CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-12080

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap" issue.

    Published: 25 Jun 2018
    7.5
    High

    CVE-2018-12081

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Target Coin (TGT), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap" issue.

    Published: 25 Jun 2018
    7.5
    High

    CVE-2018-12082

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for Fujinto (NTO), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap" issue.

    Published: 25 Jun 2018
    7.5
    High

    CVE-2018-12083

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for GOAL Bonanza (GOAL), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap" issue.

    Published: 25 Jun 2018
    7.5
    High

    CVE-2018-12063

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable variable sellPrice, aka the "tradeTrap" issue.

    Published: 25 Jun 2018
    7.5
    High

    CVE-2018-12068

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for Target Coin (TGT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable variable sellPrice, aka the "tradeTrap" issue.

    Published: 25 Jun 2018
    7.5
    High

    CVE-2018-12084

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for BitAsean (BAS), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap" issue.

    Published: 25 Jun 2018
    7.5
    High

    CVE-2018-11446

    Last Modified: 21 Nov 2024

    The buy function of a smart contract implementation for Gold Reward (GRX), an Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the buyer because of overflow of the multiplication of its argument amount and a manipulable variable buyPrice, aka the "tradeTrap" issue.

    Published: 25 Jun 2018
    7.5
    High

    CVE-2018-12062

    Last Modified: 21 Nov 2024

    The sell function of a smart contract implementation for SwftCoin (SWFTC), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable variable sellPrice, aka the "tradeTrap" issue.

    Published: 25 Jun 2018
    7.5
    High

    CVE-2018-12078

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for PolyAI (AI), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap" issue.

    Published: 25 Jun 2018
    7.5
    High

    CVE-2018-12702

    Last Modified: 21 Nov 2024

    The approveAndCallcode function of a smart contract implementation for Globalvillage ecosystem (GVE), an Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer the contract's balances into their account) because the callcode (i.e., _spender.call(_extraData)) is not verified, aka the "evilReflex" issue. NOTE: a PeckShield disclosure states "some researchers have independently discussed the mechanism of such vulnerability."

    Published: 25 Jun 2018
    7.5
    High

    CVE-2018-12703

    Last Modified: 21 Nov 2024

    The approveAndCallcode function of a smart contract implementation for Block 18 (18T), an tradable Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer the contract's balances into their account) because the callcode (i.e., _spender.call(_extraData)) is not verified, aka the "evilReflex" issue. NOTE: a PeckShield disclosure states "some researchers have independently discussed the mechanism of such vulnerability."

    Published: 25 Jun 2018
    Unknown

    CVE-2018-10848

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-12532. Reason: This candidate is a reservation duplicate of CVE-2018-12532. Notes: All CVE users should reference CVE-2018-12532 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 Jun 2018
    Unknown

    CVE-2018-10849

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-12533. Reason: This candidate is a reservation duplicate of CVE-2018-12533. Notes: All CVE users should reference CVE-2018-12533 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 Jun 2018
    4.3
    Medium

    CVE-2018-12716

    Last Modified: 21 Nov 2024

    The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine the physical location of most web browsers by leveraging the presence of one of these devices on its local network, extracting the scan_results bssid fields, and sending these fields in a geolocation/v1/geolocate Google Maps Geolocation API request.

    Published: 25 Jun 2018
    8.8
    High

    CVE-2018-1000600

    Last Modified: 21 Nov 2024

    A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 25 Jun 2018
    7.6
    High

    CVE-2018-10893

    Last Modified: 21 Nov 2024

    Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.

    Published: 25 Jun 2018
    5.9
    Medium

    CVE-2018-25008

    Last Modified: 21 Nov 2024

    In the standard library in Rust before 1.29.0, there is weak synchronization in the Arc::get_mut method. This synchronization issue can be lead to memory safety issues through race conditions.

    Published: 25 Jun 2018
    7.8
    High

    CVE-2018-11987

    Last Modified: 21 Nov 2024

    In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, if there is an unlikely memory alloc failure for the secure pool in boot, it can result in wrong pointer access causing kernel panic.

    Published: 25 Jun 2018
    6.5
    Medium

    CVE-2018-1000601

    Last Modified: 21 Nov 2024

    A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and earlier in BasicSSHUserPrivateKey.java that allows attackers with a Jenkins account and the permission to configure credential bindings to read arbitrary files from the Jenkins master file system.

    Published: 25 Jun 2018
    6.1
    Medium

    CVE-2018-12705

    Last Modified: 21 Nov 2024

    DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).

    Published: 24 Jun 2018
    9.8
    Critical

    CVE-2018-12706

    Last Modified: 21 Nov 2024

    DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.

    Published: 24 Jun 2018
    9.8
    Critical

    CVE-2018-21029

    Last Modified: 21 Nov 2024

    systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability since hostname validation does not have anything to do with this issue (i.e. there is no hostname to be sent)

    Published: 24 Jun 2018
    9.8
    Critical

    CVE-2018-11560

    Last Modified: 21 Nov 2024

    The webService binary on Insteon HD IP Camera White 2864-222 devices has a stack-based Buffer Overflow leading to Control-Flow Hijacking via a crafted usr key, as demonstrated by a long remoteIp parameter to cgi-bin/CGIProxy.fcgi on port 34100.

    Published: 23 Jun 2018
    9.8
    Critical

    CVE-2018-12640

    Last Modified: 21 Nov 2024

    The webService binary on Insteon HD IP Camera White 2864-222 devices has a Buffer Overflow via a crafted pid, pwd, or usr key in a GET request on port 34100.

    Published: 23 Jun 2018
    8.8
    High

    CVE-2018-12692

    Last Modified: 21 Nov 2024

    TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the wps_setup_pin parameter to /data/wps.setup.json.

    Published: 23 Jun 2018
    6.5
    Medium

    CVE-2018-12693

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow in TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to cause a denial of service (outage) via a long type parameter to /data/syslog.filter.json.

    Published: 23 Jun 2018
    6.1
    Medium

    CVE-2018-12696

    Last Modified: 21 Nov 2024

    mao10cms 6 allows XSS via the article page.

    Published: 23 Jun 2018
    7.5
    High

    CVE-2018-12694

    Last Modified: 21 Nov 2024

    TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote attackers to cause a denial of service (reboot) via data/reboot.json.

    Published: 23 Jun 2018
    6.1
    Medium

    CVE-2018-12695

    Last Modified: 21 Nov 2024

    mao10cms 6 allows XSS via the m=bbs&a=index page.

    Published: 23 Jun 2018
    9.8
    Critical

    CVE-2018-12714

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 4.17.2. The filter parsing in kernel/trace/trace_events_filter.c could be called with no filter, which is an N=0 case when it expected at least one line to have been read, thus making the N-1 index invalid. This allows attackers to cause a denial of service (slab out-of-bounds write) or possibly have unspecified other impact via crafted perf_event_open and mmap system calls.

    Published: 23 Jun 2018
    6.5
    Medium

    CVE-2018-7682

    Last Modified: 21 Nov 2024

    Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains.

    Published: 22 Jun 2018
    9.8
    Critical

    CVE-2018-12689

    Last Modified: 21 Nov 2024

    phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.

    Published: 22 Jun 2018
    9.8
    Critical

    CVE-2018-12688

    Last Modified: 21 Nov 2024

    tinyexr 0.9.5 has a segmentation fault in the wav2Decode function.

    Published: 22 Jun 2018
    7.5
    High

    CVE-2018-12687

    Last Modified: 21 Nov 2024

    tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h.

    Published: 22 Jun 2018
    9.8
    Critical

    CVE-2018-12678

    Last Modified: 21 Nov 2024

    Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocket/exec endpoint, which allows remote attackers to bypass intended access restrictions or conduct SSRF attacks.

    Published: 22 Jun 2018
    7.8
    High

    CVE-2018-1000201

    Last Modified: 21 Nov 2024

    ruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be hijacked on Windows OS, when a Symbol is used as DLL name instead of a String This vulnerability appears to have been fixed in v1.9.24 and later.

    Published: 22 Jun 2018
    7.2
    High

    CVE-2018-12636

    Last Modified: 21 Nov 2024

    The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.

    Published: 22 Jun 2018
    6.1
    Medium

    CVE-2018-12654

    Last Modified: 21 Nov 2024

    Reflected Cross-Site Scripting (XSS) exists in the Bibliography module in SLiMS 8 Akasia 8.3.1 via an admin/modules/bibliography/index.php?keywords= URI.

    Published: 22 Jun 2018
    6.1
    Medium

    CVE-2018-12655

    Last Modified: 21 Nov 2024

    Reflected Cross-Site Scripting (XSS) exists in the Circulation module in SLiMS 8 Akasia 8.3.1 via an admin/modules/circulation/loan_rules.php?keywords= URI, a related issue to CVE-2017-7242.

    Published: 22 Jun 2018
    6.1
    Medium

    CVE-2018-12656

    Last Modified: 21 Nov 2024

    Reflected Cross-Site Scripting (XSS) exists in the Membership module in SLiMS 8 Akasia 8.3.1 via an admin/modules/membership/index.php?keywords= URI.

    Published: 22 Jun 2018
    6.1
    Medium

    CVE-2018-12657

    Last Modified: 21 Nov 2024

    Reflected Cross-Site Scripting (XSS) exists in the Master File module in SLiMS 8 Akasia 8.3.1 via an admin/modules/master_file/rda_cmc.php?keywords= URI.

    Published: 22 Jun 2018
    6.1
    Medium

    CVE-2018-12658

    Last Modified: 21 Nov 2024

    Reflected Cross-Site Scripting (XSS) exists in the Stock Take module in SLiMS 8 Akasia 8.3.1 via an admin/modules/stock_take/index.php?keywords= URI.

    Published: 22 Jun 2018
    5.3
    Medium

    CVE-2017-7568

    Last Modified: 21 Nov 2024

    NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account information to authenticated users when the LDAP authentication configuration is tested via the user interface.

    Published: 22 Jun 2018
    8.8
    High

    CVE-2018-12659

    Last Modified: 21 Nov 2024

    SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting the csrf_token parameter.

    Published: 22 Jun 2018
    9.8
    Critical

    CVE-2018-12649

    Last Modified: 21 Nov 2024

    An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92. An adversary can bypass the brute-force protection by using a PUT HTTP method instead of a POST HTTP method in the login part, because this protection was only covering POST requests.

    Published: 22 Jun 2018
    4
    Medium

    CVE-2018-1655

    Last Modified: 21 Nov 2024

    IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory. IBM X-Force ID: 144748.

    Published: 22 Jun 2018
    Unknown

    CVE-2018-12430

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-12429. Reason: This candidate is a reservation duplicate of CVE-2018-12429. Notes: All CVE users should reference CVE-2018-12429 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 22 Jun 2018
    7.5
    High

    CVE-2018-12642

    Last Modified: 21 Nov 2024

    Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.

    Published: 22 Jun 2018
    5.4
    Medium

    CVE-2018-0618

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Jun 2018