CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2018-11738

    Last Modified: 21 Nov 2024

    An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function ntfs_make_data_run in tsk/fs/ntfs.c which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service attack.

    Published: 5 Jun 2018
    6.1
    Medium

    CVE-2018-11735

    Last Modified: 21 Nov 2024

    index.php?action=createaccount in Ximdex 4.0 has XSS via the sname or fname parameter.

    Published: 5 Jun 2018
    9.8
    Critical

    CVE-2018-11736

    Last Modified: 21 Nov 2024

    An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file.

    Published: 5 Jun 2018
    5.4
    Medium

    CVE-2017-18286

    Last Modified: 21 Nov 2024

    nZEDb v0.7.3.3 has XSS in the 404 error page.

    Published: 5 Jun 2018
    9.8
    Critical

    CVE-2018-1000544

    Last Modified: 21 Nov 2024

    rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..

    Published: 5 Jun 2018
    5.5
    Medium

    CVE-2018-1002201

    Last Modified: 21 Nov 2024

    zt-zip before 1.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

    Published: 5 Jun 2018
    6.5
    Medium

    CVE-2018-1002202

    Last Modified: 21 Nov 2024

    zip4j before 1.3.3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

    Published: 5 Jun 2018
    7
    High

    CVE-2018-10853

    Last Modified: 21 Nov 2024

    A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current privilege(CPL) level while emulating unprivileged instructions. An unprivileged guest user/process could use this flaw to potentially escalate privileges inside guest.

    Published: 5 Jun 2018
    8.8
    High

    CVE-2018-12027

    Last Modified: 21 Nov 2024

    An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said socket are writable by a normal user that is not the application's user, then that non-application user can swap that directory with something else, resulting in traffic being redirected to a non-application user's process through an alternative Unix domain socket.

    Published: 5 Jun 2018
    7.8
    High

    CVE-2018-12028

    Last Modified: 21 Nov 2024

    An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious application then generates an error, it would cause Passenger's process manager to kill said reported arbitrary PID.

    Published: 5 Jun 2018
    8.8
    High

    CVE-2018-12085

    Last Modified: 21 Nov 2024

    Liblouis 3.6.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440.

    Published: 5 Jun 2018
    8.8
    High

    CVE-2018-8009

    Last Modified: 21 Nov 2024

    Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that accept a zip file.

    Published: 5 Jun 2018
    5.5
    Medium

    CVE-2019-0161

    Last Modified: 21 Nov 2024

    Stack overflow in XHCI for EDK II may allow an unauthenticated user to potentially enable denial of service via local access.

    Published: 5 Jun 2018
    5.5
    Medium

    CVE-2018-1002200

    Last Modified: 21 Nov 2024

    plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

    Published: 5 Jun 2018
    8.2
    High

    CVE-2018-11806

    Last Modified: 21 Nov 2024

    m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.

    Published: 5 Jun 2018
    9.8
    Critical

    CVE-2018-12026

    Last Modified: 21 Nov 2024

    During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads and writes, which in turn can result in information disclosure and privilege escalation.

    Published: 5 Jun 2018
    7
    High

    CVE-2018-12029

    Last Modified: 21 Nov 2024

    A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but before it was chowned, leads to the target of the link being chowned via the path. Targeting sensitive files such as root's crontab file allows privilege escalation.

    Published: 5 Jun 2018
    5.5
    Medium

    CVE-2018-8026

    Last Modified: 21 Nov 2024

    This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.xml, enumsConfig.xml referred from schema.xml, TIKA parsecontext config file). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network. The manipulated files can be uploaded as configsets using Solr's API, allowing to exploit that vulnerability.

    Published: 5 Jun 2018
    8.8
    High

    CVE-2018-3853

    Last Modified: 21 Nov 2024

    An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software Foxit PDF Reader version 9.0.1.1049. A specially crafted PDF document can trigger a previously freed object in memory to be reused resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

    Published: 4 Jun 2018
    3.7
    Low

    CVE-2017-12092

    Last Modified: 21 Nov 2024

    An exploitable file write vulnerability exists in the memory module functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a file write resulting in a new program being written to the memory module. An attacker can send an unauthenticated packet to trigger this vulnerability.

    Published: 4 Jun 2018
    7.8
    High

    CVE-2016-8390

    Last Modified: 21 Nov 2024

    An exploitable out of bounds write vulnerability exists in the parsing of ELF Section Headers of Hopper Disassembler 3.11.20. A specially crafted ELF file can cause attacker controlled pointer arithmetic resulting in a partially controlled out of bounds write. An attacker can craft an ELF file with specific section headers to trigger this vulnerability.

    Published: 4 Jun 2018
    8.1
    High

    CVE-2016-10695

    Last Modified: 21 Nov 2024

    The npm-test-sqlite3-trunk module provides asynchronous, non-blocking SQLite3 bindings. npm-test-sqlite3-trunk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.

    Published: 4 Jun 2018
    6.1
    Medium

    CVE-2017-16008

    Last Modified: 21 Nov 2024

    i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one at a time, untrusted user input can use the name of one of the dictionary keys to inject script into the browser. This affects i18next <=1.10.2.

    Published: 4 Jun 2018
    6.1
    Medium

    CVE-2017-16009

    Last Modified: 21 Nov 2024

    ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag-grid.

    Published: 4 Jun 2018
    6.1
    Medium

    CVE-2017-16016

    Last Modified: 21 Nov 2024

    Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cross site scripting (XSS) in certain scenarios: If allowed at least one nonTextTags, the result is a potential XSS vulnerability.

    Published: 4 Jun 2018
    6.1
    Medium

    CVE-2017-16022

    Last Modified: 21 Nov 2024

    Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not escaped in versions 0.5.0 and earlier. If control over the labels is obtained, script can be injected. The script will run on the client side whenever that specific graph is loaded.

    Published: 4 Jun 2018
    7.5
    High

    CVE-2017-16055

    Last Modified: 21 Nov 2024

    `sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 4 Jun 2018
    6.1
    Medium

    CVE-2017-16017

    Last Modified: 21 Nov 2024

    sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scripting vulnerability.

    Published: 4 Jun 2018
    8.1
    High

    CVE-2017-16040

    Last Modified: 21 Nov 2024

    gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.

    Published: 4 Jun 2018
    7.5
    High

    CVE-2017-16048

    Last Modified: 21 Nov 2024

    `node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 4 Jun 2018
    8.1
    High

    CVE-2016-10696

    Last Modified: 21 Nov 2024

    windows-latestchromedriver downloads the latest version of chromedriver.exe. windows-latestchromedriver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.

    Published: 4 Jun 2018
    8.1
    High

    CVE-2016-10697

    Last Modified: 21 Nov 2024

    react-native-baidu-voice-synthesizer is a baidu voice speech synthesizer for react native. react-native-baidu-voice-synthesizer downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.

    Published: 4 Jun 2018
    6.1
    Medium

    CVE-2017-0928

    Last Modified: 21 Nov 2024

    html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variable causing sanitization to be bypassed.

    Published: 4 Jun 2018
    6.5
    Medium

    CVE-2017-0930

    Last Modified: 21 Nov 2024

    augustine node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path.

    Published: 4 Jun 2018
    6.1
    Medium

    CVE-2017-0931

    Last Modified: 21 Nov 2024

    html-janitor node module suffers from a Cross-Site Scripting (XSS) vulnerability via clean() accepting user-controlled values.

    Published: 4 Jun 2018
    7.5
    High

    CVE-2017-16005

    Last Modified: 21 Nov 2024

    Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he can swap header names and change the meaning of the request without changing the signature.

    Published: 4 Jun 2018
    6.1
    Medium

    CVE-2017-16006

    Last Modified: 21 Nov 2024

    Remarkable is a markdown parser. In versions 1.6.2 and lower, remarkable allows the use of `data:` URIs in links and can therefore execute javascript.

    Published: 4 Jun 2018
    5.9
    Medium

    CVE-2017-16007

    Last Modified: 21 Nov 2024

    node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and node.js-based servers. node-jose earlier than version 0.9.3 is vulnerable to an invalid curve attack. This allows an attacker to recover the private secret key when JWE with Key Agreement with Elliptic Curve Diffie-Hellman Ephemeral Static (ECDH-ES) is used.

    Published: 4 Jun 2018
    Unknown

    CVE-2017-16011

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6708. Reason: This candidate is a duplicate of CVE-2012-6708. Notes: All CVE users should reference CVE-2012-6708 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 4 Jun 2018
    7.5
    High

    CVE-2017-16013

    Last Modified: 21 Nov 2024

    hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception is thrown. This may cause hapi to crash or to hang the client connection until the timeout period is reached.

    Published: 4 Jun 2018
    6.1
    Medium

    CVE-2017-16015

    Last Modified: 21 Nov 2024

    Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means that if the application did not sanitize html on behalf of forms, use of forms may be vulnerable to cross site scripting

    Published: 4 Jun 2018
    6.1
    Medium

    CVE-2017-16018

    Last Modified: 21 Nov 2024

    Restify is a framework for building REST APIs. Restify >=2.0.0 <=4.0.4 using URL encoded script tags in a non-existent URL, an attacker can get script to run in some browsers.

    Published: 4 Jun 2018
    6.1
    Medium

    CVE-2017-16019

    Last Modified: 21 Nov 2024

    GitBook is a command line tool (and Node.js library) for building beautiful books using GitHub/Git and Markdown (or AsciiDoc). Stored Cross-Site-Scripting (XSS) is possible in GitBook before 3.2.2 by including code outside of backticks in any ebook. This code will be executed on the online reader.

    Published: 4 Jun 2018
    9.8
    Critical

    CVE-2017-16020

    Last Modified: 21 Nov 2024

    Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.

    Published: 4 Jun 2018
    6.5
    Medium

    CVE-2017-16024

    Last Modified: 21 Nov 2024

    The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp directory, possibly allowing an attacker on the server to obtain confidential information from the buffer/tmp file, while it exists.

    Published: 4 Jun 2018
    5.9
    Medium

    CVE-2017-16025

    Last Modified: 21 Nov 2024

    Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerability via an invalid Cookie header. This is only present when websocket authentication is set to `cookie`. Submitting an invalid cookie on the websocket upgrade request will cause the node process to error out.

    Published: 4 Jun 2018
    5.3
    Medium

    CVE-2017-16028

    Last Modified: 21 Nov 2024

    react-native-meteor-oauth is a library for Oauth2 login to a Meteor server in React Native. The oauth Random Token is generated using a non-cryptographically strong RNG (Math.random()).

    Published: 4 Jun 2018
    7.5
    High

    CVE-2017-16029

    Last Modified: 21 Nov 2024

    hostr is a simple web server that serves up the contents of the current directory. There is a directory traversal vulnerability in hostr 2.3.5 and earlier that allows an attacker to read files outside the current directory by sending `../` in the url path for GET requests.

    Published: 4 Jun 2018
    7.5
    High

    CVE-2017-16036

    Last Modified: 21 Nov 2024

    `badjs-sourcemap-server` receives files sent by `badjs-sourcemap`. `badjs-sourcemap-server` is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 4 Jun 2018
    7.5
    High

    CVE-2017-16037

    Last Modified: 21 Nov 2024

    `gomeplus-h5-proxy` is vulnerable to a directory traversal issue, allowing attackers to access any file in the system by placing '../' in the URL.

    Published: 4 Jun 2018