CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-12498

    Last Modified: 21 Nov 2024

    spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php.

    Published: 15 Jun 2018
    9.8
    Critical

    CVE-2018-12491

    Last Modified: 21 Nov 2024

    PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploading a .php file within a .php.zip archive, a similar issue to CVE-2018-8944.

    Published: 15 Jun 2018
    6.5
    Medium

    CVE-2018-12493

    Last Modified: 21 Nov 2024

    An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsWebFile/list.html?path=../ URI.

    Published: 15 Jun 2018
    6.5
    Medium

    CVE-2018-12494

    Last Modified: 21 Nov 2024

    An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsTemplate/content.html?path=../ URI.

    Published: 15 Jun 2018
    7.5
    High

    CVE-2018-12492

    Last Modified: 21 Nov 2024

    PHPOK 4.9.032 has an arbitrary file deletion vulnerability in the delfile_f function in framework/admin/tpl_control.php.

    Published: 15 Jun 2018
    7.8
    High

    CVE-2018-12034

    Last Modified: 21 Nov 2024

    In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds read vulnerability in yr_execute_code in libyara/exec.c.

    Published: 15 Jun 2018
    7.8
    High

    CVE-2018-12035

    Last Modified: 21 Nov 2024

    In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds write vulnerability in yr_execute_code in libyara/exec.c.

    Published: 15 Jun 2018
    9.8
    Critical

    CVE-2018-12481

    Last Modified: 21 Nov 2024

    The Olive Tree Ftp Server application 1.32 for Android has a "Sensitive Data on the Clipboard" vulnerability, as demonstrated by reading the "User password" field with the Drozer post.capture.clipboard module.

    Published: 15 Jun 2018
    5.4
    Medium

    CVE-2018-12030

    Last Modified: 21 Nov 2024

    Chevereto Free before 1.0.13 has XSS.

    Published: 15 Jun 2018
    6.5
    Medium

    CVE-2018-12459

    Last Modified: 21 Nov 2024

    An inconsistent bits-per-sample value in the ff_mpeg4_decode_picture_header function in libavcodec/mpeg4videodec.c in FFmpeg 4.0 may trigger an assertion violation while converting a crafted AVI file to MPEG4, leading to a denial of service.

    Published: 15 Jun 2018
    6.5
    Medium

    CVE-2018-12460

    Last Modified: 21 Nov 2024

    libavcodec in FFmpeg 4.0 may trigger a NULL pointer dereference if the studio profile is incorrectly detected while converting a crafted AVI file to MPEG4, leading to a denial of service, related to idctdsp.c and mpegvideo.c.

    Published: 15 Jun 2018
    7.8
    High

    CVE-2018-5854

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow can occur in fastboot from all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.

    Published: 15 Jun 2018
    7.8
    High

    CVE-2018-5857

    Last Modified: 21 Nov 2024

    In the WCD CPE codec, a Use After Free condition can occur in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.

    Published: 15 Jun 2018
    6.5
    Medium

    CVE-2018-12458

    Last Modified: 21 Nov 2024

    An improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c in FFmpeg 2.8 and 4.0 may trigger an assertion violation while converting a crafted AVI file to MPEG4, leading to a denial of service.

    Published: 15 Jun 2018
    3.7
    Low

    CVE-2018-1419

    Last Modified: 21 Nov 2024

    IBM WebSphere MQ 8.0 and 9.0, when configured to use a PAM module for authentication, could allow a user to cause a deadlock in the IBM MQ PAM code which could result in a denial of service. IBM X-Force ID: 138949.

    Published: 15 Jun 2018
    8.4
    High

    CVE-2018-1460

    Last Modified: 21 Nov 2024

    IBM Netezza Platform Software (IBM PureData System for Analytics 1.0.0) could allow a local user to modify a world writable file, which could be used to execute commands as root. IBM X-Force ID: 140211.

    Published: 15 Jun 2018
    4.7
    Medium

    CVE-2018-6671

    Last Modified: 21 Nov 2024

    Application Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows remote authenticated users to bypass localhost only access security protection for some ePO features via a specially crafted HTTP request.

    Published: 15 Jun 2018
    5.7
    Medium

    CVE-2018-6672

    Last Modified: 21 Nov 2024

    Information disclosure vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows authenticated users to view sensitive information in plain text format via unspecified vectors.

    Published: 15 Jun 2018
    8.8
    High

    CVE-2018-12457

    Last Modified: 21 Nov 2024

    expressCart before 1.1.6 allows remote attackers to create an admin user via a /admin/setup Referer header.

    Published: 15 Jun 2018
    8.8
    High

    CVE-2018-12447

    Last Modified: 21 Nov 2024

    The restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.8 and other products, has an integer overflow that leads to a heap-based buffer overflow and remote code execution.

    Published: 15 Jun 2018
    4.7
    Medium

    CVE-2018-12434

    Last Modified: 21 Nov 2024

    LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

    Published: 15 Jun 2018
    5.9
    Medium

    CVE-2018-12435

    Last Modified: 21 Nov 2024

    Botan 2.5.0 through 2.6.0 before 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP, related to dsa/dsa.cpp, ec_group/ec_group.cpp, and ecdsa/ecdsa.cpp. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

    Published: 15 Jun 2018
    4.7
    Medium

    CVE-2018-12436

    Last Modified: 21 Nov 2024

    wolfcrypt/src/ecc.c in wolfSSL before 3.15.1.patch allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

    Published: 15 Jun 2018
    4.9
    Medium

    CVE-2018-12438

    Last Modified: 21 Nov 2024

    The Elliptic Curve Cryptography library (aka sunec or libsunec) allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

    Published: 15 Jun 2018
    4.7
    Medium

    CVE-2018-12439

    Last Modified: 21 Nov 2024

    MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

    Published: 15 Jun 2018
    9.8
    Critical

    CVE-2018-12356

    Last Modified: 21 Nov 2024

    An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verification routine parses the output of GnuPG with an incomplete regular expression, which allows remote attackers to spoof file signatures on configuration files and extension scripts. Modifying the configuration file allows the attacker to inject additional encryption keys under their control, thereby disclosing passwords to the attacker. Modifying the extension scripts allows the attacker arbitrary code execution.

    Published: 15 Jun 2018
    4.9
    Medium

    CVE-2018-12433

    Last Modified: 21 Nov 2024

    cryptlib through 3.4.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a key, the attacker needs access to either the local machine or a different virtual machine on the same physical host. NOTE: the vendor does not include side-channel attacks within its threat model

    Published: 15 Jun 2018
    8.1
    High

    CVE-2018-18559

    Last Modified: 21 Nov 2024

    In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt and bind on an AF_PACKET socket. This issue exists because of the 15fe076edea787807a7cdc168df832544b58eba6 incomplete fix for a race condition. The code mishandles a certain multithreaded case involving a packet_do_bind unregister action followed by a packet_notifier register action. Later, packet_release operates on only one of the two applicable linked lists. The attacker can achieve Program Counter control.

    Published: 15 Jun 2018
    4.8
    Medium

    CVE-2018-12431

    Last Modified: 21 Nov 2024

    SeaCMS V6.61 has XSS via the site name parameter on an adm1n/admin_config.php page (aka a system management page).

    Published: 14 Jun 2018
    6.1
    Medium

    CVE-2018-12432

    Last Modified: 21 Nov 2024

    JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI.

    Published: 14 Jun 2018
    7.5
    High

    CVE-2018-12420

    Last Modified: 21 Nov 2024

    IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request.

    Published: 14 Jun 2018
    7.5
    High

    CVE-2018-12423

    Last Modified: 21 Nov 2024

    In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.

    Published: 14 Jun 2018
    7.8
    High

    CVE-2018-6516

    Last Modified: 21 Nov 2024

    On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-client-tools) 16.4.x prior to 16.4.6, 17.3.x prior to 17.3.6, and 18.1.x prior to 18.1.2 to load arbitrary code with privilege escalation.

    Published: 14 Jun 2018
    6.1
    Medium

    CVE-2018-11690

    Last Modified: 21 Nov 2024

    The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

    Published: 14 Jun 2018
    8.8
    High

    CVE-2017-12070

    Last Modified: 21 Nov 2024

    Unsigned versions of the DLLs distributed by the OPC Foundation may be replaced with malicious code.

    Published: 14 Jun 2018
    6.1
    Medium

    CVE-2018-11689

    Last Modified: 21 Nov 2024

    Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)

    Published: 14 Jun 2018
    7.5
    High

    CVE-2018-8819

    Last Modified: 21 Nov 2024

    An XXE issue was discovered in Automated Logic Corporation (ALC) WebCTRL Versions 6.0, 6.1 and 6.5. An unauthenticated attacker could enter malicious input to WebCTRL and a weakly configured XML parser will allow the application to disclose full file contents from the underlying web server OS via the "X-Wap-Profile" HTTP header.

    Published: 14 Jun 2018
    9.8
    Critical

    CVE-2018-12421

    Last Modified: 21 Nov 2024

    LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a string.

    Published: 14 Jun 2018
    8.8
    High

    CVE-2018-12114

    Last Modified: 21 Nov 2024

    Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.

    Published: 14 Jun 2018
    4.8
    Medium

    CVE-2018-10821

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin role to inject arbitrary web script or HTML via the search panel.

    Published: 14 Jun 2018
    8.8
    High

    CVE-2018-4833

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.3), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.6), SCALANCE X-300 switch family (incl. SIPLUS NET variants) (All versions < V4.1.3), SCALANCE X408 (All versions < V4.1.3), SCALANCE X414 (All versions), SIMATIC RF182C (All versions). Unprivileged remote attackers located in the same local network segment (OSI Layer 2) could gain remote code execution on the affected products by sending a specially crafted DHCP response to a client's DHCP request.

    Published: 14 Jun 2018
    5.4
    Medium

    CVE-2018-8927

    Last Modified: 21 Nov 2024

    Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users to create arbitrary events via the (1) cal_id or (2) original_cal_id parameter.

    Published: 14 Jun 2018
    7.8
    High

    CVE-2017-17173

    Last Modified: 21 Nov 2024

    Due to insufficient parameters verification GPU driver of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.356(C00) has an arbitrary memory free vulnerability. An attacker can tricks a user into installing a malicious application on the smart phone, and send given parameter to driver to release special kernel memory resource. Successful exploit may result in phone crash or arbitrary code execution.

    Published: 14 Jun 2018
    7.5
    High

    CVE-2017-17309

    Last Modified: 21 Nov 2024

    Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received HTTP requests, a remote attacker may access the local files on the device without authentication.

    Published: 14 Jun 2018
    7.3
    High

    CVE-2017-17172

    Last Modified: 21 Nov 2024

    Huawei smart phones LYO-L21 with software LYO-L21C479B107, LYO-L21C479B107 have a privilege escalation vulnerability. An authenticated, local attacker can crafts malformed packets after tricking a user to install a malicious application and exploit this vulnerability when in the exception handling process. Successful exploitation may cause the attacker to obtain a higher privilege of the smart phones.

    Published: 14 Jun 2018
    4.3
    Medium

    CVE-2018-0871

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when Edge improperly marks files, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8234.

    Published: 14 Jun 2018
    7.5
    High

    CVE-2018-0978

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8249.

    Published: 14 Jun 2018
    7
    High

    CVE-2018-0982

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.

    Published: 14 Jun 2018
    6.5
    Medium

    CVE-2018-8113

    Last Modified: 21 Nov 2024

    A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mark of the Web Tagging (MOTW), aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11.

    Published: 14 Jun 2018
    4.7
    Medium

    CVE-2018-8121

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8207.

    Published: 14 Jun 2018