CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2017-1299

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125161.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1306

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125460.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1313

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125724.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1315

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125727.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1561

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131760.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1562

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131761.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1565

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131765.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1592

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132493.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1608

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132928.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1277

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124752.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1281

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124759.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1314

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125725.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1564

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131764.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1652

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133263.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1717

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134796.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1275

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124750.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1621

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133088.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1691

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134066.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1715

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134637.

    Published: 3 Jul 2018
    9.8
    Critical

    CVE-2018-11052

    Last Modified: 21 Nov 2024

    Dell EMC ECS versions 3.2.0.0 and 3.2.0.1 contain an authentication bypass vulnerability. A remote unauthenticated attacker could exploit this vulnerability to read and modify S3 objects by supplying specially crafted S3 requests.

    Published: 3 Jul 2018
    7.8
    High

    CVE-2018-11634

    Last Modified: 21 Nov 2024

    Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web application's user passwords in cleartext by reading /var/www/xms/xmsdb/default.db.

    Published: 3 Jul 2018
    8.8
    High

    CVE-2018-11636

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to execute malicious and unauthorized actions.

    Published: 3 Jul 2018
    7.5
    High

    CVE-2018-11637

    Last Modified: 21 Nov 2024

    Information leakage vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to read arbitrary files from the /var/ directory because a symlink exists under the web root.

    Published: 3 Jul 2018
    7.2
    High

    CVE-2018-11638

    Last Modified: 21 Nov 2024

    Unrestricted Upload of a File with a Dangerous Type in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated users to upload malicious code to the web root to gain code execution.

    Published: 3 Jul 2018
    9.1
    Critical

    CVE-2018-11640

    Last Modified: 21 Nov 2024

    XML External Entity (XXE) vulnerability in the web service in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to read arbitrary files or cause a denial of service (resource consumption).

    Published: 3 Jul 2018
    7.8
    High

    CVE-2018-11642

    Last Modified: 21 Nov 2024

    Incorrect Permission Assignment on the /var/www/xms/cleanzip.sh shell script run periodically in Dialogic PowerMedia XMS through 3.5 allows local users to execute code as the root user.

    Published: 3 Jul 2018
    9.8
    Critical

    CVE-2018-11635

    Last Modified: 21 Nov 2024

    Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to bypass authentication.

    Published: 3 Jul 2018
    8.1
    High

    CVE-2018-11639

    Last Modified: 21 Nov 2024

    Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to access a user's password in cleartext.

    Published: 3 Jul 2018
    9.8
    Critical

    CVE-2018-11641

    Last Modified: 21 Nov 2024

    Use of Hard-coded Credentials in /var/www/xms/application/controllers/gatherLogs.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to interact with a web service.

    Published: 3 Jul 2018
    7.5
    High

    CVE-2018-13112

    Last Modified: 21 Nov 2024

    get_l2len in common/get.c in Tcpreplay 4.3.0 beta1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packets, as demonstrated by tcpprep.

    Published: 3 Jul 2018
    7.5
    High

    CVE-2018-11051

    Last Modified: 21 Nov 2024

    RSA Certificate Manager Versions 6.9 build 560 through 6.9 build 564 contain a path traversal vulnerability in the RSA CMP Enroll Server and the RSA REST Enroll Server. A remote unauthenticated attacker could potentially exploit this vulnerability by manipulating input parameters of the application to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.

    Published: 3 Jul 2018
    8.8
    High

    CVE-2018-11643

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote authenticated users to execute arbitrary SQL commands via the filterPattern parameter.

    Published: 3 Jul 2018
    7.8
    High

    CVE-2018-13102

    Last Modified: 21 Nov 2024

    AnyDesk before "12.06.2018 - 4.1.3" on Windows 7 SP1 has a DLL preloading vulnerability.

    Published: 3 Jul 2018
    9.6
    Critical

    CVE-2018-11316

    Last Modified: 21 Nov 2024

    The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can result in remote device control and privileged device and network information to be exfiltrated by an attacker.

    Published: 3 Jul 2018
    4.8
    Medium

    CVE-2018-13106

    Last Modified: 21 Nov 2024

    ClipperCMS 1.3.3 has stored XSS via the "Tools -> Configuration" screen of the manager/ URI.

    Published: 3 Jul 2018
    5.3
    Medium

    CVE-2018-7635

    Last Modified: 21 Nov 2024

    Whale Browser before 1.0.41.8 displays no URL information but only a title of a web page on the browser's address bar when visiting a blank page, which allows an attacker to display a malicious web page with a fake domain name.

    Published: 3 Jul 2018
    9.8
    Critical

    CVE-2018-4852

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device could potentially circumvent the authentication mechanism if he/she is able to obtain certain knowledge specific to the attacked device.

    Published: 3 Jul 2018
    8.8
    High

    CVE-2018-4854

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp could modify the administrative client stored on the device. If a legitimate user downloads and executes the modified client from the affected device, then he/she could obtain code execution on the client system.

    Published: 3 Jul 2018
    4.3
    Medium

    CVE-2018-7763

    Last Modified: 21 Nov 2024

    The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The 'css' parameter contains a directory traversal vulnerability.

    Published: 3 Jul 2018
    4.3
    Medium

    CVE-2018-7764

    Last Modified: 21 Nov 2024

    The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software versions prior to v1.3.4. There is a directory traversal vulnerability in the processing of the 's' parameter of the applet.

    Published: 3 Jul 2018
    8.8
    High

    CVE-2018-7765

    Last Modified: 21 Nov 2024

    The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the object_id input parameter.

    Published: 3 Jul 2018
    8.8
    High

    CVE-2018-7766

    Last Modified: 21 Nov 2024

    The vulnerability exists within processing of track_getdata.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input parameter.

    Published: 3 Jul 2018
    8.8
    High

    CVE-2018-7767

    Last Modified: 21 Nov 2024

    The vulnerability exists within processing of editobject.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the type input parameter.

    Published: 3 Jul 2018
    8.8
    High

    CVE-2018-7768

    Last Modified: 21 Nov 2024

    The vulnerability exists within processing of loadtemplate.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the tpl input parameter.

    Published: 3 Jul 2018
    8.8
    High

    CVE-2018-7769

    Last Modified: 21 Nov 2024

    The vulnerability exists within processing of xmlserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input parameter.

    Published: 3 Jul 2018
    6.5
    Medium

    CVE-2018-7770

    Last Modified: 21 Nov 2024

    The vulnerability exists within processing of sendmail.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The applet allows callers to select arbitrary files to send to an arbitrary email address.

    Published: 3 Jul 2018
    8.8
    High

    CVE-2018-7772

    Last Modified: 21 Nov 2024

    The vulnerability exists within processing of applets which are exposed on the web service in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query to determine whether a user is logged in is subject to SQL injection on the loginSeed parameter, which can be embedded in the HTTP cookie of the request.

    Published: 3 Jul 2018
    8.8
    High

    CVE-2018-7774

    Last Modified: 21 Nov 2024

    The vulnerability exists within processing of localize.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the username input parameter.

    Published: 3 Jul 2018
    Unknown

    CVE-2018-7775

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-9960. Reason: This candidate is a duplicate of CVE-2017-9960. Notes: All CVE users should reference CVE-2017-9960 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 3 Jul 2018
    4.3
    Medium

    CVE-2018-7776

    Last Modified: 21 Nov 2024

    The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. System information is returned to the attacker that contains sensitive data.

    Published: 3 Jul 2018