CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2016-10687

    Last Modified: 21 Nov 2024

    windows-selenium-chromedriver is a module that downloads the Selenium Jar file. windows-selenium-chromedriver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.

    Published: 4 Jun 2018
    8.1
    High

    CVE-2016-10688

    Last Modified: 21 Nov 2024

    Haxe 3 : The Cross-Platform Toolkit (a fork from David Mouton's damoebius/haxe-npm) haxe3 downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.

    Published: 4 Jun 2018
    8.1
    High

    CVE-2016-10689

    Last Modified: 21 Nov 2024

    The windows-iedriver module downloads fixed version of iedriverserver.exe windows-iedriver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.

    Published: 4 Jun 2018
    8.1
    High

    CVE-2016-10692

    Last Modified: 21 Nov 2024

    haxeshim haxe shim to deal with coexisting versions. haxeshim downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.

    Published: 4 Jun 2018
    8.1
    High

    CVE-2016-10693

    Last Modified: 21 Nov 2024

    pm2-kafka is a PM2 module that installs and runs a kafka server pm2-kafka downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.

    Published: 4 Jun 2018
    9.8
    Critical

    CVE-2018-10611

    Last Modified: 21 Nov 2024

    Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unauthenticated users to launch applications and support remote code execution through web services.

    Published: 4 Jun 2018
    7.5
    High

    CVE-2018-10613

    Last Modified: 21 Nov 2024

    Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior.

    Published: 4 Jun 2018
    7.5
    High

    CVE-2018-11712

    Last Modified: 21 Nov 2024

    WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ versions 2.20.0 and 2.20.1, failed to perform TLS certificate verification for WebSocket connections.

    Published: 4 Jun 2018
    9.8
    Critical

    CVE-2018-11714

    Last Modified: 21 Nov 2024

    An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action.

    Published: 4 Jun 2018
    8.1
    High

    CVE-2018-10615

    Last Modified: 21 Nov 2024

    Directory traversal may lead to files being exfiltrated or deleted on the GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior host platform.

    Published: 4 Jun 2018
    6.5
    Medium

    CVE-2018-11713

    Last Modified: 21 Nov 2024

    WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy settings for WebSocket connections. As a result, users could be deanonymized by crafted web sites via a WebSocket connection.

    Published: 4 Jun 2018
    6.1
    Medium

    CVE-2018-11709

    Last Modified: 21 Nov 2024

    wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.

    Published: 4 Jun 2018
    5.3
    Medium

    CVE-2016-1000339

    Last Modified: 12 May 2025

    In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven approach used in the algorithm it turns out that if the data channel on the CPU can be monitored the lookup table accesses are sufficient to leak information on the AES key being used. There was also a leak in AESEngine although it was substantially less. AESEngine has been modified to remove any signs of leakage (testing carried out on Intel X86-64) and is now the primary AES class for the BC JCE provider from 1.56. Use of AESFastEngine is now only recommended where otherwise deemed appropriate.

    Published: 4 Jun 2018
    7.5
    High

    CVE-2016-1000340

    Last Modified: 12 May 2025

    In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in the implementation of squaring for several raw math classes have been fixed (org.bouncycastle.math.raw.Nat???). These classes are used by our custom elliptic curve implementations (org.bouncycastle.math.ec.custom.**), so there was the possibility of rare (in general usage) spurious calculations for elliptic curve scalar multiplications. Such errors would have been detected with high probability by the output validation for our scalar multipliers.

    Published: 4 Jun 2018
    5.9
    Medium

    CVE-2016-1000341

    Last Modified: 12 May 2025

    In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack. Where timings can be closely observed for the generation of signatures, the lack of blinding in 1.55, or earlier, may allow an attacker to gain information about the signature's k value and ultimately the private value as well.

    Published: 4 Jun 2018
    7.5
    High

    CVE-2016-1000342

    Last Modified: 12 May 2025

    In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a signed structure.

    Published: 4 Jun 2018
    7.5
    High

    CVE-2016-1000343

    Last Modified: 12 May 2025

    In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator.

    Published: 4 Jun 2018
    8.8
    High

    CVE-2018-11710

    Last Modified: 21 Nov 2024

    soundlib/pattern.h in libopenmpt before 0.3.9 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted AMS file because of an invalid write near address 0 in an out-of-memory situation.

    Published: 4 Jun 2018
    9.8
    Critical

    CVE-2018-11711

    Last Modified: 21 Nov 2024

    A remote attacker can bypass the System Manager Mode on the Canon MF210 and MF220 web interface without knowing the PIN for /login.html via vectors involving /portal_top.html to get full access to the device. NOTE: the vendor reportedly responded that this issue occurs when a customer keeps the default settings without using the countermeasures and best practices shown in the documentation

    Published: 4 Jun 2018
    Unknown

    CVE-2018-10761

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 4 Jun 2018
    Unknown

    CVE-2018-10762

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 4 Jun 2018
    8.8
    High

    CVE-2018-11683

    Last Modified: 21 Nov 2024

    Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440.

    Published: 4 Jun 2018
    8.8
    High

    CVE-2018-11684

    Last Modified: 21 Nov 2024

    Liblouis 3.5.0 has a stack-based Buffer Overflow in the function includeFile in compileTranslationTable.c.

    Published: 4 Jun 2018
    9.8
    Critical

    CVE-2018-11692

    Last Modified: 21 Nov 2024

    An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode authentication for /tlogin.cgi via vectors involving frame.cgi?page=DevStatus. NOTE: the vendor reportedly responded that this issue occurs when a customer keeps the default settings without using the countermeasures and best practices shown in the documentation

    Published: 4 Jun 2018
    8.1
    High

    CVE-2018-11693

    Last Modified: 21 Nov 2024

    An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::skip_over_scopes which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.

    Published: 4 Jun 2018
    8.8
    High

    CVE-2018-11695

    Last Modified: 21 Nov 2024

    An issue was discovered in LibSass <3.5.3. A NULL pointer dereference was found in the function Sass::Expand::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 4 Jun 2018
    8.1
    High

    CVE-2018-11697

    Last Modified: 21 Nov 2024

    An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::exactly() which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.

    Published: 4 Jun 2018
    8.1
    High

    CVE-2018-11698

    Last Modified: 21 Nov 2024

    An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::handle_error which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.

    Published: 4 Jun 2018
    Unknown

    CVE-2018-9994

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 4 Jun 2018
    8.8
    High

    CVE-2018-11685

    Last Modified: 21 Nov 2024

    Liblouis 3.5.0 has a stack-based Buffer Overflow in the function compileHyphenation in compileTranslationTable.c.

    Published: 4 Jun 2018
    8.8
    High

    CVE-2018-11696

    Last Modified: 21 Nov 2024

    An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Inspect::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 4 Jun 2018
    7.1
    High

    CVE-2017-18285

    Last Modified: 21 Nov 2024

    The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain read and write access to arbitrary files by leveraging access to a certain account for a burp-server.conf change.

    Published: 4 Jun 2018
    7.1
    High

    CVE-2017-18284

    Last Modified: 21 Nov 2024

    The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL.

    Published: 4 Jun 2018
    8.8
    High

    CVE-2018-11694

    Last Modified: 21 Nov 2024

    An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Functions::selector_append which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 4 Jun 2018
    5.4
    Medium

    CVE-2018-1000184

    Last Modified: 21 Nov 2024

    A server-side request forgery vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubPluginConfig.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.

    Published: 4 Jun 2018
    4.3
    Medium

    CVE-2018-1000185

    Last Modified: 21 Nov 2024

    A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.

    Published: 4 Jun 2018
    6.5
    Medium

    CVE-2018-1000187

    Last Modified: 21 Nov 2024

    A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in sensitive variables such as passwords being written to logs.

    Published: 4 Jun 2018
    6.4
    Medium

    CVE-2018-1000182

    Last Modified: 21 Nov 2024

    A server-side request forgery vulnerability exists in Jenkins Git Plugin 3.9.0 and older in AssemblaWeb.java, GitBlitRepositoryBrowser.java, Gitiles.java, TFS2013GitRepositoryBrowser.java, ViewGitWeb.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.

    Published: 4 Jun 2018
    5.9
    Medium

    CVE-2018-12232

    Last Modified: 21 Nov 2024

    In net/socket.c in the Linux kernel through 4.17.1, there is a race condition between fchownat and close in cases where they target the same socket file descriptor, related to the sock_close and sockfs_setattr functions. fchownat does not increment the file descriptor reference count, which allows close to set the socket to NULL during fchownat's execution, leading to a NULL pointer dereference and system crash.

    Published: 4 Jun 2018
    6.5
    Medium

    CVE-2018-1000183

    Last Modified: 21 Nov 2024

    A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubServerConfig.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 4 Jun 2018
    9.8
    Critical

    CVE-2018-12882

    Last Modified: 21 Nov 2024

    exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it closes a stream that it is not responsible for closing. The vulnerable code is reachable through the PHP exif_read_data function.

    Published: 3 Jun 2018
    5.5
    Medium

    CVE-2018-13095

    Last Modified: 21 Nov 2024

    An issue was discovered in fs/xfs/libxfs/xfs_inode_buf.c in the Linux kernel through 4.17.3. A denial of service (memory corruption and BUG) can occur for a corrupted xfs image upon encountering an inode that is in extent format, but has more extents than fit in the inode fork.

    Published: 3 Jun 2018
    6.5
    Medium

    CVE-2018-20822

    Last Modified: 21 Nov 2024

    LibSass 3.5.4 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Complex_Selector::perform in ast.hpp and Sass::Inspect::operator in inspect.cpp).

    Published: 3 Jun 2018
    9.8
    Critical

    CVE-2018-11682

    Last Modified: 21 Nov 2024

    Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to products using the Stanza Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a vulnerability because what can be done through the ports revolve around controlling lighting, not code execution. A certain set of commands are listed, which bear some similarity to code, but they are not arbitrary and do not allow admin-level control of a machine

    Published: 2 Jun 2018
    9.8
    Critical

    CVE-2018-11629

    Last Modified: 21 Nov 2024

    Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the HomeWorks QS Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a vulnerability because what can be done through the ports revolve around controlling lighting, not code execution. A certain set of commands are listed, which bear some similarity to code, but they are not arbitrary and do not allow admin-level control of a machine

    Published: 2 Jun 2018
    9.8
    Critical

    CVE-2018-11681

    Last Modified: 21 Nov 2024

    Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the RadioRA 2 Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a vulnerability because what can be done through the ports revolve around controlling lighting, not code execution. A certain set of commands are listed, which bear some similarity to code, but they are not arbitrary and do not allow admin-level control of a machine

    Published: 2 Jun 2018
    8.8
    High

    CVE-2018-11679

    Last Modified: 21 Nov 2024

    An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability that can add an article via /index.php?case=table&act=add&table=archive&admin_dir=admin.

    Published: 2 Jun 2018
    6.5
    Medium

    CVE-2018-11680

    Last Modified: 21 Nov 2024

    An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability in the rich text editor that can add an IFRAME element. This might be used in a DoS attack if a referenced remote URL is refreshed at a rapid rate.

    Published: 2 Jun 2018
    6.5
    Medium

    CVE-2018-19839

    Last Modified: 21 Nov 2024

    In LibSass prior to 3.5.5, the function handle_error in sass_context.cpp allows attackers to cause a denial-of-service resulting from a heap-based buffer over-read via a crafted sass file.

    Published: 2 Jun 2018
    6.5
    Medium

    CVE-2018-20821

    Last Modified: 21 Nov 2024

    The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Parser::parse_css_variable_value in parser.cpp).

    Published: 2 Jun 2018