CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-13347

    Last Modified: 21 Nov 2024

    mpatch.c in Mercurial before 4.6.1 mishandles integer addition and subtraction, aka OVE-20180430-0002.

    Published: 6 Jun 2018
    6.5
    Medium

    CVE-2018-6148

    Last Modified: 21 Nov 2024

    Incorrect implementation in Content Security Policy in Google Chrome prior to 67.0.3396.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 6 Jun 2018
    7.5
    High

    CVE-2018-13346

    Last Modified: 21 Nov 2024

    The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of the original data, aka OVE-20180430-0004.

    Published: 6 Jun 2018
    7.5
    High

    CVE-2017-16099

    Last Modified: 21 Nov 2024

    The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed into no-case it can block the event loop causing a denial of service condition.

    Published: 6 Jun 2018
    7.5
    High

    CVE-2018-13348

    Last Modified: 21 Nov 2024

    The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data, but actually are not, aka OVE-20180430-0001.

    Published: 6 Jun 2018
    8.1
    High

    CVE-2018-1000197

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users with Overall/Read permission to read and write the Black Duck Hub plugin configuration.

    Published: 5 Jun 2018
    6.5
    Medium

    CVE-2018-10057

    Last Modified: 21 Nov 2024

    The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to write the miner configuration file to arbitrary locations on the server due to missing basedir restrictions (absolute directory traversal).

    Published: 5 Jun 2018
    8.8
    High

    CVE-2018-10058

    Last Modified: 21 Nov 2024

    The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers.

    Published: 5 Jun 2018
    7.8
    High

    CVE-2018-7884

    Last Modified: 21 Nov 2024

    An issue was discovered in DisplayLink Core Software Cleaner Application 8.2.1956. When the drivers are updated to a newer version, the product launches a process as SYSTEM to uninstall the old version: cl_1956.exe is run as SYSTEM on the %systemroot%\Temp folder, where any user can write a DLL (e.g., version.dll) to perform DLL Hijacking and elevate privileges to SYSTEM.

    Published: 5 Jun 2018
    9.8
    Critical

    CVE-2017-7637

    Last Modified: 21 Nov 2024

    QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to run arbitrary OS commands against the system with root privileges.

    Published: 5 Jun 2018
    6.5
    Medium

    CVE-2018-1000198

    Last Modified: 21 Nov 2024

    A XML external entity processing vulnerability exists in Jenkins Black Duck Hub Plugin 3.1.0 and older in PostBuildScanDescriptor.java that allows attackers with Overall/Read permission to make Jenkins process XML eternal entities in an XML document.

    Published: 5 Jun 2018
    5.4
    Medium

    CVE-2018-1000202

    Last Modified: 21 Nov 2024

    A persisted cross-site scripting vulnerability exists in Jenkins Groovy Postbuild Plugin 2.3.1 and older in various Jelly files that allows attackers able to control build badge content to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.

    Published: 5 Jun 2018
    9.8
    Critical

    CVE-2018-11586

    Last Modified: 21 Nov 2024

    XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

    Published: 5 Jun 2018
    4.7
    Medium

    CVE-2018-3691

    Last Modified: 21 Nov 2024

    Some implementations in Intel Integrated Performance Primitives Cryptography Library before version 2018 U3.1 do not properly ensure constant execution time.

    Published: 5 Jun 2018
    8.8
    High

    CVE-2017-7635

    Last Modified: 21 Nov 2024

    QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections.

    Published: 5 Jun 2018
    6.1
    Medium

    CVE-2017-7636

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to inject arbitrary web script or HTML.

    Published: 5 Jun 2018
    5.3
    Medium

    CVE-2017-7639

    Last Modified: 21 Nov 2024

    QNAP NAS application Proxy Server through version 1.2.0 does not authenticate requests properly. Successful exploitation can lead to change of the settings of Proxy Server.

    Published: 5 Jun 2018
    6.5
    Medium

    CVE-2018-1000196

    Last Modified: 21 Nov 2024

    A exposure of sensitive information vulnerability exists in Jenkins Gitlab Hook Plugin 1.4.2 and older in gitlab_notifier.rb, views/gitlab_notifier/global.erb that allows attackers with local Jenkins master file system access or control of a Jenkins administrator's web browser (e.g. malicious extension) to retrieve the configured Gitlab token.

    Published: 5 Jun 2018
    6.5
    Medium

    CVE-2018-1000186

    Last Modified: 21 Nov 2024

    A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 5 Jun 2018
    5.4
    Medium

    CVE-2018-1000188

    Last Modified: 21 Nov 2024

    A server-side request forgery vulnerability exists in Jenkins CAS Plugin 1.4.1 and older in CasSecurityRealm.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.

    Published: 5 Jun 2018
    8.3
    High

    CVE-2018-10597

    Last Modified: 21 Nov 2024

    IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that allows an unauthenticated attacker to access memory ("write-what-where") from an attacker-chosen device address within the same subnet.

    Published: 5 Jun 2018
    8.8
    High

    CVE-2018-1000189

    Last Modified: 21 Nov 2024

    A command execution vulnerability exists in Jenkins Absint Astree Plugin 1.0.5 and older in AstreeBuilder.java that allows attackers with Overall/Read access to execute a command on the Jenkins master.

    Published: 5 Jun 2018
    6.5
    Medium

    CVE-2018-1000190

    Last Modified: 21 Nov 2024

    A exposure of sensitive information vulnerability exists in Jenkins Black Duck Hub Plugin 4.0.0 and older in PostBuildScanDescriptor.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 5 Jun 2018
    5.3
    Medium

    CVE-2018-10599

    Last Modified: 21 Nov 2024

    IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that allows an unauthenticated attacker to read memory from an attacker-chosen device address within the same subnet.

    Published: 5 Jun 2018
    7.5
    High

    CVE-2017-7654

    Last Modified: 21 Nov 2024

    In Eclipse Mosquitto 1.4.15 and earlier, a Memory Leak vulnerability was found within the Mosquitto Broker. Unauthenticated clients can send crafted CONNECT packets which could cause a denial of service in the Mosquitto Broker.

    Published: 5 Jun 2018
    5.3
    Medium

    CVE-2017-7653

    Last Modified: 21 Nov 2024

    The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client could cause other clients that do reject invalid UTF-8 strings to disconnect themselves from the broker by sending a topic string which is not valid UTF-8, and so cause a denial of service for the clients.

    Published: 5 Jun 2018
    6.5
    Medium

    CVE-2018-1000191

    Last Modified: 21 Nov 2024

    A exposure of sensitive information vulnerability exists in Jenkins Black Duck Detect Plugin 1.4.0 and older in DetectPostBuildStepDescriptor.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 5 Jun 2018
    8.2
    High

    CVE-2018-10601

    Last Modified: 21 Nov 2024

    IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that exposes an "echo" service, in which an attacker-sent buffer to an attacker-chosen device address within the same subnet is copied to the stack with no boundary checks, hence resulting in stack overflow.

    Published: 5 Jun 2018
    5.5
    Medium

    CVE-2018-8008

    Last Modified: 21 Nov 2024

    Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.

    Published: 5 Jun 2018
    6.5
    Medium

    CVE-2018-1332

    Last Modified: 21 Nov 2024

    Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose a vulnerability that could allow a user to impersonate another user when communicating with some Storm Daemons.

    Published: 5 Jun 2018
    5.9
    Medium

    CVE-2018-1454

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 140089.

    Published: 5 Jun 2018
    8.4
    High

    CVE-2017-1350

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 could allow a user to escalate their privileges to administrator due to improper access controls. IBM X-Force ID: 126526.

    Published: 5 Jun 2018
    7.3
    High

    CVE-2018-10813

    Last Modified: 21 Nov 2024

    In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie and re-sign it using the hardcoded secret. Due to the use of Passport.js, this could lead to privilege escalation.

    Published: 5 Jun 2018
    7.3
    High

    CVE-2018-10966

    Last Modified: 21 Nov 2024

    An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the Passport.js contents of the session cookie to contain the ID number of the account they wish to take over, and re-sign it using the hard coded secret.

    Published: 5 Jun 2018
    6.1
    Medium

    CVE-2018-1432

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to cross-frame scripting which is a vulnerability that allows an attacker to load Information Server components inside an HTML iframe tag on a malicious page. The attacker could use this weakness to devise a Clickjacking attack to conduct phishing, frame sniffing, social engineering or Cross-Site Request Forgery attacks. IBM X-Force ID: 139360.

    Published: 5 Jun 2018
    8.8
    High

    CVE-2018-7943

    Last Modified: 21 Nov 2024

    There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass the authentication by some special operations. Due to insufficient authentication, an attacker may exploit the vulnerability to get some sensitive information and high-level users' privilege.

    Published: 5 Jun 2018
    7.8
    High

    CVE-2018-6662

    Last Modified: 21 Nov 2024

    Privilege Escalation vulnerability in McAfee Management of Native Encryption (MNE) before 4.1.4 allows local users to gain elevated privileges via a crafted user input.

    Published: 5 Jun 2018
    6.5
    Medium

    CVE-2018-8923

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology File Station before 1.1.4-0122 allows remote authenticated users to inject arbitrary web script or HTML via malicious attachments.

    Published: 5 Jun 2018
    6.5
    Medium

    CVE-2018-8924

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Title Tootip in Synology Office before 3.0.3-2143 allows remote authenticated users to inject arbitrary web script or HTML via the malicious file name.

    Published: 5 Jun 2018
    6.1
    Medium

    CVE-2016-9490

    Last Modified: 21 Nov 2024

    ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Manager is prone to a Cross-Site Scripting vulnerability in parameter LIMIT, in URL path /DiagAlertAction.do?REQTYPE=AJAX&LIMIT=1233. The URL is also available without authentication.

    Published: 5 Jun 2018
    9.8
    Critical

    CVE-2016-9488

    Last Modified: 21 Nov 2024

    ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users' password hashes, which are MD5 hashes without salt, and, depending on the database type and its configuration, could also execute operating system commands using SQL queries.

    Published: 5 Jun 2018
    7.5
    High

    CVE-2018-1000181

    Last Modified: 21 Nov 2024

    Kitura 2.3.0 and earlier have an unintended read access to unauthorised files and folders that can be exploited by a crafted URL resulting in information disclosure.

    Published: 5 Jun 2018
    9.8
    Critical

    CVE-2018-11743

    Last Modified: 21 Nov 2024

    The init_copy function in kernel.c in mruby 1.4.1 makes initialize_copy calls for TT_ICLASS objects, which allows attackers to cause a denial of service (mrb_hash_keys uninitialized pointer and application crash) or possibly have unspecified other impact.

    Published: 5 Jun 2018
    9.8
    Critical

    CVE-2018-11722

    Last Modified: 21 Nov 2024

    WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded.

    Published: 5 Jun 2018
    8.8
    High

    CVE-2018-1252

    Last Modified: 21 Nov 2024

    RSA Web Threat Detection versions prior to 6.4, contain an SQL injection vulnerability in the Administration and Forensics applications. An authenticated malicious user with low privileges could potentially exploit this vulnerability to execute SQL commands on the back-end database to gain unauthorized access to the tool's monitoring and user information by supplying specially crafted input data to the affected application.

    Published: 5 Jun 2018
    9.8
    Critical

    CVE-2018-11554

    Last Modified: 21 Nov 2024

    The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Discrepancy Information Exposure issue and an unexpectedly long lifetime for a verification code, which makes it easier for remote attackers to hijack accounts via a brute-force approach.

    Published: 5 Jun 2018
    9.8
    Critical

    CVE-2018-11678

    Last Modified: 21 Nov 2024

    plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.

    Published: 5 Jun 2018
    8.1
    High

    CVE-2018-11739

    Last Modified: 21 Nov 2024

    An issue was discovered in libtskimg.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function raw_read in tsk/img/raw.c which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service attack.

    Published: 5 Jun 2018
    8.1
    High

    CVE-2018-11740

    Last Modified: 21 Nov 2024

    An issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function tsk_UTF16toUTF8 in tsk/base/tsk_unicode.c which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service attack.

    Published: 5 Jun 2018
    8.1
    High

    CVE-2018-11737

    Last Modified: 21 Nov 2024

    An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function ntfs_fix_idxrec in tsk/fs/ntfs_dent.cpp which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.

    Published: 5 Jun 2018