CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-14438

    Last Modified: 21 Nov 2024

    In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which allows attackers to modify the access control arbitrarily.

    Published: 28 Jun 2018
    6.5
    Medium

    CVE-2018-12891

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.10.x. Certain PV MMU operations may take a long time to process. For that reason Xen explicitly checks for the need to preempt the current vCPU at certain points. A few rarely taken code paths did bypass such checks. By suitably enforcing the conditions through its own page table contents, a malicious guest may cause such bypasses to be used for an unbounded number of iterations. A malicious or buggy PV guest may cause a Denial of Service (DoS) affecting the entire host. Specifically, it may prevent use of a physical CPU for an indeterminate period of time. All Xen versions from 3.4 onwards are vulnerable. Xen versions 3.3 and earlier are vulnerable to an even wider class of attacks, due to them lacking preemption checks altogether in the affected code paths. Only x86 systems are affected. ARM systems are not affected. Only multi-vCPU x86 PV guests can leverage the vulnerability. x86 HVM or PVH guests as well as x86 single-vCPU PV ones cannot leverage the vulnerability.

    Published: 27 Jun 2018
    6.5
    Medium

    CVE-2018-12893

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.10.x. One of the fixes in XSA-260 added some safety checks to help prevent Xen livelocking with debug exceptions. Unfortunately, due to an oversight, at least one of these safety checks can be triggered by a guest. A malicious PV guest can crash Xen, leading to a Denial of Service. All Xen systems which have applied the XSA-260 fix are vulnerable. Only x86 systems are vulnerable. ARM systems are not vulnerable. Only x86 PV guests can exploit the vulnerability. x86 HVM and PVH guests cannot exploit the vulnerability. An attacker needs to be able to control hardware debugging facilities to exploit the vulnerability, but such permissions are typically available to unprivileged users.

    Published: 27 Jun 2018
    7.5
    High

    CVE-2018-5527

    Last Modified: 21 Nov 2024

    On BIG-IP 13.1.0-13.1.0.7, a remote attacker using undisclosed methods against virtual servers configured with a Client SSL or Server SSL profile that has the SSL Forward Proxy feature enabled can force the Traffic Management Microkernel (tmm) to leak memory. As a result, system memory usage increases over time, which may eventually cause a decrease in performance or a system reboot due to memory exhaustion.

    Published: 27 Jun 2018
    6.5
    Medium

    CVE-2018-1354

    Last Modified: 21 Nov 2024

    An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avatar picture of other users with arbitrary content.

    Published: 27 Jun 2018
    6.1
    Medium

    CVE-2018-1355

    Last Modified: 21 Nov 2024

    An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user into generating a PDF file containing injected malicious URLs.

    Published: 27 Jun 2018
    5.3
    Medium

    CVE-2018-5528

    Last Modified: 21 Nov 2024

    Under certain conditions, TMM may restart and produce a core file while processing APM data on BIG-IP 13.0.1 or 13.1.0.4-13.1.0.7.

    Published: 27 Jun 2018
    5.9
    Medium

    CVE-2017-16718

    Last Modified: 21 Nov 2024

    Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be edited remotely via ADS. This special command supports encrypted authentication with username/password. The encryption uses a fixed key, that could be extracted by an attacker. Precondition of the exploitation of this weakness is network access at the moment a route is added.

    Published: 27 Jun 2018
    9.1
    Critical

    CVE-2017-16726

    Last Modified: 21 Nov 2024

    Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to achieve security purposes and therefore does not include any encryption algorithms because of their negative effect on performance and throughput. An attacker can forge arbitrary ADS packets when legitimate ADS traffic is observable.

    Published: 27 Jun 2018
    7.2
    High

    CVE-2018-12912

    Last Modified: 21 Nov 2024

    An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via an admin/index.php/database/operate?dbaction=emptytable&tablename= URI.

    Published: 27 Jun 2018
    7.5
    High

    CVE-2018-12913

    Last Modified: 21 Nov 2024

    In Miniz 2.0.7, tinfl_decompress in miniz_tinfl.c has an infinite loop because sym2 and counter can both remain equal to zero.

    Published: 27 Jun 2018
    9.8
    Critical

    CVE-2018-12914

    Last Modified: 21 Nov 2024

    A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a directory traversal pathname. After an unzip operation, the attacker can execute arbitrary code by visiting a .jsp URI.

    Published: 27 Jun 2018
    9.8
    Critical

    CVE-2018-12915

    Last Modified: 21 Nov 2024

    In libpbc.a in PBC through 2017-03-02, there is a buffer over-read in calc_hash in map.c.

    Published: 27 Jun 2018
    9.8
    Critical

    CVE-2018-12917

    Last Modified: 21 Nov 2024

    In libpbc.a in PBC through 2017-03-02, there is a heap-based buffer over-read in _pbcM_ip_new in map.c.

    Published: 27 Jun 2018
    9.8
    Critical

    CVE-2018-12918

    Last Modified: 21 Nov 2024

    In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcB_register_fields in bootstrap.c.

    Published: 27 Jun 2018
    6.1
    Medium

    CVE-2018-12919

    Last Modified: 21 Nov 2024

    In CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter.

    Published: 27 Jun 2018
    5.3
    Medium

    CVE-2018-1553

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server Liberty prior to 18.0.0.2 could allow a remote attacker to obtain sensitive information, caused by mishandling of exceptions by the SAML Web SSO feature. IBM X-Force ID: 142890.

    Published: 27 Jun 2018
    9.8
    Critical

    CVE-2018-12916

    Last Modified: 21 Nov 2024

    In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcP_message_default in proto.c.

    Published: 27 Jun 2018
    7.5
    High

    CVE-2018-1306

    Last Modified: 21 Nov 2024

    The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload. An attacker could exploit this vulnerability to obtain configuration data and other sensitive information.

    Published: 27 Jun 2018
    9.8
    Critical

    CVE-2018-1457

    Last Modified: 5 Feb 2025

    An undisclosed vulnerability in IBM Rational DOORS 9.5.1 through 9.6.1.10 application allows an attacker to gain DOORS administrator privileges. IBM X-Force ID: 140208.

    Published: 27 Jun 2018
    5.9
    Medium

    CVE-2018-1543

    Last Modified: 21 Nov 2024

    IBM WebSphere MQ 8.0 and 9.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL certificate. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 142598.

    Published: 27 Jun 2018
    5.4
    Medium

    CVE-2018-1507

    Last Modified: 21 Nov 2024

    IBM DOORS Next Generation (DNG/RRC) 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 141415.

    Published: 27 Jun 2018
    7.5
    High

    CVE-2018-12909

    Last Modified: 21 Nov 2024

    Webgrind 1.5 relies on user input to display a file, which lets anyone view files from the local filesystem (that the webserver user has access to) via an index.php?op=fileviewer&file= URI. NOTE: the vendor indicates that the product is not intended for a "publicly accessible environment.

    Published: 27 Jun 2018
    6.5
    Medium

    CVE-2018-5436

    Last Modified: 21 Nov 2024

    The Spotfire server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contain multiple vulnerabilities that may allow for the disclosure of information, including user and data source credentials. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 7.12.0, TIBCO Spotfire Server: versions up to and including 7.8.1; 7.9.0; 7.10.0; 7.11.0; 7.12.0.

    Published: 27 Jun 2018
    9.6
    Critical

    CVE-2018-5435

    Last Modified: 21 Nov 2024

    The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contain multiple vulnerabilities that may allow for remote code execution. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0; 7.12.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 7.12.0, TIBCO Spotfire Deployment Kit: versions up to and including 7.8.0; 7.9.0;7.9.1;7.10.0;7.10.1;7.11.0; 7.12.0, TIBCO Spotfire Desktop: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0;7.12.0, TIBCO Spotfire Desktop Language Packs: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0.

    Published: 27 Jun 2018
    6.8
    Medium

    CVE-2018-5437

    Last Modified: 21 Nov 2024

    The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contain multiple vulnerabilities that may allow for unauthorized information disclosure. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0; 7.12.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 7.12.0, TIBCO Spotfire Deployment Kit: versions up to and including 7.8.0; 7.9.0;7.9.1;7.10.0;7.10.1;7.11.0; 7.12.0, TIBCO Spotfire Desktop: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0;7.12.0, TIBCO Spotfire Desktop Language Packs: versions up to and including 7.8.0; 7.9.0; 7.9.1; 7.10.0; 7.10.1; 7.11.0.

    Published: 27 Jun 2018
    9.8
    Critical

    CVE-2018-12908

    Last Modified: 21 Nov 2024

    Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for the /dashboard/deposit URI, as demonstrated by discovering database credentials.

    Published: 27 Jun 2018
    6.1
    Medium

    CVE-2018-12905

    Last Modified: 21 Nov 2024

    joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions.

    Published: 27 Jun 2018
    7.5
    High

    CVE-2018-12907

    Last Modified: 21 Nov 2024

    In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of any URL's content to Google, because there is no validation of a URL field received from the Google Cloud Storage API server, aka a "RESTLESS" issue.

    Published: 27 Jun 2018
    9.9
    Critical

    CVE-2018-12892

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probably an erroneous merge conflict resolution. Malicious guest administrators or (in some situations) users may be able to write to supposedly read-only disk images. Only emulated SCSI disks (specified as "sd" in the libxl disk configuration, or an equivalent) are affected. IDE disks ("hd") are not affected (because attempts to make them readonly are rejected). Additionally, CDROM devices (that is, devices specified to be presented to the guest as CDROMs, regardless of the nature of the backing storage on the host) are not affected; they are always read only. Only systems using qemu-xen (rather than qemu-xen-traditional) as the device model version are vulnerable. Only systems using libxl or libxl-based toolstacks are vulnerable. (This includes xl, and libvirt with the libxl driver.) The vulnerability is present in Xen versions 4.7 and later. (In earlier versions, provided that the patch for XSA-142 has been applied, attempts to create read only disks are rejected.) If the host and guest together usually support PVHVM, the issue is exploitable only if the malicious guest administrator has control of the guest kernel or guest kernel command line.

    Published: 27 Jun 2018
    3.3
    Low

    CVE-2018-13053

    Last Modified: 21 Nov 2024

    The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has an integer overflow via a large relative timeout because ktime_add_safe is not used.

    Published: 27 Jun 2018
    9.8
    Critical

    CVE-2017-18342

    Last Modified: 21 Nov 2024

    In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the function.

    Published: 27 Jun 2018
    5.3
    Medium

    CVE-2018-12536

    Last Modified: 21 Nov 2024

    In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a java.nio.file.InvalidPathException which includes the full path to the base resource directory that the DefaultServlet and/or webapp is using. If this InvalidPathException is then handled by the default Error Handler, the InvalidPathException message is included in the error response, revealing the full server path to the requesting system.

    Published: 27 Jun 2018
    5.5
    Medium

    CVE-2018-14617

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference and panic in hfsplus_lookup() in fs/hfsplus/dir.c when opening a file (that is purportedly a hard link) in an hfs+ filesystem that has malformed catalog data, and is mounted read-only without a metadata directory.

    Published: 27 Jun 2018
    5.4
    Medium

    CVE-2018-12903

    Last Modified: 21 Nov 2024

    In CyberArk Endpoint Privilege Manager (formerly Viewfinity) 10.2.1.603, there is persistent XSS via an account name on the create token screen, the VfManager.asmx SelectAccounts->DisplayName screen, a user's groups in ConfigurationPage, the Dialog Title field, and App Group Name in the Application Group Wizard.

    Published: 26 Jun 2018
    6.5
    Medium

    CVE-2018-11053

    Last Modified: 21 Nov 2024

    Dell EMC iDRAC Service Module for all supported Linux and XenServer versions v3.0.1, v3.0.2, v3.1.0, v3.2.0, when started, changes the default file permission of the hosts file of the host operating system (/etc/hosts) to world writable. A malicious low privileged operating system user or process could modify the host file and potentially redirect traffic from the intended destination to sites hosting malicious or unwanted content.

    Published: 26 Jun 2018
    6.1
    Medium

    CVE-2018-12902

    Last Modified: 21 Nov 2024

    In Easy Magazine through 2012-10-26, there is XSS in the search bar of the web site.

    Published: 26 Jun 2018
    7.5
    High

    CVE-2018-3840

    Last Modified: 21 Nov 2024

    A denial-of-service vulnerability exists in the Pixar Renderman IT Display Service 21.6 (0x67). The vulnerability is present in the parsing of a network packet without proper validation of the packet. The data read by the application is not validated, and its use can lead to a null pointer dereference. The IT application is opened by a user and then listens for a connection on port 4001. An attacker can deliver an attack once the application has been opened.

    Published: 26 Jun 2018
    7.5
    High

    CVE-2018-3841

    Last Modified: 21 Nov 2024

    A denial-of-service vulnerability exists in the Pixar Renderman IT Display Service 21.6 (0x69). The vulnerability is present in the parsing of a network packet without proper validation of the packet. The data read-in is not validated, and its use can lead to a null pointer dereference. The IT application is opened by a user and then listens for a connection on port 4001. An attacker can deliver an attack once the application has been opened.

    Published: 26 Jun 2018
    5.8
    Medium

    CVE-2018-1614

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 using malformed SAML responses from the SAML identity provider could allow a remote attacker to obtain sensitive information. IBM X-Force ID: 144270.

    Published: 26 Jun 2018
    8.8
    High

    CVE-2018-12895

    Last Modified: 21 Nov 2024

    WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in the wp-includes/post.php wp_delete_attachment function. The attacker must have capabilities for files and posts that are normally available only to the Author, Editor, and Administrator roles. The attack methodology is to delete wp-config.php and then launch a new installation process to increase the attacker's privileges.

    Published: 26 Jun 2018
    5.3
    Medium

    CVE-2018-1374

    Last Modified: 21 Nov 2024

    An IBM WebSphere MQ (Maintenance levels 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.8, 8.0.0.0 - 8.0.0.8, 9.0.0.0 - 9.0.0.2, and 9.0.0 - 9.0.4) client connecting to a Queue Manager could cause a SIGSEGV in the Channel process amqrmppa. IBM X-Force ID: 137775.

    Published: 26 Jun 2018
    9.8
    Critical

    CVE-2018-10594

    Last Modified: 21 Nov 2024

    Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS2 and AHSIM_5x0, AHSIM_5x1) utilize a fixed-length stack buffer where an unverified length value can be read from the network packets via a specific network port, causing the buffer to be overwritten. This may allow remote code execution, cause the application to crash, or result in a denial-of-service condition in the application server.

    Published: 26 Jun 2018
    8.8
    High

    CVE-2018-12712

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, using the "class_exists" function in PHP. In PHP 5.3, this function validates invalid names as valid, which can result in a Local File Inclusion.

    Published: 26 Jun 2018
    6.1
    Medium

    CVE-2018-12711

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3.8.9. In some cases, the link of the current language might contain unescaped HTML special characters. This may lead to reflective XSS via injection of arbitrary parameters and/or values on the current page URL.

    Published: 26 Jun 2018
    7.5
    High

    CVE-2018-10659

    Last Modified: 21 Nov 2024

    There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that calls the UND undefined ARM instruction.

    Published: 26 Jun 2018
    9.8
    Critical

    CVE-2018-10660

    Last Modified: 21 Nov 2024

    An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.

    Published: 26 Jun 2018
    9.8
    Critical

    CVE-2018-10661

    Last Modified: 21 Nov 2024

    An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.

    Published: 26 Jun 2018
    9.8
    Critical

    CVE-2018-10662

    Last Modified: 21 Nov 2024

    An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.

    Published: 26 Jun 2018
    7.5
    High

    CVE-2018-10663

    Last Modified: 21 Nov 2024

    An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation.

    Published: 26 Jun 2018