CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2018-13339

    Last Modified: 21 Nov 2024

    Imperavi Redactor 3 in Angular Redactor 1.1.6, when HTML content mode is used, allows stored XSS, as demonstrated by an onerror attribute of an IMG element, a related issue to CVE-2018-7035.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2016-10724

    Last Modified: 21 Nov 2024

    Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (deprecated since Q1 2016) if an attacker can sign a message with a certain private key that had been known by unintended actors, because of an infinitely sized map. This affects other uses of the codebase, such as Bitcoin Knots before v0.13.0.knots20160814 and many altcoins.

    Published: 5 Jul 2018
    8.8
    High

    CVE-2018-13340

    Last Modified: 21 Nov 2024

    Gleez CMS 1.2.0 has CSRF, as demonstrated by a /page/add request.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2016-10725

    Last Modified: 21 Nov 2024

    In Bitcoin Core before v0.13.0, a non-final alert is able to block the special "final alert" (which is supposed to override all other alerts) because operations occur in the wrong order. This behavior occurs in the remote network alert system (deprecated since Q1 2016). This affects other uses of the codebase, such as Bitcoin Knots before v0.13.0.knots20160814 and many altcoins.

    Published: 5 Jul 2018
    9.8
    Critical

    CVE-2018-12571

    Last Modified: 21 Nov 2024

    uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly causing a traffic amplification and/or SSRF outcome.

    Published: 5 Jul 2018
    8.8
    High

    CVE-2018-12739

    Last Modified: 21 Nov 2024

    In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266.

    Published: 5 Jul 2018
    9.8
    Critical

    CVE-2018-13052

    Last Modified: 21 Nov 2024

    In CyberArk Endpoint Privilege Manager (formerly Viewfinity), Privilege Escalation is possible if the attacker has one process that executes as Admin.

    Published: 5 Jul 2018
    6.1
    Medium

    CVE-2018-9997

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in mail compose in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev28 allows remote attackers to inject arbitrary web script or HTML via the data-target attribute in an HTML page with data-toggle gadgets.

    Published: 5 Jul 2018
    6.5
    Medium

    CVE-2018-9998

    Last Modified: 21 Nov 2024

    Open-Xchange OX App Suite before 7.6.3-rev37, 7.8.x before 7.8.2-rev40, 7.8.3 before 7.8.3-rev48, and 7.8.4 before 7.8.4-rev28 include folder names in API error responses, which allows remote attackers to obtain sensitive information via the folder parameter in an "all" action to api/tasks.

    Published: 5 Jul 2018
    8.1
    High

    CVE-2018-12520

    Last Modified: 21 Nov 2024

    An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program startup. This results in deterministic session IDs being allocated for active user sessions. An attacker with foreknowledge of the operating system and standard library in use by the host running the service and the username of the user whose session they're targeting can abuse the deterministic random number generation in order to hijack the user's session, thus escalating their access.

    Published: 5 Jul 2018
    6.1
    Medium

    CVE-2018-8738

    Last Modified: 21 Nov 2024

    Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS.

    Published: 5 Jul 2018
    6.1
    Medium

    CVE-2018-8046

    Last Modified: 21 Nov 2024

    The getTip() method of Action Columns of Sencha Ext JS 4 to 6 before 6.6.0 is vulnerable to XSS attacks, even when passed HTML-escaped data. This framework brings no built-in XSS protection, so the developer has to ensure that data is correctly sanitized. However, the getTip() method of Action Columns takes HTML-escaped data and un-escapes it. If the tooltip contains user-controlled data, an attacker could exploit this to create a cross-site scripting attack, even when developers took precautions and escaped data.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-10987

    Last Modified: 21 Nov 2024

    An issue was discovered on Dongguan Diqee Diqee360 devices. The affected vacuum cleaner suffers from an authenticated remote code execution vulnerability. An authenticated attacker can send a specially crafted UDP packet, and execute commands on the vacuum cleaner as root. The bug is in the function REQUEST_SET_WIFIPASSWD (UDP command 153). A crafted UDP packet runs "/mnt/skyeye/mode_switch.sh %s" with an attacker controlling the %s variable. In some cases, authentication can be achieved with the default password of 888888 for the admin account.

    Published: 5 Jul 2018
    7.8
    High

    CVE-2018-10988

    Last Modified: 21 Nov 2024

    An issue was discovered on Diqee Diqee360 devices. A firmware update process, integrated into the firmware, starts at boot and tries to find the update folder on the microSD card. It executes code, without a digital signature, as root from the /mnt/sdcard/$PRO_NAME/upgrade.sh or /sdcard/upgrage_360/upgrade.sh pathname.

    Published: 5 Jul 2018
    6.5
    Medium

    CVE-2018-12103

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-890L with firmware 1.21B02beta01 and earlier, DIR-885L/R with firmware 1.21B03beta01 and earlier, and DIR-895L/R with firmware 1.21B04beta04 and earlier devices (all hardware revisions). Due to the predictability of the /docs/captcha_(number).jpeg URI, being local to the network, but unauthenticated to the administrator's panel, an attacker can disclose the CAPTCHAs used by the access point and can elect to load the CAPTCHA of their choosing, leading to unauthorized login attempts to the access point.

    Published: 5 Jul 2018
    9.8
    Critical

    CVE-2018-12113

    Last Modified: 21 Nov 2024

    Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a PASV response.

    Published: 5 Jul 2018
    8.8
    High

    CVE-2018-13031

    Last Modified: 21 Nov 2024

    DamiCMS v6.0.0 aand 6.1.0 allows CSRF via admin.php?s=/Admin/doadd to add an administrator account.

    Published: 5 Jul 2018
    6.8
    Medium

    CVE-2018-12691

    Last Modified: 21 Nov 2024

    Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and earlier allows attackers to bypass network access control via data plane packet injection.

    Published: 5 Jul 2018
    9.8
    Critical

    CVE-2018-12976

    Last Modified: 21 Nov 2024

    In Go Doc Dot Org (gddo) through 2018-06-27, an attacker could use specially crafted <go-import> tags in packages being fetched by gddo to cause a directory traversal and remote code execution.

    Published: 5 Jul 2018
    6.8
    Medium

    CVE-2018-7944

    Last Modified: 21 Nov 2024

    Huawei smart phones Emily-AL00A with software 8.1.0.106(SP2C00) and 8.1.0.107(SP5C00) have a Factory Reset Protection (FRP) bypass vulnerability. An attacker gets some user's smart phone and performs some special operations in the guide function. The attacker may exploit the vulnerability to bypass FRP function and use the phone normally.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13325

    Last Modified: 21 Nov 2024

    The _sell function of a smart contract implementation for GROWCHAIN (GROW), an Ethereum token, has an integer overflow.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13328

    Last Modified: 21 Nov 2024

    The transfer, transferFrom, and mint functions of a smart contract implementation for PFGc, an Ethereum token, have an integer overflow.

    Published: 5 Jul 2018
    6.1
    Medium

    CVE-2017-11175

    Last Modified: 21 Nov 2024

    In J2 Innovations FIN Stack 4.0, the authentication webform is vulnerable to reflected XSS via the query string to /login.

    Published: 5 Jul 2018
    6.5
    Medium

    CVE-2018-12021

    Last Modified: 21 Nov 2024

    Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few specific Singularity features.

    Published: 5 Jul 2018
    6.1
    Medium

    CVE-2018-13252

    Last Modified: 21 Nov 2024

    Entrust Datacard Syntera CS 5.x has XSS via the name field of "Domain or Computer Name" in the login page.

    Published: 5 Jul 2018
    6.5
    Medium

    CVE-2018-13301

    Last Modified: 21 Nov 2024

    In FFmpeg 4.0.1, due to a missing check of a profile value before setting it, the ff_mpeg4_decode_picture_header function in libavcodec/mpeg4videodec.c may trigger a NULL pointer dereference while converting a crafted AVI file to MPEG4, leading to a denial of service.

    Published: 5 Jul 2018
    8.8
    High

    CVE-2018-13302

    Last Modified: 21 Nov 2024

    In FFmpeg 4.0.1, improper handling of frame types (other than EAC3_FRAME_TYPE_INDEPENDENT) that have multiple independent substreams in the handle_eac3 function in libavformat/movenc.c may trigger an out-of-array access while converting a crafted AVI file to MPEG4, leading to a denial of service or possibly unspecified other impact.

    Published: 5 Jul 2018
    6.5
    Medium

    CVE-2018-13303

    Last Modified: 21 Nov 2024

    In FFmpeg 4.0.1, a missing check for failure of a call to init_get_bits8() in the avpriv_ac3_parse_header function in libavcodec/ac3_parser.c may trigger a NULL pointer dereference while converting a crafted AVI file to MPEG4, leading to a denial of service.

    Published: 5 Jul 2018
    8.1
    High

    CVE-2018-13305

    Last Modified: 21 Nov 2024

    In FFmpeg 4.0.1, due to a missing check for negative values of the mquant variable, the vc1_put_blocks_clamped function in libavcodec/vc1_block.c may trigger an out-of-array access while converting a crafted AVI file to MPEG4, leading to an information disclosure or a denial of service.

    Published: 5 Jul 2018
    8.1
    High

    CVE-2018-13300

    Last Modified: 21 Nov 2024

    In FFmpeg 3.2 and 4.0.1, an improper argument (AVCodecParameters) passed to the avpriv_request_sample function in the handle_eac3 function in libavformat/movenc.c may trigger an out-of-array read while converting a crafted AVI file to MPEG4, leading to a denial of service and possibly an information disclosure.

    Published: 5 Jul 2018
    6.5
    Medium

    CVE-2018-13304

    Last Modified: 21 Nov 2024

    In libavcodec in FFmpeg 4.0.1, improper maintenance of the consistency between the context profile field and studio_profile in libavcodec may trigger an assertion failure while converting a crafted AVI file to MPEG4, leading to a denial of service, related to error_resilience.c, h263dec.c, and mpeg4videodec.c.

    Published: 5 Jul 2018
    8.1
    High

    CVE-2018-3761

    Last Modified: 21 Nov 2024

    Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.

    Published: 5 Jul 2018
    4.3
    Medium

    CVE-2018-3762

    Last Modified: 21 Nov 2024

    Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to.

    Published: 5 Jul 2018
    4.8
    Medium

    CVE-2018-3764

    Last Modified: 21 Nov 2024

    In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group admins.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-3766

    Last Modified: 21 Nov 2024

    Path traversal in buttle module versions <= 0.2.0 allows to read any file in the server.

    Published: 5 Jul 2018
    6.1
    Medium

    CVE-2018-3769

    Last Modified: 21 Nov 2024

    ruby-grape ruby gem suffers from a cross-site scripting (XSS) vulnerability via "format" parameter.

    Published: 5 Jul 2018
    8.8
    High

    CVE-2016-10522

    Last Modified: 21 Nov 2024

    rails_admin ruby gem <v1.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. Non-GET methods were not validating CSRF tokens and, as a result, an attacker could hypothetically gain access to the application administrative endpoints exposed by the gem.

    Published: 5 Jul 2018
    9.1
    Critical

    CVE-2018-3767

    Last Modified: 21 Nov 2024

    `memjs` versions <= 1.1.0 allocates and stores buffers on typed input, resulting in DoS and uninitialized memory usage.

    Published: 5 Jul 2018
    Unknown

    CVE-2016-10545

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 5 Jul 2018
    4.8
    Medium

    CVE-2018-3763

    Last Modified: 21 Nov 2024

    In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group admins.

    Published: 5 Jul 2018
    Unknown

    CVE-2018-3768

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-1000539. Reason: This candidate is a reservation duplicate of CVE-2018-1000539. Notes: All CVE users should reference CVE-2018-1000539 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Jul 2018
    6.5
    Medium

    CVE-2018-13250

    Last Modified: 21 Nov 2024

    libming 0.4.8 has a NULL pointer dereference in the getString function of the decompile.c file, related to decompileSTRINGCONCAT. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

    Published: 5 Jul 2018
    6.5
    Medium

    CVE-2018-13251

    Last Modified: 21 Nov 2024

    In libming 0.4.8, there is an excessive memory allocation attempt in the readBytes function of the util/read.c file, related to parseSWF_DEFINEBITSJPEG2. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted swf file.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-8038

    Last Modified: 21 Nov 2024

    Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.

    Published: 5 Jul 2018
    6.5
    Medium

    CVE-2018-8928

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Address Book Editor in Synology CardDAV Server before 6.0.8-0086 allows remote authenticated users to inject arbitrary web script or HTML via the (1) family_name, (2) given_name, or (3) additional_name parameter.

    Published: 5 Jul 2018
    6.5
    Medium

    CVE-2017-16773

    Last Modified: 21 Nov 2024

    Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users to bypass permission checks for directories in POSIX mode.

    Published: 5 Jul 2018
    8.1
    High

    CVE-2018-9185

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file sent to client-side when pages bookmarked in web portal use the Single Sign-On feature.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-12018

    Last Modified: 21 Nov 2024

    The GetBlockHeadersMsg handler in the LES protocol implementation in Go Ethereum (aka geth) before 1.8.11 may lead to an access violation because of an integer signedness error for the array index, which allows attackers to launch a Denial of Service attack by sending a packet with a -1 query.Skip value. The vulnerable remote node would be crashed by such an attack immediately, aka the EPoD (Ethereum Packet of Death) issue.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13157

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for CryptonitexCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 5 Jul 2018
    7.5
    High

    CVE-2018-13159

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for bankcoin (BNK), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 5 Jul 2018