CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-10945

    Last Modified: 21 Nov 2024

    The mg_handle_cgi function in mongoose.c in Mongoose 6.11 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash, or NULL pointer dereference) via an HTTP request, related to the mbuf_insert function.

    Published: 19 Jun 2018
    8.8
    High

    CVE-2018-11116

    Last Modified: 21 Nov 2024

    OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authenticated users to call arbitrary methods (i.e., achieve ubus access over HTTP) that were only supposed to be accessible to a specific user, as demonstrated by the file, log, and service namespaces, potentially leading to remote Information Disclosure or Code Execution. NOTE: The developer disputes this as a vulnerability, indicating that rpcd functions appropriately

    Published: 19 Jun 2018
    5.5
    Medium

    CVE-2018-12096

    Last Modified: 21 Nov 2024

    The liblnk_data_string_get_utf8_string_size function in liblnk_data_string.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed this as described in libyal/liblnk issue 33 on GitHub

    Published: 19 Jun 2018
    8.8
    High

    CVE-2018-12293

    Last Modified: 21 Nov 2024

    The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer overflow, which could be abused by crafted HTML content.

    Published: 19 Jun 2018
    8.8
    High

    CVE-2018-12294

    Last Modified: 21 Nov 2024

    WebCore/platform/graphics/texmap/TextureMapperLayer.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.2, is vulnerable to a use after free for a WebCore::TextureMapperLayer object.

    Published: 19 Jun 2018
    7.8
    High

    CVE-2018-11526

    Last Modified: 21 Nov 2024

    The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.

    Published: 19 Jun 2018
    9.8
    Critical

    CVE-2018-6210

    Last Modified: 21 Nov 2024

    D-Link DIR-620 devices, with a certain Rostelekom variant of firmware 1.0.37, have a hardcoded rostel account, which makes it easier for remote attackers to obtain access via a TELNET session.

    Published: 19 Jun 2018
    9.8
    Critical

    CVE-2015-4043

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in ConnX ESP HR Management 4.4.0 allows remote attackers to execute arbitrary SQL commands via the ctl00$cphMainContent$txtUserName parameter to frmLogin.aspx.

    Published: 19 Jun 2018
    6.5
    Medium

    CVE-2018-11537

    Last Modified: 21 Nov 2024

    Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain.

    Published: 19 Jun 2018
    7.5
    High

    CVE-2018-8727

    Last Modified: 17 Aug 2026

    Path Traversal in Gateway in Mirasys DVMS Workstation 5.12.6 and earlier allows an attacker to traverse the file system to access files or directories via the Web Client webserver.

    Published: 19 Jun 2018
    7.8
    High

    CVE-2018-11525

    Last Modified: 21 Nov 2024

    The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.

    Published: 19 Jun 2018
    8.8
    High

    CVE-2018-12582

    Last Modified: 21 Nov 2024

    An issue was discovered in AKCMS 6.1. CSRF can add an admin account via a /index.php?file=account&action=manageaccounts&job=newaccount URI.

    Published: 19 Jun 2018
    6.5
    Medium

    CVE-2018-12583

    Last Modified: 21 Nov 2024

    An issue was discovered in AKCMS 6.1. CSRF can delete an article via an admincp deleteitem action to index.php.

    Published: 19 Jun 2018
    6.1
    Medium

    CVE-2018-12580

    Last Modified: 21 Nov 2024

    library/DBTech/Security/Action/Sessions.php in DragonByte vBSecurity 3.x through 3.3.0 for vBulletin 3 and vBulletin 4 allows self-XSS via $session['user_agent'] in the "Login Sessions" feature.

    Published: 19 Jun 2018
    9.8
    Critical

    CVE-2018-12578

    Last Modified: 21 Nov 2024

    There is a heap-based buffer overflow in bmp_compress1_row in appliers.cpp in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact.

    Published: 19 Jun 2018
    7.8
    High

    CVE-2018-11701

    Last Modified: 21 Nov 2024

    FastStone Image Viewer 6.2 has a User Mode Write AV at 0x005cb509, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

    Published: 19 Jun 2018
    7.8
    High

    CVE-2018-11702

    Last Modified: 21 Nov 2024

    FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00578cb3, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

    Published: 19 Jun 2018
    7.8
    High

    CVE-2018-11705

    Last Modified: 21 Nov 2024

    FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00578cc4, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

    Published: 19 Jun 2018
    7.8
    High

    CVE-2018-11706

    Last Modified: 21 Nov 2024

    FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00578dd8, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

    Published: 19 Jun 2018
    7.8
    High

    CVE-2018-11707

    Last Modified: 21 Nov 2024

    FastStone Image Viewer 6.2 has a User Mode Read and Execute AV at 0x0057898e, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

    Published: 19 Jun 2018
    7.5
    High

    CVE-2018-8030

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than allowed maximum message size limit (100MB by default). The broker crashes due to the defect. AMQP protocols 0-10 and 1.0 are not affected.

    Published: 19 Jun 2018
    7.8
    High

    CVE-2018-11703

    Last Modified: 21 Nov 2024

    FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00402d6a, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

    Published: 19 Jun 2018
    7.8
    High

    CVE-2018-11704

    Last Modified: 21 Nov 2024

    FastStone Image Viewer 6.2 has a User Mode Write AV at 0x00402d7d, triggered when the user opens a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

    Published: 19 Jun 2018
    8.8
    High

    CVE-2018-12559

    Last Modified: 21 Nov 2024

    An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The mount target path check in mounter.cpp `mpOk()` is insufficient. A regular user can consequently mount a CIFS filesystem anywhere (e.g., outside of the /home directory tree) by passing directory traversal sequences such as a home/../usr substring.

    Published: 19 Jun 2018
    6.5
    Medium

    CVE-2018-12560

    Last Modified: 21 Nov 2024

    An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. Arbitrary unmounts can be performed by regular users via directory traversal sequences such as a home/../sys/kernel substring.

    Published: 19 Jun 2018
    8.8
    High

    CVE-2018-12561

    Last Modified: 21 Nov 2024

    An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. A regular user can inject additional mount options such as file_mode= by manipulating (for example) the domain parameter of the samba URL.

    Published: 19 Jun 2018
    6.5
    Medium

    CVE-2018-12564

    Last Modified: 21 Nov 2024

    An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and valid yaml.

    Published: 19 Jun 2018
    8.8
    High

    CVE-2018-12565

    Last Modified: 21 Nov 2024

    An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote code execution can occur.

    Published: 19 Jun 2018
    9.8
    Critical

    CVE-2018-12562

    Last Modified: 21 Nov 2024

    An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wrapper' uses the shell to forward the arguments to the actual mount.cifs binary. The shell evaluates wildcards (such as in an injected string:/home/../tmp/* string).

    Published: 19 Jun 2018
    9.8
    Critical

    CVE-2018-12557

    Last Modified: 21 Nov 2024

    An issue was discovered in Zuul 3.x before 3.1.0. If nodes become offline during the build, the no_log attribute of a task is ignored. If the unreachable error occurred in a task used with a loop variable (e.g., with_items), the contents of the loop items would be printed in the console. This could lead to accidentally leaking credentials or secrets.

    Published: 19 Jun 2018
    6.5
    Medium

    CVE-2018-12563

    Last Modified: 21 Nov 2024

    An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to download any file from the filesystem if it's readable by lavaserver and valid yaml.

    Published: 19 Jun 2018
    8.8
    High

    CVE-2018-12599

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.8-3 Q16, ReadBMPImage and WriteBMPImage in coders/bmp.c allow attackers to cause an out of bounds write via a crafted file.

    Published: 19 Jun 2018
    8.8
    High

    CVE-2018-12600

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.c allow attackers to cause an out of bounds write via a crafted file.

    Published: 19 Jun 2018
    7.5
    High

    CVE-2018-12558

    Last Modified: 21 Nov 2024

    The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30 form-field characters ("\f").

    Published: 19 Jun 2018
    9.8
    Critical

    CVE-2018-10623

    Last Modified: 21 Nov 2024

    Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior performs read operations on a memory buffer where the position can be determined by a value read from a .dpa file. This may cause improper restriction of operations within the bounds of the memory buffer, allow remote code execution, alter the intended control flow, allow reading of sensitive information, or cause the application to crash.

    Published: 18 Jun 2018
    9.8
    Critical

    CVE-2018-10617

    Last Modified: 21 Nov 2024

    Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length heap buffer where a value larger than the buffer can be read from a .dpa file into the buffer, causing the buffer to be overwritten. This may allow remote code execution or cause the application to crash.

    Published: 18 Jun 2018
    9.8
    Critical

    CVE-2018-10621

    Last Modified: 21 Nov 2024

    Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length stack buffer where a value larger than the buffer can be read from a .dpa file into the buffer, causing the buffer to be overwritten. This may allow remote code execution or cause the application to crash.

    Published: 18 Jun 2018
    9.8
    Critical

    CVE-2018-9021

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests.

    Published: 18 Jun 2018
    9.8
    Critical

    CVE-2018-9022

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file.

    Published: 18 Jun 2018
    8.8
    High

    CVE-2018-9023

    Last Modified: 21 Nov 2024

    An input validation vulnerability in CA Privileged Access Manager 2.x allows unprivileged users to execute arbitrary commands by passing specially crafted arguments to the update_crld script.

    Published: 18 Jun 2018
    5.3
    Medium

    CVE-2018-9024

    Last Modified: 21 Nov 2024

    An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a log file.

    Published: 18 Jun 2018
    7.5
    High

    CVE-2018-9025

    Last Modified: 21 Nov 2024

    An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with specially crafted input.

    Published: 18 Jun 2018
    7.5
    High

    CVE-2018-9028

    Last Modified: 21 Nov 2024

    Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking.

    Published: 18 Jun 2018
    9.8
    Critical

    CVE-2018-9029

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to conduct SQL injection attacks.

    Published: 18 Jun 2018
    9.8
    Critical

    CVE-2015-4664

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.

    Published: 18 Jun 2018
    7.5
    High

    CVE-2018-9026

    Last Modified: 21 Nov 2024

    A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions with a specially crafted request.

    Published: 18 Jun 2018
    7.5
    High

    CVE-2018-1333

    Last Modified: 21 Nov 2024

    By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).

    Published: 18 Jun 2018
    6.1
    Medium

    CVE-2018-9027

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a specially crafted link.

    Published: 18 Jun 2018
    6.5
    Medium

    CVE-2018-12530

    Last Modified: 21 Nov 2024

    An issue was discovered in MetInfo 6.0.0. admin/app/batch/csvup.php allows remote attackers to delete arbitrary files via a flienamecsv=../ directory traversal. This can be exploited via CSRF.

    Published: 18 Jun 2018
    9.8
    Critical

    CVE-2018-12531

    Last Modified: 21 Nov 2024

    An issue was discovered in MetInfo 6.0.0. install\index.php allows remote attackers to write arbitrary PHP code into config_db.php, a different vulnerability than CVE-2018-7271.

    Published: 18 Jun 2018