CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-10403

    Last Modified: 21 Nov 2024

    An issue was discovered in F-Secure XFENCE and Little Flocker. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will execute.

    Published: 13 Jun 2018
    7.8
    High

    CVE-2018-10406

    Last Modified: 21 Nov 2024

    An issue was discovered in Yelp OSXCollector. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will execute.

    Published: 13 Jun 2018
    7.8
    High

    CVE-2018-10408

    Last Modified: 21 Nov 2024

    An issue was discovered in VirusTotal. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will execute.

    Published: 13 Jun 2018
    6.1
    Medium

    CVE-2018-12040

    Last Modified: 21 Nov 2024

    Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _profiler/open?file= URI. NOTE: The vendor states "The XSS ... is in the web profiler, a tool that should never be deployed in production (so, we don't handle those issues as security issues).

    Published: 13 Jun 2018
    5.4
    Medium

    CVE-2017-3907

    Last Modified: 21 Nov 2024

    Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows remote attackers to execute arbitrary HTML code to be reflected in the response web page via unspecified vector.

    Published: 13 Jun 2018
    6.2
    Medium

    CVE-2017-3936

    Last Modified: 21 Nov 2024

    OS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows attackers to run arbitrary OS commands with limited privileges via not sanitizing the user input data before exporting it into a CSV format output.

    Published: 13 Jun 2018
    5.6
    Medium

    CVE-2018-3665

    Last Modified: 21 Nov 2024

    System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.

    Published: 13 Jun 2018
    7.5
    High

    CVE-2017-3968

    Last Modified: 21 Nov 2024

    Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers to disclose sensitive information or manipulate the database via a crafted authentication cookie.

    Published: 13 Jun 2018
    9.8
    Critical

    CVE-2018-5488

    Last Modified: 21 Nov 2024

    NetApp SANtricity Web Services Proxy versions 1.10.x000.0002 through 2.12.X000.0002 and SANtricity Storage Manager 11.30.0X00.0004 through 11.42.0X00.0001 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service bound to the network, and are susceptible to unauthenticated remote code execution.

    Published: 13 Jun 2018
    5.4
    Medium

    CVE-2018-12339

    Last Modified: 21 Nov 2024

    ArticleCMS through 2017-02-19 has XSS via an "add an article" action.

    Published: 13 Jun 2018
    5.3
    Medium

    CVE-2018-7559

    Last Modified: 21 Nov 2024

    An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET Legacy Stack and Sample Code before GitHub commit 2018-03-13. A vulnerability in OPC UA applications can allow a remote attacker to determine a Server's private key by sending carefully constructed bad UserIdentityTokens as part of an oracle attack.

    Published: 13 Jun 2018
    7.5
    High

    CVE-2018-10363

    Last Modified: 21 Nov 2024

    An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices.

    Published: 13 Jun 2018
    7.8
    High

    CVE-2017-11672

    Last Modified: 21 Nov 2024

    The OPC Foundation Local Discovery Server (LDS) before 1.03.367 is installed as a Windows Service without adding double quotes around the opcualds.exe executable path, which might allow local users to gain privileges.

    Published: 13 Jun 2018
    6.5
    Medium

    CVE-2017-17443

    Last Modified: 21 Nov 2024

    OPC Foundation Local Discovery Server (LDS) 1.03.370 required a security update to resolve multiple vulnerabilities that allow attackers to trigger a crash by placing invalid data into the configuration file. This vulnerability requires an attacker with access to the file system where the configuration file is stored; however, if the configuration file is altered the LDS will be unavailable until it is repaired.

    Published: 13 Jun 2018
    8.8
    High

    CVE-2017-15695

    Last Modified: 21 Nov 2024

    When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geode function. This allows remote code execution. Code deployment should be restricted to users with DATA:MANAGE privilege.

    Published: 13 Jun 2018
    5.9
    Medium

    CVE-2018-11386

    Last Modified: 21 Nov 2024

    An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under some configurations and with a well-crafted payload, it was possible to do a denial of service on a Symfony application without too much resources.

    Published: 13 Jun 2018
    6.1
    Medium

    CVE-2018-11688

    Last Modified: 21 Nov 2024

    Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

    Published: 13 Jun 2018
    7.8
    High

    CVE-2018-12321

    Last Modified: 21 Nov 2024

    There is a heap out of bounds read in radare2 2.6.0 in java_switch_op() in libr/anal/p/anal_java.c via a crafted Java binary file.

    Published: 13 Jun 2018
    5.5
    Medium

    CVE-2018-12322

    Last Modified: 21 Nov 2024

    There is a heap out of bounds read in radare2 2.6.0 in _6502_op() in libr/anal/p/anal_6502.c via a crafted iNES ROM binary file.

    Published: 13 Jun 2018
    6.2
    Medium

    CVE-2018-5242

    Last Modified: 21 Nov 2024

    Norton App Lock prior to version 1.3.0.329 can be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking the device, thereby allowing the individual to gain device access.

    Published: 13 Jun 2018
    6.1
    Medium

    CVE-2017-16652

    Last Modified: 21 Nov 2024

    An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path parameter and generates a redirect response, but no check is performed on the path, which could be an absolute URL to an external domain. This Open redirect vulnerability can be exploited for example to mount effective phishing attacks.

    Published: 13 Jun 2018
    8.1
    High

    CVE-2018-11385

    Last Modified: 21 Nov 2024

    An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login feature may allow an attacker to impersonate a victim towards the web application if the session id value was previously known to the attacker.

    Published: 13 Jun 2018
    8.8
    High

    CVE-2018-11406

    Last Modified: 21 Nov 2024

    An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is logged out. This behavior can be disabled through the invalidate_session option. In this case, CSRF tokens were not erased during logout which allowed for CSRF token fixation.

    Published: 13 Jun 2018
    9.8
    Critical

    CVE-2018-11407

    Last Modified: 21 Nov 2024

    An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an unauthenticated bind. NOTE: this issue exists because of an incomplete fix for CVE-2016-2403.

    Published: 13 Jun 2018
    6.1
    Medium

    CVE-2018-11408

    Last Modified: 21 Nov 2024

    The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a container. NOTE: this issue exists because of an incomplete fix for CVE-2017-16652.

    Published: 13 Jun 2018
    7.8
    High

    CVE-2018-12320

    Last Modified: 21 Nov 2024

    There is a use after free in radare2 2.6.0 in r_anal_bb_free() in libr/anal/bb.c via a crafted Java binary file.

    Published: 13 Jun 2018
    6.8
    Medium

    CVE-2018-12323

    Last Modified: 21 Nov 2024

    An issue was discovered on Momentum Axel 720P 5.1.8 devices. A password of EHLGVG is hard-coded for the root and admin accounts, which makes it easier for physically proximate attackers to login at the console.

    Published: 13 Jun 2018
    3.7
    Low

    CVE-2018-3759

    Last Modified: 21 Nov 2024

    private_address_check ruby gem before 0.5.0 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition due to the address the socket uses not being checked. DNS entries with a TTL of 0 can trigger this case where the initial resolution is a public address but the subsequent resolution is a private address.

    Published: 13 Jun 2018
    6.1
    Medium

    CVE-2018-12290

    Last Modified: 21 Nov 2024

    The Yii2-StateMachine extension v2.x.x for Yii2 has XSS.

    Published: 13 Jun 2018
    9.8
    Critical

    CVE-2018-12292

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.

    Published: 13 Jun 2018
    7.4
    High

    CVE-2018-1431

    Last Modified: 21 Nov 2024

    A vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could allow a local attacker to obtain control of the Spectrum Scale daemon and to access and modify files in the Spectrum Scale file system, and possibly to obtain administrator privileges on the node. IBM X-Force ID: 139240.

    Published: 13 Jun 2018
    7.5
    High

    CVE-2018-12291

    Last Modified: 21 Nov 2024

    The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly.

    Published: 13 Jun 2018
    3.1
    Low

    CVE-2018-1393

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.6 could allow an authenticated user to execute a specially crafted command that could obtain sensitive information. IBM X-Force ID: 138378.

    Published: 13 Jun 2018
    6.1
    Medium

    CVE-2018-12273

    Last Modified: 21 Nov 2024

    The /edit URI in the DMS component in Ximdex 4.0 has XSS via the Ciudad or Nombre parameter.

    Published: 13 Jun 2018
    5.8
    Medium

    CVE-2018-5434

    Last Modified: 21 Nov 2024

    The TIBCO Designer component of TIBCO Software Inc.'s TIBCO Runtime Agent, and TIBCO Runtime Agent for z/Linux contains vulnerabilities wherein a malicious user could perform XML external entity expansion (XXE) attacks to disclose host machine information. Affected releases are TIBCO Software Inc.'s TIBCO Runtime Agent: versions up to and including 5.10.0, and TIBCO Runtime Agent for z/Linux: versions up to and including 5.9.1.

    Published: 13 Jun 2018
    6.5
    Medium

    CVE-2011-4183

    Last Modified: 21 Nov 2024

    A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. Affected releases are SUSE open build service prior to 2.1.16.

    Published: 13 Jun 2018
    6.1
    Medium

    CVE-2018-12272

    Last Modified: 21 Nov 2024

    xowl/request.php in Ximdex 4.0 has XSS via the content parameter.

    Published: 13 Jun 2018
    8
    High

    CVE-2018-5432

    Last Modified: 21 Nov 2024

    The TIBCO Administrator server component of of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, and TIBCO Administrator - Enterprise Edition for z/Linux contains multiple vulnerabilities wherein a malicious user could theoretically perform cross-site scripting (XSS) attacks by way of manipulating artifacts prior to uploading them. Affected releases are TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition: versions up to and including 5.10.0, and TIBCO Administrator - Enterprise Edition for z/Linux: versions up to and including 5.9.1.

    Published: 13 Jun 2018
    6.5
    Medium

    CVE-2018-5433

    Last Modified: 21 Nov 2024

    The TIBCO Administrator server component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, and TIBCO Administrator - Enterprise Edition for z/Linux contains vulnerabilities wherein a malicious user could perform XML external entity expansion (XXE) attacks to disclose host machine information. Affected releases are TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition: versions up to and including 5.10.0, and TIBCO Administrator - Enterprise Edition for z/Linux: versions up to and including 5.9.1.

    Published: 13 Jun 2018
    8.8
    High

    CVE-2018-12263

    Last Modified: 21 Nov 2024

    portfolioCMS 1.0.5 allows upload of arbitrary .php files via the admin/portfolio.php?newpage=true URI.

    Published: 13 Jun 2018
    6.1
    Medium

    CVE-2018-12266

    Last Modified: 21 Nov 2024

    system\errors\404.php in HongCMS 3.0.0 has XSS via crafted input that triggers a 404 HTTP status code.

    Published: 13 Jun 2018
    9.8
    Critical

    CVE-2018-12268

    Last Modified: 21 Nov 2024

    acccheck.pl in acccheck 0.2.1 allows Command Injection via shell metacharacters in a username or password file, as demonstrated by injection into an smbclient command line.

    Published: 13 Jun 2018
    4.9
    Medium

    CVE-2018-12437

    Last Modified: 5 Jun 2026

    LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

    Published: 13 Jun 2018
    4.7
    Medium

    CVE-2018-12440

    Last Modified: 21 Nov 2024

    BoringSSL through 2018-06-14 allows a memory-cache side-channel attack on DSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a DSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

    Published: 13 Jun 2018
    5.3
    Medium

    CVE-2018-12537

    Last Modified: 21 Nov 2024

    In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.

    Published: 13 Jun 2018
    4.7
    Medium

    CVE-2018-0495

    Last Modified: 21 Nov 2024

    Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

    Published: 13 Jun 2018
    9.8
    Critical

    CVE-2018-11218

    Last Modified: 21 Nov 2024

    Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.

    Published: 13 Jun 2018
    9.8
    Critical

    CVE-2018-11219

    Last Modified: 21 Nov 2024

    An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking.

    Published: 13 Jun 2018
    6.5
    Medium

    CVE-2018-1152

    Last Modified: 21 Nov 2024

    libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image.

    Published: 13 Jun 2018
    8.4
    High

    CVE-2018-12326

    Last Modified: 21 Nov 2024

    Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privileges via a crafted command line. NOTE: It is unclear whether there are any common situations in which redis-cli is used with, for example, a -h (aka hostname) argument from an untrusted source.

    Published: 13 Jun 2018