CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2018-15587

    Last Modified: 21 Nov 2024

    GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment.

    Published: 27 May 2018
    6.5
    Medium

    CVE-2018-11439

    Last Modified: 21 Nov 2024

    The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted audio file.

    Published: 27 May 2018
    9.8
    Critical

    CVE-2018-6411

    Last Modified: 21 Nov 2024

    An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection.

    Published: 26 May 2018
    7.5
    High

    CVE-2018-11505

    Last Modified: 21 Nov 2024

    The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.

    Published: 26 May 2018
    5.3
    Medium

    CVE-2018-6409

    Last Modified: 21 Nov 2024

    An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerability via the download.php q parameter.

    Published: 26 May 2018
    9.8
    Critical

    CVE-2018-6410

    Last Modified: 21 Nov 2024

    An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.

    Published: 26 May 2018
    8.8
    High

    CVE-2018-11500

    Last Modified: 21 Nov 2024

    An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUser/list" that can add an admin account.

    Published: 26 May 2018
    8.8
    High

    CVE-2018-11501

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS.

    Published: 26 May 2018
    6.5
    Medium

    CVE-2018-11496

    Last Modified: 21 Nov 2024

    In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks certain size validation.

    Published: 26 May 2018
    8
    High

    CVE-2018-11494

    Last Modified: 21 Nov 2024

    The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move, xml, remove) that allows attackers to execute arbitrary code if the remove step is skipped, because the attacker can discover a secret temporary directory name (containing 10 random digits) via a directory traversal attack involving language_info['code'].

    Published: 26 May 2018
    4.9
    Medium

    CVE-2018-11495

    Last Modified: 21 Nov 2024

    OpenCart through 3.0.2.0 allows directory traversal in the editDownload function in admin\model\catalog\download.php via admin/index.php?route=catalog/download/edit, related to the download_id. For example, an attacker can download ../../config.php.

    Published: 26 May 2018
    7.8
    High

    CVE-2018-11498

    Last Modified: 21 Nov 2024

    In Lizard v1.0 and LZ5 v2.0 (the prior release, before the product was renamed), there is an unchecked buffer size during a memcpy in the Lizard_decompress_LIZv1 function (lib/lizard_decompress_liz.h). Remote attackers can leverage this vulnerability to cause a denial of service via a crafted input file, as well as achieve remote code execution.

    Published: 26 May 2018
    9.8
    Critical

    CVE-2018-11499

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability exists in handle_error() in sass_context.cpp in LibSass 3.4.x and 3.5.x through 3.5.4 that could be leveraged to cause a denial of service (application crash) or possibly unspecified other impact.

    Published: 26 May 2018
    8.8
    High

    CVE-2018-11493

    Last Modified: 5 May 2025

    An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m=link&f=index&v=add.

    Published: 26 May 2018
    6.1
    Medium

    CVE-2018-11487

    Last Modified: 21 Nov 2024

    PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php.

    Published: 26 May 2018
    5.5
    Medium

    CVE-2021-20219

    Last Modified: 21 Nov 2024

    A denial of service vulnerability was found in n_tty_receive_char_special in drivers/tty/n_tty.c of the Linux kernel. In this flaw a local attacker with a normal user privilege could delay the loop (due to a changing ldata->read_head, and a missing sanity check) and cause a threat to the system availability.

    Published: 26 May 2018
    5.5
    Medium

    CVE-2018-14613

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 4.17.10. There is an invalid pointer dereference in io_ctl_map_page() when mounting and operating a crafted btrfs image, because of a lack of block group item validation in check_leaf_item in fs/btrfs/tree-checker.c.

    Published: 26 May 2018
    5.5
    Medium

    CVE-2018-14614

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 4.17.10. There is an out-of-bounds access in __remove_dirty_segment() in fs/f2fs/segment.c when mounting an f2fs image.

    Published: 26 May 2018
    5.5
    Medium

    CVE-2018-14609

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 4.17.10. There is an invalid pointer dereference in __del_reloc_root() in fs/btrfs/relocation.c when mounting a crafted btrfs image, related to removing reloc rb_trees when reloc control has not been initialized.

    Published: 26 May 2018
    5.5
    Medium

    CVE-2018-14611

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 4.17.10. There is a use-after-free in try_merge_free_space() when mounting a crafted btrfs image, because of a lack of chunk type flag checks in btrfs_check_chunk_valid in fs/btrfs/volumes.c.

    Published: 26 May 2018
    5.5
    Medium

    CVE-2018-11504

    Last Modified: 21 Nov 2024

    The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html.

    Published: 26 May 2018
    5.5
    Medium

    CVE-2018-11503

    Last Modified: 21 Nov 2024

    The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html.

    Published: 26 May 2018
    5.5
    Medium

    CVE-2018-14610

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 4.17.10. There is out-of-bounds access in write_extent_buffer() when mounting and operating a crafted btrfs image, because of a lack of verification that each block group has a corresponding chunk at mount time, within btrfs_read_block_groups in fs/btrfs/extent-tree.c.

    Published: 26 May 2018
    5.5
    Medium

    CVE-2018-14612

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 4.17.10. There is an invalid pointer dereference in btrfs_root_node() when mounting a crafted btrfs image, because of a lack of chunk block group mapping validation in btrfs_read_block_groups in fs/btrfs/extent-tree.c, and a lack of empty-tree checks in check_leaf in fs/btrfs/tree-checker.c.

    Published: 26 May 2018
    6.1
    Medium

    CVE-2018-11472

    Last Modified: 21 Nov 2024

    Monstra CMS 3.0.4 has Reflected XSS during Login (i.e., the login parameter to admin/index.php).

    Published: 25 May 2018
    8
    High

    CVE-2018-11474

    Last Modified: 21 Nov 2024

    Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab. A password change at admin/index.php?id=users&action=edit&user_id=1 does not invalidate a session that is open in a different browser.

    Published: 25 May 2018
    8
    High

    CVE-2018-11475

    Last Modified: 21 Nov 2024

    Monstra CMS 3.0.4 has a Session Management Issue in the Users tab. A password change at users/1/edit does not invalidate a session that is open in a different browser.

    Published: 25 May 2018
    9.8
    Critical

    CVE-2018-9091

    Last Modified: 21 Nov 2024

    A critical vulnerability in the KEMP LoadMaster Operating System (LMOS) 6.0.44 through 7.2.41.2 and Long Term Support (LTS) LMOS before 7.1.35.5 related to Session Management could allow an unauthenticated, remote attacker to bypass security protections, gain system privileges, and execute elevated commands such as ls, ps, cat, etc., thereby compromising the system. Through this remote execution, in certain cases, exposure of sensitive system data such as certificates, private keys, and other information may be possible.

    Published: 25 May 2018
    6.1
    Medium

    CVE-2018-11473

    Last Modified: 21 Nov 2024

    Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).

    Published: 25 May 2018
    5.4
    Medium

    CVE-2018-11471

    Last Modified: 21 Nov 2024

    Cockpit 0.5.5 has XSS via a collection, form, or region.

    Published: 25 May 2018
    7.8
    High

    CVE-2018-11479

    Last Modified: 21 Nov 2024

    The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that establishes a \\.\pipe\WindscribeService named pipe endpoint that allows the Windscribe VPN process to connect and execute an OpenVPN process or other processes (like taskkill, etc.). There is no validation of the program name before constructing the lpCommandLine argument for a CreateProcess call. An attacker can run any malicious process with SYSTEM privileges through this named pipe.

    Published: 25 May 2018
    3.1
    Low

    CVE-2018-8862

    Last Modified: 21 Nov 2024

    In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, an improper authentication vulnerability caused by specially crafted malicious radio transmissions may allow an attacker to remotely trigger false alarms.

    Published: 25 May 2018
    9.8
    Critical

    CVE-2018-8871

    Last Modified: 21 Nov 2024

    In Delta Electronics Automation TPEditor version 1.89 or prior, parsing a malformed program file may cause heap-based buffer overflow vulnerability, which may allow remote code execution.

    Published: 25 May 2018
    5.3
    Medium

    CVE-2017-14185

    Last Modified: 21 Nov 2024

    An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN web portal.

    Published: 25 May 2018
    3.1
    Low

    CVE-2018-8864

    Last Modified: 21 Nov 2024

    In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, a missing encryption of sensitive data vulnerability caused by specially crafted malicious radio transmissions may allow an attacker to remotely trigger false alarms.

    Published: 25 May 2018
    8.8
    High

    CVE-2018-10350

    Last Modified: 21 Nov 2024

    A SQL injection remote code execution vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw within the handling of parameters provided to wcs\_bwlists\_handler.php. Authentication is required in order to exploit this vulnerability.

    Published: 25 May 2018
    7.8
    High

    CVE-2018-6233

    Last Modified: 21 Nov 2024

    A buffer overflow privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222060 by the tmnciesc.sys driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 25 May 2018
    7.5
    High

    CVE-2018-6237

    Last Modified: 21 Nov 2024

    A vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker to manipulate the product to send a large number of specially crafted HTTP requests to potentially cause the file system to fill up, eventually causing a denial of service (DoS) situation.

    Published: 25 May 2018
    8.8
    High

    CVE-2017-9641

    Last Modified: 21 Nov 2024

    PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system. OSIsoft recommends that users upgrade to PI Vision 2017 or greater to mitigate this vulnerability.

    Published: 25 May 2018
    7.8
    High

    CVE-2018-6232

    Last Modified: 21 Nov 2024

    A buffer overflow privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x22205C by the tmnciesc.sys driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 25 May 2018
    7.8
    High

    CVE-2018-6235

    Last Modified: 21 Nov 2024

    An Out-of-Bounds write privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222814 by the tmnciesc.sys driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 25 May 2018
    5.5
    Medium

    CVE-2018-6234

    Last Modified: 21 Nov 2024

    An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within processing of IOCTL 0x222814 by the tmnciesc.sys driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 25 May 2018
    7
    High

    CVE-2018-6236

    Last Modified: 21 Nov 2024

    A Time-of-Check Time-of-Use privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222813 by the tmusa driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 25 May 2018
    8.4
    High

    CVE-2018-1565

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner. IBM X-Force ID: 143022.

    Published: 25 May 2018
    5.5
    Medium

    CVE-2018-1449

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140044.

    Published: 25 May 2018
    5.5
    Medium

    CVE-2018-1451

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140046.

    Published: 25 May 2018
    5.5
    Medium

    CVE-2018-1452

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140047.

    Published: 25 May 2018
    7.8
    High

    CVE-2018-1459

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to stack based buffer overflow, caused by improper bounds checking which could lead an attacker to execute arbitrary code. IBM X-Force ID: 140210.

    Published: 25 May 2018
    7.4
    High

    CVE-2018-1515

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1, under specific or unusual conditions, could allow a local user to overflow a buffer which may result in a privilege escalation to the DB2 instance owner. IBM X-Force ID: 141624.

    Published: 25 May 2018
    4.9
    Medium

    CVE-2017-1752

    Last Modified: 21 Nov 2024

    IBM UrbanCode Deploy 6.1 and 6.2 could allow an authenticated privileged user to obtain highly sensitive information. IBM X-Force ID: 135547.

    Published: 25 May 2018