CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2016-10616

    Last Modified: 21 Nov 2024

    openframe-image is an Openframe extension which adds support for images via fbi. openframe-image downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10617

    Last Modified: 21 Nov 2024

    box2d-native downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10622

    Last Modified: 21 Nov 2024

    nodeschnaps is a NodeJS compatibility layer for Java (Rhino). nodeschnaps downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10623

    Last Modified: 21 Nov 2024

    macaca-chromedriver-zxa is a Node.js wrapper for the selenium chromedriver. macaca-chromedriver-zxa downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10628

    Last Modified: 21 Nov 2024

    selenium-wrapper is a selenium server wrapper, including installation and chrome webdriver. selenium-wrapper downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10629

    Last Modified: 21 Nov 2024

    nw-with-arm is a NW Installer including ARM-Build. nw-with-arm downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10633

    Last Modified: 21 Nov 2024

    dwebp-bin is a dwebp node.js wrapper that convert WebP into PNG. dwebp-bin downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    8.1
    High

    CVE-2016-10634

    Last Modified: 21 Nov 2024

    scala-standalone-bin is a Binary wrapper for ScalaJS. scala-standalone-bin downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 1 Jun 2018
    5.4
    Medium

    CVE-2018-10382

    Last Modified: 21 Nov 2024

    MODX Revolution 2.6.3 has XSS.

    Published: 1 Jun 2018
    4.8
    Medium

    CVE-2018-11581

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability on Brother HL series printers allows remote attackers to inject arbitrary web script or HTML via the url parameter to etc/loginerror.html.

    Published: 1 Jun 2018
    8.8
    High

    CVE-2018-11671

    Last Modified: 21 Nov 2024

    An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php?m=admin&c=access&a=adduserhandle.

    Published: 1 Jun 2018
    Unknown

    CVE-2018-3742

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-3745. Reason: This candidate is a reservation duplicate of CVE-2018-3745. Notes: All CVE users should reference CVE-2018-3745 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 Jun 2018
    6.1
    Medium

    CVE-2018-3743

    Last Modified: 21 Nov 2024

    Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server.

    Published: 1 Jun 2018
    9.8
    Critical

    CVE-2018-3746

    Last Modified: 21 Nov 2024

    The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim's machine.

    Published: 1 Jun 2018
    6.1
    Medium

    CVE-2018-3755

    Last Modified: 21 Nov 2024

    XSS in sexstatic <=0.6.2 causes HTML injection in directory name(s) leads to Stored XSS when malicious file is embed with <iframe> element used in directory name.

    Published: 1 Jun 2018
    7.8
    High

    CVE-2018-11551

    Last Modified: 21 Nov 2024

    AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability exists because a DLL file is loaded by 'pbxsetup.exe' improperly.

    Published: 1 Jun 2018
    8.8
    High

    CVE-2018-11670

    Last Modified: 21 Nov 2024

    An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary PHP code via the content parameter to index.php?m=admin&c=media&a=fileconnect.

    Published: 1 Jun 2018
    6.1
    Medium

    CVE-2018-11552

    Last Modified: 21 Nov 2024

    There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field. The vulnerability exists due to insufficient filtration of user-supplied data. A remote attacker can execute arbitrary HTML and script code in a browser in the context of the vulnerable application.

    Published: 1 Jun 2018
    6.1
    Medium

    CVE-2018-11628

    Last Modified: 21 Nov 2024

    Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malicious attackers to send a crafted URL for XSS.

    Published: 1 Jun 2018
    7.5
    High

    CVE-2018-11657

    Last Modified: 21 Nov 2024

    ngiflib.c in MiniUPnP ngiflib 0.4 has an infinite loop in DecodeGifImg and LoadGif.

    Published: 1 Jun 2018
    7.5
    High

    CVE-2017-2852

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the unserialization of lists functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause an out-of-bounds read, resulting in a denial of service. An attacker can send a malicious packet to trigger this vulnerability.

    Published: 1 Jun 2018
    7.5
    High

    CVE-2017-2858

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the traversal of lists functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause an out-of-bounds read, resulting in a denial of service. An attacker can send a malicious packet to trigger this vulnerability.

    Published: 1 Jun 2018
    7.5
    High

    CVE-2017-2860

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the lookup entry functionality of KeyTrees in Natus Xltek NeuroWorks 8. A specially crafted network packet can cause an out-of-bounds read, resulting in a denial of service. An attacker can send a malicious packet to trigger this vulnerability.

    Published: 1 Jun 2018
    6.1
    Medium

    CVE-2018-11485

    Last Modified: 21 Nov 2024

    The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.

    Published: 1 Jun 2018
    6.1
    Medium

    CVE-2018-11486

    Last Modified: 21 Nov 2024

    An issue was discovered in the MULTIDOTS Advance Search for WooCommerce plugin 1.0.9 and earlier for WordPress. This plugin is vulnerable to a stored Cross-site scripting (XSS) vulnerability. A non-authenticated user can save the plugin settings and inject malicious JavaScript code in the Custom CSS textarea field, which will be loaded on every site page.

    Published: 1 Jun 2018
    9.8
    Critical

    CVE-2018-11652

    Last Modified: 21 Nov 2024

    CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.

    Published: 1 Jun 2018
    6.1
    Medium

    CVE-2018-11649

    Last Modified: 21 Nov 2024

    Hue 3.12 has XSS via the /pig/save/ name and script parameters.

    Published: 1 Jun 2018
    6.1
    Medium

    CVE-2018-11650

    Last Modified: 21 Nov 2024

    Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.

    Published: 1 Jun 2018
    6.1
    Medium

    CVE-2018-11651

    Last Modified: 21 Nov 2024

    Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.

    Published: 1 Jun 2018
    7.5
    High

    CVE-2018-5513

    Last Modified: 21 Nov 2024

    On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.3, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, a malformed TLS handshake causes TMM to crash leading to a disruption of service. This issue is only exposed on the data plane when Proxy SSL configuration is enabled. The control plane is not impacted by this issue.

    Published: 1 Jun 2018
    5.9
    Medium

    CVE-2018-5522

    Last Modified: 21 Nov 2024

    On F5 BIG-IP 13.0.0, 12.0.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, when processing DIAMETER transactions with carefully crafted attribute-value pairs, TMM may crash.

    Published: 1 Jun 2018
    5.3
    Medium

    CVE-2018-5524

    Last Modified: 21 Nov 2024

    Under certain conditions, on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.6.1 HF2-11.6.3.1, virtual servers configured with Client SSL or Server SSL profiles which make use of network hardware security module (HSM) functionality are exposed and impacted by this issue.

    Published: 1 Jun 2018
    6.5
    Medium

    CVE-2018-5526

    Last Modified: 21 Nov 2024

    Under certain conditions, on F5 BIG-IP ASM 13.1.0-13.1.0.5, Behavioral DOS (BADOS) protection may fail during an attack.

    Published: 1 Jun 2018
    8.8
    High

    CVE-2018-7950

    Last Modified: 21 Nov 2024

    The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Successful exploit may allow attackers to obtain the management privilege of the system.

    Published: 1 Jun 2018
    5.3
    Medium

    CVE-2017-6153

    Last Modified: 21 Nov 2024

    Features in F5 BIG-IP 13.0.0-13.1.0.3, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 system that utilizes inflate functionality directly, via an iRule, or via the inflate code from PEM module are subjected to a service disruption via a "Zip Bomb" attack.

    Published: 1 Jun 2018
    7.2
    High

    CVE-2018-5523

    Last Modified: 21 Nov 2024

    On F5 BIG-IP 13.1.0-13.1.0.3, 13.0.0, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 and Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.

    Published: 1 Jun 2018
    4.2
    Medium

    CVE-2017-17171

    Last Modified: 21 Nov 2024

    Some Huawei smart phones have the denial of service (DoS) vulnerability due to the improper processing of malicious parameters. An attacker may trick a target user into installing a malicious APK and launch attacks using a pre-installed app with specific permissions. Successful exploit could allow the app to send specific parameters to the smart phone driver, which will result in system restart.

    Published: 1 Jun 2018
    6.1
    Medium

    CVE-2018-5521

    Last Modified: 21 Nov 2024

    On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can be used to reflect arbitrary content into GeoIP lookup responses, potentially exposing clients to XSS.

    Published: 1 Jun 2018
    4.3
    Medium

    CVE-2018-5525

    Last Modified: 21 Nov 2024

    A local file vulnerability exists in the F5 BIG-IP Configuration utility on versions 13.0.0, 12.1.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 that exposes files containing F5-provided data only and do not include any configuration data, proxied traffic, or other potentially sensitive customer data.

    Published: 1 Jun 2018
    8.8
    High

    CVE-2018-7949

    Last Modified: 21 Nov 2024

    The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a privilege escalation vulnerability. A remote attacker may send some specially crafted login messages to the affected products. Due to improper authentication design, successful exploit enables low privileged users to get or modify passwords of highly privileged users.

    Published: 1 Jun 2018
    8.8
    High

    CVE-2018-7951

    Last Modified: 21 Nov 2024

    The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Successful exploit may allow attackers to obtain the management privilege of the system.

    Published: 1 Jun 2018
    5.4
    Medium

    CVE-2018-7976

    Last Modified: 21 Nov 2024

    There is a stored cross-site scripting (XSS) vulnerability in Huawei eSpace Desktop V300R001C00 and V300R001C50 version. Due to the insufficient validation of the input, an authenticated, remote attacker could exploit this vulnerability to send abnormal messages to the system and perform a XSS attack. A successful exploit could cause the eSpace Desktop to hang up, and the function will restore to normal after restarting the eSpace Desktop.

    Published: 1 Jun 2018
    6.5
    Medium

    CVE-2018-8921

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in File Sharing Notify Toast in Synology Drive before 1.0.2-10275 allows remote authenticated users to inject arbitrary web script or HTML via the malicious file name.

    Published: 1 Jun 2018
    6.5
    Medium

    CVE-2018-8922

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access non-shared files or folders via unspecified vectors.

    Published: 1 Jun 2018
    7.5
    High

    CVE-2018-11646

    Last Modified: 21 Nov 2024

    webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKit, as used in WebKitGTK+ through 2.21.3, mishandle an unset pageURL, leading to an application crash.

    Published: 1 Jun 2018
    7.8
    High

    CVE-2018-12233

    Last Modified: 21 Nov 2024

    In the ea_get function in fs/jfs/xattr.c in the Linux kernel through 4.17.1, a memory corruption bug in JFS can be triggered by calling setxattr twice with two different extended attribute names on the same file. This vulnerability can be triggered by an unprivileged user with the ability to create files and execute programs. A kmalloc call is incorrect, leading to slab-out-of-bounds in jfs_xattr.

    Published: 1 Jun 2018
    7.8
    High

    CVE-2018-14734

    Last Modified: 21 Nov 2024

    drivers/infiniband/core/ucma.c in the Linux kernel through 4.17.11 allows ucma_leave_multicast to access a certain data structure after a cleanup step in ucma_process_join, which allows attackers to cause a denial of service (use-after-free).

    Published: 1 Jun 2018
    6.5
    Medium

    CVE-2018-16642

    Last Modified: 21 Nov 2024

    The function InsertRow in coders/cut.c in ImageMagick 7.0.7-37 allows remote attackers to cause a denial of service via a crafted image file due to an out-of-bounds write.

    Published: 1 Jun 2018
    7.8
    High

    CVE-2018-6552

    Last Modified: 21 Nov 2024

    Apport does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root privileges, or escape from containers. The is_same_ns() function returns True when /proc/<global pid>/ does not exist in order to indicate that the crash should be handled in the global namespace rather than inside of a container. However, the portion of the data/apport code that decides whether or not to forward a crash to a container does not always replace sys.argv[1] with the value stored in the host_pid variable when /proc/<global pid>/ does not exist which results in the container pid being used in the global namespace. This flaw affects versions 2.20.8-0ubuntu4 through 2.20.9-0ubuntu7, 2.20.7-0ubuntu3.7, 2.20.7-0ubuntu3.8, 2.20.1-0ubuntu2.15 through 2.20.1-0ubuntu2.17, and 2.14.1-0ubuntu3.28.

    Published: 31 May 2018
    6.1
    Medium

    CVE-2018-9186

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF validation failure" page allows attacker to execute unauthorized script code via inject malicious scripts in HTTP referer header.

    Published: 31 May 2018