CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-12109

    Last Modified: 21 Nov 2024

    An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The TransformPaletteC<FileIO>::process function in transform/palette_C.hpp allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PAM image file.

    Published: 11 Jun 2018
    6.1
    Medium

    CVE-2018-12111

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /wt3/mydocs.php URI.

    Published: 11 Jun 2018
    7.5
    High

    CVE-2018-12093

    Last Modified: 21 Nov 2024

    tinyexr 0.9.5 has a memory leak in ParseEXRHeaderFromMemory in tinyexr.h.

    Published: 11 Jun 2018
    5.4
    Medium

    CVE-2018-12095

    Last Modified: 21 Nov 2024

    A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod parameter of info.php.

    Published: 11 Jun 2018
    4.8
    Medium

    CVE-2018-12100

    Last Modified: 21 Nov 2024

    Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI.

    Published: 11 Jun 2018
    9.8
    Critical

    CVE-2018-12092

    Last Modified: 21 Nov 2024

    tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.

    Published: 11 Jun 2018
    5.4
    Medium

    CVE-2018-12094

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 11 Jun 2018
    7.5
    High

    CVE-2018-12089

    Last Modified: 21 Nov 2024

    In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cluster, when the Service Fabric Cluster target is configured in Azure Active Directory security mode and a deployment is executed with OctopusPrintVariables set to True. This is fixed in 2018.6.0.

    Published: 11 Jun 2018
    7.5
    High

    CVE-2018-12025

    Last Modified: 21 Nov 2024

    The transferFrom function of a smart contract implementation for FuturXE (FXE), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized transfer of digital assets because of a logic error. The developer messed up with the boolean judgment - if the input value is smaller than or equal to allowed value, the transfer session would stop execution by returning false. This makes no sense, because the transferFrom() function should require the transferring value to not exceed the allowed value in the first place. Suppose this function asks for the allowed value to be smaller than the input. Then, the attacker could easily ignore the allowance: after this condition, the `allowed[from][msg.sender] -= value;` would cause an underflow because the allowed part is smaller than the value. The attacker could transfer any amount of FuturXe tokens of any accounts to an appointed account (the `_to` address) because the allowed value is initialized to 0, and the attacker could bypass this restriction even without the victim's private key.

    Published: 11 Jun 2018
    6.1
    Medium

    CVE-2018-12090

    Last Modified: 21 Nov 2024

    There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introduce arbitrary JavaScript via manipulation of an unsanitized GET parameter during a forgotPasswordChange.jsp?key= password change.

    Published: 11 Jun 2018
    5.9
    Medium

    CVE-2018-10855

    Last Modified: 21 Nov 2024

    Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12125

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12129

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12132

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12134

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12135

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12136

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12137

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12140

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12141

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12142

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12143

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12144

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12145

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12146

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12156

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12157

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12164

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12165

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12170

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12186

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12194

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12195

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12197

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12138

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12139

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12184

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    8.8
    High

    CVE-2018-12264

    Last Modified: 21 Nov 2024

    Exiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea in value.hpp.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12128

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    Unknown

    CVE-2018-12133

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 11 Jun 2018
    8.8
    High

    CVE-2018-12265

    Last Modified: 21 Nov 2024

    Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basicio.cpp.

    Published: 11 Jun 2018
    9.8
    Critical

    CVE-2018-13797

    Last Modified: 21 Nov 2024

    The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.

    Published: 11 Jun 2018
    7.5
    High

    CVE-2018-12088

    Last Modified: 21 Nov 2024

    S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versions of the filesystem metadata database as up-to-date, temporarily inject zero-valued bytes into files, or temporarily hide parts of files. This is related to the checksum_basic_mapping function.

    Published: 10 Jun 2018
    4.2
    Medium

    CVE-2018-10881

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound access in ext4_get_group_info function, a denial of service, and a system crash by mounting and operating on a crafted ext4 filesystem image.

    Published: 10 Jun 2018
    7.5
    High

    CVE-2018-12453

    Last Modified: 21 Nov 2024

    Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-service via an XGROUP command in which the key is not a stream.

    Published: 10 Jun 2018
    6.5
    Medium

    CVE-2018-10360

    Last Modified: 21 Nov 2024

    The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

    Published: 9 Jun 2018
    5.3
    Medium

    CVE-2018-8041

    Last Modified: 21 Nov 2024

    Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.

    Published: 9 Jun 2018
    5.5
    Medium

    CVE-2018-10880

    Last Modified: 21 Nov 2024

    Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting and writing to a crafted ext4 image in ext4_update_inline_data(). An attacker could use this to cause a system crash and a denial of service.

    Published: 9 Jun 2018
    9.8
    Critical

    CVE-2018-0225

    Last Modified: 29 Nov 2024

    The Enterprise Console in Cisco AppDynamics App iQ Platform before 4.4.3.10598 (HF4) allows SQL injection, aka the Security Advisory 2089 issue.

    Published: 8 Jun 2018
    6.5
    Medium

    CVE-2018-1281

    Last Modified: 21 Nov 2024

    The clustered setup of Apache MXNet allows users to specify which IP address and port the scheduler will listen on via the DMLC_PS_ROOT_URI and DMLC_PS_ROOT_PORT env variables. In versions older than 1.0.0, however, the MXNet framework will listen on 0.0.0.0 rather than user specified DMLC_PS_ROOT_URI once a scheduler node is initialized. This exposes the instance running MXNet to any attackers reachable via the interface they didn't expect to be listening on. For example: If a user wants to run a clustered setup locally, they may specify to run on 127.0.0.1. But since MXNet will listen on 0.0.0.0, it makes the port accessible on all network interfaces.

    Published: 8 Jun 2018