CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-0496

    Last Modified: 21 Nov 2024

    Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allow an attacker to overwrite arbitrary files on the user's system.

    Published: 12 Jun 2018
    7.8
    High

    CVE-2018-3571

    Last Modified: 21 Nov 2024

    In the KGSL driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a Use After Free condition can occur when printing information about sparse memory allocations

    Published: 12 Jun 2018
    7.8
    High

    CVE-2018-3572

    Last Modified: 21 Nov 2024

    While processing a DSP buffer in an audio driver's event handler, an index of a buffer is not checked before accessing the buffer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 12 Jun 2018
    7.8
    High

    CVE-2018-3581

    Last Modified: 21 Nov 2024

    In the WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a buffer overwrite can occur if the vdev_id received from firmware is larger than max_bssid.

    Published: 12 Jun 2018
    7.8
    High

    CVE-2018-3582

    Last Modified: 21 Nov 2024

    Buffer overflow can occur due to improper input validation in multiple WMA event handler functions in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 12 Jun 2018
    7.8
    High

    CVE-2018-5842

    Last Modified: 21 Nov 2024

    An arbitrary address write can occur if a compromised WLAN firmware sends incorrect data to WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 12 Jun 2018
    7.8
    High

    CVE-2018-5844

    Last Modified: 21 Nov 2024

    In the video driver function set_output_buffers(), binfo can be accessed after being freed in a failure scenario in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 12 Jun 2018
    7.8
    High

    CVE-2018-5847

    Last Modified: 21 Nov 2024

    Early or late retirement of rotation requests can result in a Use After Free condition in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 12 Jun 2018
    7.8
    High

    CVE-2018-5851

    Last Modified: 21 Nov 2024

    Buffer over flow can occur while processing a HTT_T2H_MSG_TYPE_TX_COMPL_IND message with an out-of-range num_msdus value in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 12 Jun 2018
    7.8
    High

    CVE-2017-15842

    Last Modified: 21 Nov 2024

    Buffer might get used after it gets freed due to unlocking the mutex before freeing the buffer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 12 Jun 2018
    7.8
    High

    CVE-2018-3576

    Last Modified: 21 Nov 2024

    improper validation of array index in WiFi driver function sapInterferenceRssiCount() leads to array out-of-bounds access in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 12 Jun 2018
    7.8
    High

    CVE-2017-15854

    Last Modified: 21 Nov 2024

    The value of fix_param->num_chans is received from firmware and if it is too large, an integer overflow can occur in wma_radio_chan_stats_event_handler() for the derived length len leading to a subsequent buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 12 Jun 2018
    7.8
    High

    CVE-2017-15857

    Last Modified: 21 Nov 2024

    In the camera driver, an out-of-bounds access can occur due to an error in copying region params from user space in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 12 Jun 2018
    7.8
    High

    CVE-2017-18070

    Last Modified: 21 Nov 2024

    In wma_ndp_end_response_event_handler(), the variable len_end_rsp is a uint32 which can be overflowed if the value of variable "event->num_ndp_end_rsp_per_ndi_list" is very large which can then lead to a heap overwrite of the heap object end_rsp in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 12 Jun 2018
    7
    High

    CVE-2017-15843

    Last Modified: 21 Nov 2024

    Due to a race condition in a bus driver, a double free in msm_bus_floor_vote_context() can potentially occur in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 12 Jun 2018
    5.5
    Medium

    CVE-2018-3579

    Last Modified: 21 Nov 2024

    In the WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, event->num_entries_in_page is a value received from firmware that is not properly validated which can lead to a buffer over-read

    Published: 12 Jun 2018
    7.8
    High

    CVE-2018-5843

    Last Modified: 21 Nov 2024

    In the function wma_pdev_div_info_evt_handler() in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, there is no upper bound check on the value event->num_chains_valid received from firmware which can lead to a buffer overwrite of the fixed size chain_rssi_result structure.

    Published: 12 Jun 2018
    7
    High

    CVE-2018-5849

    Last Modified: 21 Nov 2024

    Due to a race condition in the QTEECOM driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, when more than one HLOS client loads the same TA, a Use After Free condition can occur.

    Published: 12 Jun 2018
    6.8
    Medium

    CVE-2018-12259

    Last Modified: 21 Nov 2024

    An issue was discovered on Momentum Axel 720P 5.1.8 devices. Root access can be obtained via UART pins without any restrictions, which leads to full system compromise.

    Published: 12 Jun 2018
    4.4
    Medium

    CVE-2018-12261

    Last Modified: 21 Nov 2024

    An issue was discovered on Momentum Axel 720P 5.1.8 devices. All processes run as root.

    Published: 12 Jun 2018
    9.8
    Critical

    CVE-2017-18287

    Last Modified: 21 Nov 2024

    An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the POST user_search parameter.

    Published: 12 Jun 2018
    9.8
    Critical

    CVE-2017-18288

    Last Modified: 21 Nov 2024

    An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET game parameter.

    Published: 12 Jun 2018
    9.8
    Critical

    CVE-2017-18290

    Last Modified: 21 Nov 2024

    An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET sort_direction parameter.

    Published: 12 Jun 2018
    9.8
    Critical

    CVE-2017-18291

    Last Modified: 21 Nov 2024

    An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET user parameter.

    Published: 12 Jun 2018
    9.8
    Critical

    CVE-2017-18289

    Last Modified: 21 Nov 2024

    An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exist in ladder/stats.php via the GET type parameter.

    Published: 12 Jun 2018
    4.4
    Medium

    CVE-2018-12257

    Last Modified: 21 Nov 2024

    An issue was discovered on Momentum Axel 720P 5.1.8 devices. There is Authenticated Custom Firmware Upgrade via DNS Hijacking. An authenticated root user with CLI access is able to remotely upgrade firmware to a custom image due to lack of SSL validation by changing the nameservers in /etc/resolv.conf to the attacker's server, and serving the expected HTTPS response containing new firmware for the device to download.

    Published: 12 Jun 2018
    6.8
    Medium

    CVE-2018-12258

    Last Modified: 21 Nov 2024

    An issue was discovered on Momentum Axel 720P 5.1.8 devices. Custom Firmware Upgrade is possible via an SD Card. With physical access, an attacker can upgrade the firmware in under 60 seconds by inserting an SD card containing the firmware with name 'ezviz.dav' and rebooting.

    Published: 12 Jun 2018
    6.7
    Medium

    CVE-2018-12260

    Last Modified: 21 Nov 2024

    An issue was discovered on Momentum Axel 720P 5.1.8 devices. The root password can be obtained in cleartext by issuing the command 'showKey' from the root CLI. This password may be the same on all devices

    Published: 12 Jun 2018
    5.3
    Medium

    CVE-2018-10470

    Last Modified: 21 Nov 2024

    Little Snitch versions 4.0 to 4.0.6 use the SecStaticCodeCheckValidityWithErrors() function without the kSecCSCheckAllArchitectures flag and therefore do not validate all architectures stored in a fat binary. An attacker can maliciously craft a fat binary containing multiple architectures that may cause a situation where Little Snitch treats the running process as having no code signature at all while erroneously indicating that the binary on disk does have a valid code signature. This could lead to users being confused about whether or not the code signature is valid.

    Published: 12 Jun 2018
    8.8
    High

    CVE-2018-10508

    Last Modified: 21 Nov 2024

    A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to use a specially crafted URL to elevate account permissions on vulnerable installations. An attacker must already have at least guest privileges in order to exploit this vulnerability.

    Published: 12 Jun 2018
    8.8
    High

    CVE-2018-10509

    Last Modified: 21 Nov 2024

    A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to exploit it via a Browser Refresh attack on vulnerable installations. An attacker must be using a AD logon user account in order to exploit this vulnerability.

    Published: 12 Jun 2018
    8.8
    High

    CVE-2018-12254

    Last Modified: 21 Nov 2024

    router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to a home/requested_user/Sent%20interest/ URI.

    Published: 12 Jun 2018
    4.4
    Medium

    CVE-2018-10507

    Last Modified: 21 Nov 2024

    A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or render the OfficeScan Unauthorized Change Prevention inoperable on vulnerable installations. An attacker must already have administrator privileges in order to exploit this vulnerability.

    Published: 12 Jun 2018
    9.8
    Critical

    CVE-2018-1151

    Last Modified: 21 Nov 2024

    The web server on Western Digital TV Media Player 1.03.07 and TV Live Hub 3.12.13 allow unauthenticated remote attackers to execute arbitrary code or cause denial of service via crafted HTTP requests to toServerValue.cgi.

    Published: 12 Jun 2018
    7.1
    High

    CVE-2018-5718

    Last Modified: 21 Nov 2024

    Improper restriction of write operations within the bounds of a memory buffer in snscore.sys in SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecure, SoftControl/SafenSoft Enterprise Suite before version 4.4.1 allows local users to cause a denial of service (BSOD) or modify kernel-mode memory via loading of a forged DLL into an user-mode process.

    Published: 12 Jun 2018
    5.3
    Medium

    CVE-2018-2428

    Last Modified: 21 Nov 2024

    Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. Software components affected are: SAP Infrastructure 1.0, SAP UI 7.4, 7.5, 7.51, 7.52 and version 2.0 of SAP UI for SAP NetWeaver 7.00.

    Published: 12 Jun 2018
    7.3
    High

    CVE-2011-4182

    Last Modified: 21 Nov 2024

    Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. Affected releases are sysconfig prior to 0.83.7-2.1.

    Published: 12 Jun 2018
    9.8
    Critical

    CVE-2018-2424

    Last Modified: 21 Nov 2024

    SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to the DOM that could steal user information. Software components affected are: SAP Hana Database 1.00, 2.00; SAP UI5 1.00; SAP UI5 (Java) 7.30, 7.31, 7.40, 7,50; SAP UI 7.40, 7.50, 7.51, 7.52, and version 2.0 of SAP UI for SAP NetWeaver 7.00

    Published: 12 Jun 2018
    8.4
    High

    CVE-2018-2425

    Last Modified: 21 Nov 2024

    Under certain conditions, SAP Business One, 9.2, 9.3, for SAP HANA backup service allows an attacker to access information which would otherwise be restricted.

    Published: 12 Jun 2018
    7.5
    High

    CVE-2018-12249

    Last Modified: 21 Nov 2024

    An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject" is not properly supported in class.c.

    Published: 12 Jun 2018
    5.9
    Medium

    CVE-2017-3960

    Last Modified: 21 Nov 2024

    Exploitation of Authorization vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to gain elevated privileges via a crafted HTTP request parameter.

    Published: 12 Jun 2018
    5.6
    Medium

    CVE-2017-3962

    Last Modified: 21 Nov 2024

    Password recovery exploitation vulnerability in the non-certificate-based authentication mechanism in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to crack user passwords via unsalted hashes.

    Published: 12 Jun 2018
    7.5
    High

    CVE-2018-12247

    Last Modified: 21 Nov 2024

    An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class, related to certain .clone usage, because mrb_obj_clone in kernel.c copies flags other than the MRB_FLAG_IS_FROZEN flag (e.g., the embedded flag).

    Published: 12 Jun 2018
    7.5
    High

    CVE-2018-12248

    Last Modified: 21 Nov 2024

    An issue was discovered in mruby 1.4.1. There is a heap-based buffer over-read associated with OP_ENTER because mrbgems/mruby-fiber/src/fiber.c does not extend the stack in cases of many arguments to fiber.

    Published: 12 Jun 2018
    6.1
    Medium

    CVE-2018-12229

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Public Knowledge Project (PKP) Open Journal System (OJS) 3.0.0 to 3.1.1-1 allows remote attackers to inject arbitrary web script or HTML via the templates/frontend/pages/search.tpl parameter (aka the By Author field).

    Published: 12 Jun 2018
    9.8
    Critical

    CVE-2018-11574

    Last Modified: 3 Dec 2025

    Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected.

    Published: 12 Jun 2018
    6.5
    Medium

    CVE-2018-12228

    Last Modified: 21 Nov 2024

    An issue was discovered in Asterisk Open Source 15.x before 15.4.1. When connected to Asterisk via TCP/TLS, if the client abruptly disconnects, or sends a specially crafted message, then Asterisk gets caught in an infinite loop while trying to read the data stream. This renders the system unusable.

    Published: 12 Jun 2018
    5.3
    Medium

    CVE-2018-12227

    Last Modified: 21 Nov 2024

    An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert before 13.18-cert4 and 13.21-cert before 13.21-cert2. When endpoint specific ACL rules block a SIP request, they respond with a 403 forbidden. However, if an endpoint is not identified, then a 401 unauthorized response is sent. This vulnerability just discloses which requests hit a defined endpoint. The ACL rules cannot be bypassed to gain access to the disclosed endpoints.

    Published: 12 Jun 2018
    8.8
    High

    CVE-2018-6149

    Last Modified: 21 Nov 2024

    Type confusion in JavaScript in Google Chrome prior to 67.0.3396.87 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

    Published: 12 Jun 2018
    7.5
    High

    CVE-2018-7161

    Last Modified: 21 Nov 2024

    All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation.

    Published: 12 Jun 2018