CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2017-16168

    Last Modified: 21 Nov 2024

    wffserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16171

    Last Modified: 21 Nov 2024

    hcbserver is a static file server. hcbserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16172

    Last Modified: 21 Nov 2024

    section2.madisonjbrooks12 is a simple web server. section2.madisonjbrooks12 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16173

    Last Modified: 21 Nov 2024

    utahcityfinder constructs lists of Utah cities with a certain prefix. utahcityfinder is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16174

    Last Modified: 21 Nov 2024

    whispercast is a file server. whispercast is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16175

    Last Modified: 21 Nov 2024

    ewgaddis.lab6 is a file server. ewgaddis.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    5.5
    Medium

    CVE-2018-14851

    Last Modified: 21 Nov 2024

    exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG file.

    Published: 7 Jun 2018
    5.5
    Medium

    CVE-2018-13094

    Last Modified: 21 Nov 2024

    An issue was discovered in fs/xfs/libxfs/xfs_attr_leaf.c in the Linux kernel through 4.17.3. An OOPS may occur for a corrupted xfs image after xfs_da_shrink_inode() is called with a NULL bp.

    Published: 7 Jun 2018
    5.4
    Medium

    CVE-2018-3717

    Last Modified: 21 Nov 2024

    connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.

    Published: 7 Jun 2018
    8.8
    High

    CVE-2018-4945

    Last Modified: 21 Nov 2024

    Adobe Flash Player versions 29.0.0.171 and earlier have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 7 Jun 2018
    6.5
    Medium

    CVE-2018-5000

    Last Modified: 21 Nov 2024

    Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could lead to information disclosure.

    Published: 7 Jun 2018
    6.5
    Medium

    CVE-2018-5001

    Last Modified: 21 Nov 2024

    Adobe Flash Player versions 29.0.0.171 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 7 Jun 2018
    7.8
    High

    CVE-2018-6514

    Last Modified: 21 Nov 2024

    In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a DLL preloading attack, which could lead to a privilege escalation.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16118

    Last Modified: 21 Nov 2024

    The forwarded module is used by the Express.js framework to handle the X-Forwarded-For header. It is vulnerable to a regular expression denial of service when it's passed specially crafted input to parse. This causes the event loop to be blocked causing a denial of service condition.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16119

    Last Modified: 21 Nov 2024

    Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular expression denial of service when it is passed specially crafted input to parse. This causes the event loop to be blocked causing a denial of service condition.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-7656

    Last Modified: 21 Nov 2024

    In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space URI space version) that declares a version of HTTP/0.9 was accepted and treated as a 0.9 request. If deployed behind an intermediary that also accepted and passed through the 0.9 version (but did not act on it), then the response sent could be interpreted by the intermediary as HTTP/1 headers. This could be used to poison the cache if the server allowed the origin client to generate arbitrary content in the response.

    Published: 7 Jun 2018
    9.8
    Critical

    CVE-2017-7658

    Last Modified: 21 Nov 2024

    In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2018-14883

    Last Modified: 21 Nov 2024

    An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c.

    Published: 7 Jun 2018
    7.8
    High

    CVE-2018-5002

    Last Modified: 18 Nov 2025

    Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 7 Jun 2018
    7.8
    High

    CVE-2018-6515

    Last Modified: 21 Nov 2024

    Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted configuration file an attacker could get pxp-agent to load arbitrary code with privilege escalation.

    Published: 7 Jun 2018
    9.8
    Critical

    CVE-2017-7657

    Last Modified: 21 Nov 2024

    In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body could be interpreted as a pipelined request. If Jetty was deployed behind an intermediary that imposed some authorization and that intermediary allowed arbitrarily large chunks to be passed on unchanged, then this flaw could be used to bypass the authorization imposed by the intermediary as the fake pipelined request would not be interpreted by the intermediary as a request.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2018-12015

    Last Modified: 21 Nov 2024

    In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.

    Published: 7 Jun 2018
    7.8
    High

    CVE-2018-3565

    Last Modified: 21 Nov 2024

    While sending a probe request indication in lim_send_sme_probe_req_ind() in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a buffer overflow can occur.

    Published: 6 Jun 2018
    7.8
    High

    CVE-2018-3578

    Last Modified: 21 Nov 2024

    Type mismatch for ie_len can cause the WLAN driver to allocate less memory on the heap due to implicit casting leading to a heap buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 6 Jun 2018
    7.8
    High

    CVE-2018-3580

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow can occur In the WLAN driver if the pmkid_count value is larger than the PMKIDCache size in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 6 Jun 2018
    7.5
    High

    CVE-2018-3852

    Last Modified: 21 Nov 2024

    An exploitable denial of service vulnerability exists in the Ocularis Recorder functionality of Ocularis 5.5.0.242. A specially crafted TCP packet can cause a process to terminate resulting in denial of service. An attacker can send a crafted TCP packet to trigger this vulnerability.

    Published: 6 Jun 2018
    7.8
    High

    CVE-2018-5840

    Last Modified: 21 Nov 2024

    Buffer Copy without Checking Size of Input can occur during the DRM SDE driver initialization sequence in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 6 Jun 2018
    7
    High

    CVE-2018-5845

    Last Modified: 21 Nov 2024

    A race condition in drm_atomic_nonblocking_commit() in the display driver can potentially lead to a Use After Free scenario in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 6 Jun 2018
    7.8
    High

    CVE-2018-5846

    Last Modified: 21 Nov 2024

    A Use After Free condition can occur in the IPA driver whenever the IPA IOCTLs IPA_IOC_NOTIFY_WAN_UPSTREAM_ROUTE_ADD/IPA_IOC_NOTIFY_WAN_UPSTREAM_ROUTE_DEL/IPA_IOC_NOTIFY_WAN_EMBMS_CONNECTED are called in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 6 Jun 2018
    7.8
    High

    CVE-2017-18154

    Last Modified: 21 Nov 2024

    A crafted binder request can cause an arbitrary unmap in MediaServer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 6 Jun 2018
    7.8
    High

    CVE-2018-5850

    Last Modified: 21 Nov 2024

    In the function csr_update_fils_params_rso(), insufficient validation on a key length can result in an integer underflow leading to a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 6 Jun 2018
    5.5
    Medium

    CVE-2018-3562

    Last Modified: 21 Nov 2024

    Buffer over -read can occur while processing a FILS authentication frame in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 6 Jun 2018
    7.8
    High

    CVE-2018-5841

    Last Modified: 21 Nov 2024

    dcc_curr_list is initialized with a default invalid value that is expected to be programmed by the user through a sysfs node which could lead to an invalid access in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 6 Jun 2018
    4.3
    Medium

    CVE-2018-10198

    Last Modified: 21 Nov 2024

    An issue was discovered in OTRS 6.0.x before 6.0.7. An attacker who is logged into OTRS as a customer can use the ticket overview screen to disclose internal article information of their customer tickets.

    Published: 6 Jun 2018
    6.8
    Medium

    CVE-2018-1268

    Last Modified: 21 Nov 2024

    Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not validate app GUID structure in requests. A remote authenticated malicious user knowing the GUID of an app may construct malicious requests to read from or write to the logs of that app.

    Published: 6 Jun 2018
    6.5
    Medium

    CVE-2018-1269

    Last Modified: 21 Nov 2024

    Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not handle errors thrown while constructing certain http requests. A remote authenticated user may construct malicious requests to cause the traffic controller to leave dangling TCP connections, which could cause denial of service.

    Published: 6 Jun 2018
    7.2
    High

    CVE-2018-1265

    Last Modified: 21 Nov 2024

    Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a complete takeover of a Diego Cell VM and access to all apps running on that Diego Cell.

    Published: 6 Jun 2018
    8.8
    High

    CVE-2017-7906

    Last Modified: 21 Nov 2024

    In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow an attacker to launch a request impersonating that user.

    Published: 6 Jun 2018
    9.8
    Critical

    CVE-2017-7931

    Last Modified: 21 Nov 2024

    In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access the configuration files and application pages without authentication.

    Published: 6 Jun 2018
    9.8
    Critical

    CVE-2017-7933

    Last Modified: 21 Nov 2024

    In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unauthorized access.

    Published: 6 Jun 2018
    9.8
    Critical

    CVE-2018-7510

    Last Modified: 21 Nov 2024

    In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords are presented in plaintext in a file that is accessible without authentication.

    Published: 6 Jun 2018
    7.5
    High

    CVE-2018-1000203

    Last Modified: 21 Nov 2024

    Soar Labs Soar Coin version up to and including git commit 4a2aa71ee21014e2880a3f7aad11091ed6ad434f (latest release as of Sept 2017) contains an intentional backdoor vulnerability in the function zero_fee_transaction() that can result in theft of Soar Coins by the "onlycentralAccount" (Soar Labs) after payment is processed.

    Published: 6 Jun 2018
    5.3
    Medium

    CVE-2017-1474

    Last Modified: 21 Nov 2024

    IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 128606.

    Published: 6 Jun 2018
    5.9
    Medium

    CVE-2017-1476

    Last Modified: 21 Nov 2024

    IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 128610.

    Published: 6 Jun 2018
    4.3
    Medium

    CVE-2017-1480

    Last Modified: 21 Nov 2024

    IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617.

    Published: 6 Jun 2018
    7.1
    High

    CVE-2018-1456

    Last Modified: 21 Nov 2024

    IBM Rhapsody DM 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 140091.

    Published: 6 Jun 2018
    6.1
    Medium

    CVE-2018-11553

    Last Modified: 21 Nov 2024

    SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php.

    Published: 6 Jun 2018
    9.1
    Critical

    CVE-2018-11808

    Last Modified: 21 Nov 2024

    Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to delete any file and read certain files on the server in the context of the user (which by default is "NT AUTHORITY / SYSTEM") by sending a specially crafted request to the server.

    Published: 6 Jun 2018
    7.5
    High

    CVE-2018-11813

    Last Modified: 21 Nov 2024

    libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.

    Published: 6 Jun 2018
    5.9
    Medium

    CVE-2018-10850

    Last Modified: 21 Nov 2024

    389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load. An anonymous attacker could use this flaw to trigger a denial of service.

    Published: 6 Jun 2018