CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2018-11477

    Last Modified: 21 Nov 2024

    An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The data packets that are sent between the iOS or Android application and the OBD dongle are not encrypted. The combination of this vulnerability with the lack of wireless network protection exposes all transferred car data to the public.

    Published: 30 May 2018
    8.8
    High

    CVE-2015-7610

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authentication of unspecified victims by leveraging failure to use a CSRF token.

    Published: 30 May 2018
    6.1
    Medium

    CVE-2018-10939

    Last Modified: 21 Nov 2024

    Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group.

    Published: 30 May 2018
    8.8
    High

    CVE-2018-11478

    Last Modified: 21 Nov 2024

    An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The OBD port is used to receive measurement data and debug information from the car. This on-board diagnostics feature can also be used to send commands to the car (different for every vendor / car product line / car). No authentication is needed, which allows attacks from the local Wi-Fi network.

    Published: 30 May 2018
    8.8
    High

    CVE-2018-11481

    Last Modified: 21 Nov 2024

    TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices allow authenticated remote code execution via crafted JSON data because /usr/lib/lua/luci/torchlight/validator.lua does not block various punctuation characters.

    Published: 30 May 2018
    9.8
    Critical

    CVE-2018-11482

    Last Modified: 21 Nov 2024

    /usr/lib/lua/luci/websys.lua on TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices has a hardcoded zMiVw8Kw0oxKXL0 password.

    Published: 30 May 2018
    5.3
    Medium

    CVE-2018-10995

    Last Modified: 21 Nov 2024

    SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields).

    Published: 30 May 2018
    8.1
    High

    CVE-2018-11518

    Last Modified: 21 Nov 2024

    A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP. These IVR systems rely on various frequencies of audio signals; based on the frequency, certain commands and functions are processed. Since these frequencies are accepted within a phone call, an attacker can record these frequencies and use them for service activations. This is a request-forgery issue when the required series of DTMF signals for a service activation is predictable (e.g., the IVR system does not speak a nonce to the caller). In this case, the IVR system accepts an activation request from a less-secure channel (any loudspeaker in the caller's physical environment) without verifying that the request was intended (it matches a nonce sent over a more-secure channel to the caller's earpiece).

    Published: 30 May 2018
    6.1
    Medium

    CVE-2018-11562

    Last Modified: 21 Nov 2024

    An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious link for an event view and then clicks on the deleted attributes quick filter.

    Published: 30 May 2018
    6.5
    Medium

    CVE-2018-11433

    Last Modified: 21 Nov 2024

    The mobi_get_kf8boundary_seqnumber function in util.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.

    Published: 30 May 2018
    6.5
    Medium

    CVE-2018-11434

    Last Modified: 21 Nov 2024

    The buffer_fill64 function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.

    Published: 30 May 2018
    6.5
    Medium

    CVE-2018-11435

    Last Modified: 21 Nov 2024

    The mobi_decompress_huffman_internal function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file.

    Published: 30 May 2018
    6.5
    Medium

    CVE-2018-11436

    Last Modified: 21 Nov 2024

    The buffer_addraw function in buffer.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.

    Published: 30 May 2018
    6.5
    Medium

    CVE-2018-11437

    Last Modified: 21 Nov 2024

    The mobi_reconstruct_parts function in parse_rawml.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file.

    Published: 30 May 2018
    8.8
    High

    CVE-2018-11438

    Last Modified: 21 Nov 2024

    The mobi_decompress_lz77 function in compression.c in Libmobi 0.3 allows remote attackers to cause remote code execution (heap-based buffer overflow) via a crafted mobi file.

    Published: 30 May 2018
    6.5
    Medium

    CVE-2018-11432

    Last Modified: 21 Nov 2024

    The mobi_parse_mobiheader function in read.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.

    Published: 30 May 2018
    7.8
    High

    CVE-2018-11556

    Last Modified: 21 Nov 2024

    tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerability because the issue is based on an sample program using LIBTIFF and do not apply to the lcms2 library, lcms2 does not depends on LIBTIFF other than to build sample programs, and the issue cannot be reproduced on the lcms2 library.”

    Published: 30 May 2018
    6.1
    Medium

    CVE-2018-11557

    Last Modified: 21 Nov 2024

    YIBAN Easy class education platform 2.0 has XSS via the articlelist.php k parameter.

    Published: 30 May 2018
    5.4
    Medium

    CVE-2018-11559

    Last Modified: 21 Nov 2024

    DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_last_name parameter.

    Published: 30 May 2018
    Unknown

    CVE-2018-11550

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-9850. Reason: This candidate is a reservation duplicate of CVE-2018-9850. Notes: All CVE users should reference CVE-2018-9850 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 30 May 2018
    5.4
    Medium

    CVE-2018-11558

    Last Modified: 21 Nov 2024

    DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_first_name parameter.

    Published: 30 May 2018
    7.8
    High

    CVE-2018-11555

    Last Modified: 21 Nov 2024

    tificc in Little CMS 2.9 has an out-of-bounds write in the PrecalculatedXFORM function in cmsxform.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerability because the issue is based on an sample program using LIBTIFF and do not apply to the lcms2 library, lcms2 does not depends on LIBTIFF other than to build sample programs, and the issue cannot be reproduced on the lcms2 library.”

    Published: 30 May 2018
    9.8
    Critical

    CVE-2018-12532

    Last Modified: 21 Nov 2024

    JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource's resource request, aka RF-14309.

    Published: 30 May 2018
    8.8
    High

    CVE-2018-5808

    Last Modified: 21 Nov 2024

    An error within the "find_green()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a stack-based buffer overflow and subsequently execute arbitrary code.

    Published: 30 May 2018
    8.8
    High

    CVE-2018-5809

    Last Modified: 21 Nov 2024

    An error within the "LibRaw::parse_exif()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a stack-based buffer overflow and subsequently execute arbitrary code.

    Published: 30 May 2018
    8.8
    High

    CVE-2018-5810

    Last Modified: 21 Nov 2024

    An error within the "rollei_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.

    Published: 30 May 2018
    6.5
    Medium

    CVE-2018-5811

    Last Modified: 21 Nov 2024

    An error within the "nikon_coolscan_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash.

    Published: 30 May 2018
    6.5
    Medium

    CVE-2018-5812

    Last Modified: 21 Nov 2024

    An error within the "nikon_coolscan_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to trigger a NULL pointer dereference.

    Published: 30 May 2018
    7.5
    High

    CVE-2018-11233

    Last Modified: 21 Nov 2024

    In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.

    Published: 30 May 2018
    7.8
    High

    CVE-2018-11235

    Last Modified: 21 Nov 2024

    In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs "git clone --recurse-submodules" because submodule "names" are obtained from this file, and then appended to $GIT_DIR/modules, leading to directory traversal with "../" in a name. Finally, post-checkout hooks from a submodule are executed, bypassing the intended design in which hooks are not obtained from a remote server.

    Published: 30 May 2018
    8.8
    High

    CVE-2018-11577

    Last Modified: 21 Nov 2024

    Liblouis 3.5.0 has a Segmentation fault in lou_logPrint in logging.c.

    Published: 30 May 2018
    8.8
    High

    CVE-2018-11625

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over-read via a crafted file.

    Published: 30 May 2018
    5.5
    Medium

    CVE-2018-12418

    Last Modified: 21 Nov 2024

    Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite loop when handling corrupt RAR files.

    Published: 30 May 2018
    9.8
    Critical

    CVE-2018-12533

    Last Modified: 21 Nov 2024

    JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData object, aka RF-14310.

    Published: 30 May 2018
    8.8
    High

    CVE-2018-5807

    Last Modified: 21 Nov 2024

    An error within the "samsung_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash.

    Published: 30 May 2018
    Unknown

    CVE-2018-10755

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is not about any specific product, protocol, or design, that falls into the scope of the assigning CNA. Notes: None

    Published: 29 May 2018
    9.8
    Critical

    CVE-2018-11545

    Last Modified: 21 Nov 2024

    md4c 0.2.5 has a heap-based buffer overflow in md_merge_lines because md_is_link_label mishandles the case of a link label composed solely of backslash escapes.

    Published: 29 May 2018
    9.8
    Critical

    CVE-2018-11546

    Last Modified: 21 Nov 2024

    md4c 0.2.5 has a heap-based buffer over-read because md_is_named_entity_contents has an off-by-one error.

    Published: 29 May 2018
    9.8
    Critical

    CVE-2018-11547

    Last Modified: 21 Nov 2024

    md_is_link_reference_definition_helper in md4c 0.2.5 has a heap-based buffer over-read because md_is_link_label mishandles loop termination.

    Published: 29 May 2018
    7.5
    High

    CVE-2018-11548

    Last Modified: 21 Nov 2024

    An issue was discovered in EOS.IO DAWN 4.2. plugins/net_plugin/net_plugin.cpp does not limit the number of P2P connections from the same source IP address.

    Published: 29 May 2018
    5.4
    Medium

    CVE-2018-11549

    Last Modified: 5 May 2025

    An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a form[qq_10]= substring.

    Published: 29 May 2018
    9.8
    Critical

    CVE-2018-11544

    Last Modified: 11 Nov 2025

    The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.ftpserver_preferences.xml file as the prefUsername and prefUserpass strings.

    Published: 29 May 2018
    5.3
    Medium

    CVE-2018-10751

    Last Modified: 21 Nov 2024

    A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463.

    Published: 29 May 2018
    7.5
    High

    CVE-2018-3734

    Last Modified: 21 Nov 2024

    stattic node module suffers from a Path Traversal vulnerability due to lack of validation of path, which allows a malicious user to read content of any file with known path.

    Published: 29 May 2018
    9.8
    Critical

    CVE-2018-3744

    Last Modified: 21 Nov 2024

    The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.

    Published: 29 May 2018
    9.1
    Critical

    CVE-2018-3745

    Last Modified: 21 Nov 2024

    atob 2.0.3 and earlier allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below.

    Published: 29 May 2018
    7.8
    High

    CVE-2018-6964

    Last Modified: 21 Nov 2024

    VMware Horizon Client for Linux (4.x before 4.8.0 and prior) contains a local privilege escalation vulnerability due to insecure usage of SUID binary. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on a Linux machine where Horizon Client is installed.

    Published: 29 May 2018
    8.1
    High

    CVE-2016-10559

    Last Modified: 21 Nov 2024

    selenium-download downloads the latest versions of the selenium standalone server and the chromedriver. selenium-download before 2.0.7 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 29 May 2018
    8.1
    High

    CVE-2016-10570

    Last Modified: 21 Nov 2024

    pngcrush-installer is an installer for Pngcrush. pngcrush-installer versions below 1.8.10 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 29 May 2018
    8.1
    High

    CVE-2016-10593

    Last Modified: 21 Nov 2024

    ibapi is an Interactive Brokers API addon for NodeJS. ibapi downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. Before 2.5.6, it may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

    Published: 29 May 2018