CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-7780

    Last Modified: 21 Nov 2024

    In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, a buffer overflow vulnerability exist in cgi program "set".

    Published: 3 Jul 2018
    8.8
    High

    CVE-2018-7781

    Last Modified: 21 Nov 2024

    In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, by sending a specially crafted request an authenticated user can view password in clear text and results in privilege escalation.

    Published: 3 Jul 2018
    8.8
    High

    CVE-2018-7782

    Last Modified: 21 Nov 2024

    In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authenticated users can view passwords in clear text.

    Published: 3 Jul 2018
    9.8
    Critical

    CVE-2018-7778

    Last Modified: 21 Nov 2024

    In Schneider Electric Evlink Charging Station versions prior to v3.2.0-12_v1, the Web Interface has an issue that may allow a remote attacker to gain administrative privileges without properly authenticating remote users.

    Published: 3 Jul 2018
    7.5
    High

    CVE-2018-7783

    Last Modified: 21 Nov 2024

    Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the DTD parameter entities technique resulting in disclosure and retrieval of arbitrary data on the affected node via out-of-band (OOB) attack. The vulnerability is triggered when input passed to the xml parser is not sanitized while parsing the xml project/template file.

    Published: 3 Jul 2018
    9.8
    Critical

    CVE-2018-7784

    Last Modified: 21 Nov 2024

    In Schneider Electric U.motion Builder software versions prior to v1.3.4, this exploit occurs when the submitted data of an input string is evaluated as a command by the application. In this way, the attacker could execute code, read the stack, or cause a segmentation fault in the running application.

    Published: 3 Jul 2018
    6.1
    Medium

    CVE-2018-7786

    Last Modified: 21 Nov 2024

    In Schneider Electric U.motion Builder software versions prior to v1.3.4, a cross site scripting (XSS) vulnerability exists which could allow injection of malicious scripts.

    Published: 3 Jul 2018
    5.3
    Medium

    CVE-2018-7787

    Last Modified: 21 Nov 2024

    In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parameter in HTTP GET request.

    Published: 3 Jul 2018
    4.9
    Medium

    CVE-2018-4856

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with administrative access to the device's management interface could lock out legitimate users. Manual interaction is required to restore the access of legitimate users.

    Published: 3 Jul 2018
    8
    High

    CVE-2018-7771

    Last Modified: 21 Nov 2024

    The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A directory traversal vulnerability allows a caller with standard user privileges to write arbitrary php files anywhere in the web service directory tree.

    Published: 3 Jul 2018
    8.8
    High

    CVE-2018-7773

    Last Modified: 21 Nov 2024

    The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the sessionid input parameter.

    Published: 3 Jul 2018
    7.5
    High

    CVE-2018-7779

    Last Modified: 21 Nov 2024

    In Schneider Electric Wiser for KNX V2.1.0 and prior, homeLYnk V2.0.1 and prior; and spaceLYnk V2.1.0 and prior, weak and unprotected FTP access could allow an attacker unauthorized access.

    Published: 3 Jul 2018
    9.8
    Critical

    CVE-2018-7785

    Last Modified: 21 Nov 2024

    In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass.

    Published: 3 Jul 2018
    8.2
    High

    CVE-2018-4851

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device could cause a Denial-of-Service condition by sending certain packets to the device, causing potential reboots of the device. The core functionality of the device could be impacted. The time serving functionality recovers when time synchronization with GPS devices or other NTP servers are completed.

    Published: 3 Jul 2018
    9.8
    Critical

    CVE-2018-4853

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp could modify the firmware of the device.

    Published: 3 Jul 2018
    6.5
    Medium

    CVE-2018-4855

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). Unencrypted storage of passwords in the client configuration files and during network transmission could allow an attacker in a privileged position to obtain access passwords.

    Published: 3 Jul 2018
    8.8
    High

    CVE-2018-7777

    Last Modified: 21 Nov 2024

    The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A remote, authenticated attacker can exploit this vulnerability by sending a crafted request to the target server.

    Published: 3 Jul 2018
    8.6
    High

    CVE-2018-11746

    Last Modified: 21 Nov 2024

    In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure channels if a HTTPS server is not available. This can expose the login credentials being used by Puppet Discovery.

    Published: 3 Jul 2018
    6.1
    Medium

    CVE-2018-12255

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field.

    Published: 3 Jul 2018
    9.8
    Critical

    CVE-2018-13101

    Last Modified: 21 Nov 2024

    KioskSimpleService.exe in RedSwimmer KioskSimple 1.4.7.0 suffers from a privilege escalation vulnerability in the WCF endpoint. The exposed methods allow read and write access to the Windows registry and control of services. These methods may be abused to achieve privilege escalation via execution of attacker controlled binaries.

    Published: 3 Jul 2018
    6.1
    Medium

    CVE-2018-13065

    Last Modified: 3 Jul 2025

    ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this issue because it may only apply to environments without a Core Rule Set configured

    Published: 3 Jul 2018
    9.8
    Critical

    CVE-2018-12910

    Last Modified: 21 Nov 2024

    The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.

    Published: 3 Jul 2018
    9.6
    Critical

    CVE-2018-11314

    Last Modified: 21 Nov 2024

    The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result in remote device control and privileged device and network information to be exfiltrated by an attacker.

    Published: 3 Jul 2018
    7.5
    High

    CVE-2018-13113

    Last Modified: 21 Nov 2024

    The transfer and transferFrom functions of a smart contract implementation for Easy Trading Token (ETT), an Ethereum token, have an integer overflow. NOTE: this has been disputed by a third party.

    Published: 3 Jul 2018
    8.8
    High

    CVE-2018-13139

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file. The vulnerability can be triggered by the executable sndfile-deinterleave.

    Published: 3 Jul 2018
    9.8
    Critical

    CVE-2018-14939

    Last Modified: 21 Nov 2024

    The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in certain environments such as FreeBSD libc, which might allow attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact if LibreOffice is automatically launched during web browsing with pathnames controlled by a remote web site.

    Published: 3 Jul 2018
    7.5
    High

    CVE-2018-13068

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for AzurionToken (AZU), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13069

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for DYchain (DYC), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13073

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for ETHEREUMBLACK (ETCBK), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13074

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for FIBToken (FIB), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13075

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Carbon Exchange Coin Token (CEC), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13076

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Betcash (BC), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13077

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for CTB, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13078

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Jitech (JTH), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13080

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Goutex (GTX), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13082

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for MODI Token (MODI), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13084

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Good Time Coin (GTY), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13088

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Futures Pease (FP), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13089

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Universal Coin (UCOIN), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13090

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for YiTongCoin (YTC), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13091

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for sumocoin (SUMO), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13070

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for EncryptedToken (ECC), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13071

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for CCindex10 (T10), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13081

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for GZS Token (GZS), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13083

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Plaza Token (PLAZA), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13085

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for FreeCoin (FREE), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13087

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Coinstar (CSTR), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13092

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Reimburse Token (REIM), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13079

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for GoodTo (GTO), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018
    7.5
    High

    CVE-2018-13086

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for IADOWR Coin (IAD), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 2 Jul 2018