-2018-2432

    Last Modified: 21 Nov 2024

    SAP BusinessObjects Business Intelligence (BI Launchpad and Central Management Console) versions 4.10, 4.20 and 4.30 allow an attacker to include invalidated data in the HTTP response header sent to a Web user. Successful exploitation of this vulnerability may lead to advanced attacks, including: cross-site scripting and page hijacking.

    Published: 10 Jul 2018
    7.5
    High

    CVE-2018-2433

    Last Modified: 21 Nov 2024

    SAP Gateway (SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.22, 7.45, 7.49 and 7.53) allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

    Published: 10 Jul 2018
    9.1
    Critical

    CVE-2018-2437

    Last Modified: 21 Nov 2024

    The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can lead to: disclosure of information and malicious file insertion or modification.

    Published: 10 Jul 2018
    5.9
    Medium

    CVE-2018-2439

    Last Modified: 21 Nov 2024

    The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is validated for authenticity and validity) and under certain conditions, will process invalid requests. Several areas of the SAP Internet Graphics Server (IGS) did not require sufficient input validation. Namely, the SAP Internet Graphics Server (IGS) HTTP and RFC listener, SAP Internet Graphics Server (IGS) portwatcher when registering a portwatcher to the multiplexer and the SAP Internet Graphics Server (IGS) multiplexer had insufficient input validation and thus allowing a malformed data packet to cause a crash.

    Published: 10 Jul 2018
    4.4
    Medium

    CVE-2018-2440

    Last Modified: 21 Nov 2024

    Under certain circumstances SAP Dynamic Authorization Management (DAM) by NextLabs (Java Policy Controller versions 7.7 and 8.5) exposes sensitive information in the application logs.

    Published: 10 Jul 2018
    6.1
    Medium

    CVE-2018-2435

    Last Modified: 21 Nov 2024

    SAP NetWeaver Enterprise Portal from 7.0 to 7.02, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

    Published: 10 Jul 2018
    4.3
    Medium

    CVE-2018-10889

    Last Modified: 21 Nov 2024

    A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.

    Published: 10 Jul 2018
    7.3
    High

    CVE-2018-10891

    Last Modified: 21 Nov 2024

    A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.

    Published: 10 Jul 2018
    9.8
    Critical

    CVE-2018-13846

    Last Modified: 21 Nov 2024

    An issue has been found in Bento4 1.5.1-624. AP4_Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp has a heap-based buffer over-read after a call from Mp42Ts.cpp, a related issue to CVE-2018-14532.

    Published: 10 Jul 2018
    4.3
    Medium

    CVE-2018-2434

    Last Modified: 21 Nov 2024

    A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user: UI add-on for SAP NetWeaver (UI_Infra, 1.0), SAP UI Implementation for Decoupled Innovations (UI_700, 2.0): SAP NetWeaver 7.00 Implementation, SAP User Interface Technology (SAP_UI 7.4, 7.5, 7.51, 7.52). There is little impact as it is not possible to embed active contents such as JavaScript or hyperlinks.

    Published: 10 Jul 2018
    8.8
    High

    CVE-2018-2436

    Last Modified: 21 Nov 2024

    Executing transaction WRCK in SAP R/3 Enterprise Retail (EHP6) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

    Published: 10 Jul 2018
    7.5
    High

    CVE-2018-2438

    Last Modified: 21 Nov 2024

    The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has several denial-of-service vulnerabilities that allow an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

    Published: 10 Jul 2018
    7.5
    High

    CVE-2018-13844

    Last Modified: 21 Nov 2024

    An issue has been found in HTSlib 1.8. It is a memory leak in fai_read in faidx.c. NOTE: This has been disputed with the assertion that this vulnerability exists in the test harness and HTSlib users would be aware of the need to destruct this object returned by fai_load() in their own code

    Published: 10 Jul 2018
    7.5
    High

    CVE-2018-13847

    Last Modified: 21 Nov 2024

    An issue has been found in Bento4 1.5.1-624. It is a SEGV in AP4_StcoAtom::AdjustChunkOffsets in Core/Ap4StcoAtom.cpp.

    Published: 10 Jul 2018
    8.8
    High

    CVE-2018-1331

    Last Modified: 21 Nov 2024

    In Apache Storm 0.10.0 through 0.10.2, 1.0.0 through 1.0.6, 1.1.0 through 1.1.2, and 1.2.0 through 1.2.1, an attacker with access to a secure storm cluster in some cases could execute arbitrary code as a different user.

    Published: 10 Jul 2018
    5.6
    Medium

    CVE-2018-3693

    Last Modified: 21 Nov 2024

    Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.

    Published: 10 Jul 2018
    5.4
    Medium

    CVE-2017-1791

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137036.

    Published: 10 Jul 2018
    8.4
    High

    CVE-2018-1566

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to execute arbitrary code due to a format string error. IBM X-Force ID: 143023.

    Published: 10 Jul 2018
    6.3
    Medium

    CVE-2017-1738

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 contains an undisclosed vulnerability that would allow an authenticated user to obtain elevated privileges. IBM X-Force ID: 134919.

    Published: 10 Jul 2018
    5.4
    Medium

    CVE-2018-1396

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138429.

    Published: 10 Jul 2018
    7.4
    High

    CVE-2018-1458

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10,1, 10.5 and 11.1 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks. IBM X-Force ID: 140209.

    Published: 10 Jul 2018
    8.4
    High

    CVE-2018-1487

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5 and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege users full access to the DB2 instance account by loading a malicious shared library. IBM X-Force ID: 140972.

    Published: 10 Jul 2018
    5.4
    Medium

    CVE-2018-1523

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141804.

    Published: 10 Jul 2018
    5.4
    Medium

    CVE-2017-1729

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134909.

    Published: 10 Jul 2018
    5.4
    Medium

    CVE-2017-1792

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137037.

    Published: 10 Jul 2018
    5.4
    Medium

    CVE-2017-1793

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137038.

    Published: 10 Jul 2018
    4.3
    Medium

    CVE-2018-1423

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation products could disclose sensitive information to an authenticated attacker that could be used in further attacks against the system. IBM X-Force ID: 139026.

    Published: 10 Jul 2018
    4.3
    Medium

    CVE-2018-1492

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation products could allow a user with physical access to the system to log in as another user due to the server's failure to properly log out from the previous session. IBM X-Force ID: 140977.

    Published: 10 Jul 2018
    5.4
    Medium

    CVE-2018-1549

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 142658.

    Published: 10 Jul 2018
    9.8
    Critical

    CVE-2018-5553

    Last Modified: 21 Nov 2024

    The Crestron Console service running on DGE-100, DM-DGE-200-C, and TS-1542-C devices with default configuration and running firmware versions 1.3384.00049.001 and lower are vulnerable to command injection that can be used to gain root-level access.

    Published: 10 Jul 2018
    5.4
    Medium

    CVE-2018-1521

    Last Modified: 21 Nov 2024

    IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141802.

    Published: 10 Jul 2018
    5.4
    Medium

    CVE-2018-1407

    Last Modified: 21 Nov 2024

    IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138445.

    Published: 10 Jul 2018
    5.4
    Medium

    CVE-2018-1408

    Last Modified: 21 Nov 2024

    IBM Rational Team Concert 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138446.

    Published: 10 Jul 2018
    7.8
    High

    CVE-2018-13833

    Last Modified: 21 Nov 2024

    An issue was discovered in cmft through 2017-09-24. The cmft::rwReadFile function in image.cpp allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact.

    Published: 10 Jul 2018
    7.5
    High

    CVE-2018-10943

    Last Modified: 21 Nov 2024

    An issue was discovered on Barco ClickShare CSE-200 and CS-100 Base Units with firmware before 1.6.0.3. Sending an arbitrary unexpected string to TCP port 7100 respecting a certain frequency timing disconnects all clients and results in a crash of the Unit.

    Published: 10 Jul 2018
    6.5
    Medium

    CVE-2018-10888

    Last Modified: 21 Nov 2024

    A flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead to an out-of-bound read while reading a binary delta file. An attacker may use this flaw to cause a Denial of Service.

    Published: 10 Jul 2018
    9.8
    Critical

    CVE-2018-13818

    Last Modified: 21 Nov 2024

    Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is not a web application and states that it is the responsibility of web applications using Twig to properly wrap input to it

    Published: 10 Jul 2018