CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-10955

    Last Modified: 21 Nov 2024

    In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x00222548.

    Published: 10 May 2018
    5.5
    Medium

    CVE-2018-10962

    Last Modified: 21 Nov 2024

    An issue was discovered in Shanghai 2345 Security Guard 3.7.0. 2345MPCSafe.exe, 2345SafeTray.exe, and 2345Speedup.exe allow local users to bypass intended process protections, and consequently terminate processes, because mouse_event is not properly considered.

    Published: 10 May 2018
    6.5
    Medium

    CVE-2018-10951

    Last Modified: 15 Aug 2025

    mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows zimbraSSLPrivateKey read access via a GetServer, GetAllServers, or GetAllActiveServers call in the Admin SOAP API.

    Published: 10 May 2018
    5.3
    Medium

    CVE-2018-10949

    Last Modified: 21 Nov 2024

    mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors.

    Published: 10 May 2018
    5.3
    Medium

    CVE-2018-10950

    Last Modified: 21 Nov 2024

    mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows Information Exposure through Verbose Error Messages containing a stack dump, tracing data, or full user-context dump.

    Published: 10 May 2018
    8.1
    High

    CVE-2019-3878

    Last Modified: 21 Nov 2024

    A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers that are normally used to start the special SAML ECP (non-browser based) can be used to bypass authentication.

    Published: 10 May 2018
    8.8
    High

    CVE-2018-6122

    Last Modified: 21 Nov 2024

    Type confusion in WebAssembly in Google Chrome prior to 66.0.3359.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 May 2018
    9.1
    Critical

    CVE-2018-1115

    Last Modified: 21 Nov 2024

    postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.

    Published: 10 May 2018
    8.8
    High

    CVE-2018-6120

    Last Modified: 21 Nov 2024

    An integer overflow that could lead to an attacker-controlled heap out-of-bounds write in PDFium in Google Chrome prior to 66.0.3359.170 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.

    Published: 10 May 2018
    9.8
    Critical

    CVE-2018-11307

    Last Modified: 21 Nov 2024

    An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.

    Published: 10 May 2018
    8.8
    High

    CVE-2018-6121

    Last Modified: 21 Nov 2024

    Insufficient validation of input in Blink in Google Chrome prior to 66.0.3359.170 allowed a remote attacker to perform privilege escalation via a crafted HTML page.

    Published: 10 May 2018
    6.5
    Medium

    CVE-2018-8860

    Last Modified: 21 Nov 2024

    In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker may be able to capture firmware updates through the adjacent network.

    Published: 9 May 2018
    6.5
    Medium

    CVE-2018-6020

    Last Modified: 21 Nov 2024

    In Silex SX-500 all versions and GE MobileLink(GEH-500) version 1.54 and prior, authentication is not verified when making certain POST requests, which may allow attackers to modify system settings.

    Published: 9 May 2018
    7.4
    High

    CVE-2018-6021

    Last Modified: 21 Nov 2024

    Silex SD-320AN version 2.01 and prior and GE MobileLink(GEH-SD-320AN) version GEH-1.1 and prior have a system call parameter that is not properly sanitized, which may allow remote code execution.

    Published: 9 May 2018
    5.4
    Medium

    CVE-2018-2416

    Last Modified: 21 Nov 2024

    SAP Identity Management 7.2 and 8.0 do not sufficiently validate an XML document accepted from an untrusted source.

    Published: 9 May 2018
    5.3
    Medium

    CVE-2018-2417

    Last Modified: 21 Nov 2024

    Under certain conditions, the SAP Identity Management 8.0 (pass of type ToASCII) allows an attacker to access information which would otherwise be restricted.

    Published: 9 May 2018
    6.5
    Medium

    CVE-2018-2420

    Last Modified: 21 Nov 2024

    SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation.

    Published: 9 May 2018
    5.3
    Medium

    CVE-2018-2422

    Last Modified: 21 Nov 2024

    SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

    Published: 9 May 2018
    9.8
    Critical

    CVE-2017-14474

    Last Modified: 21 Nov 2024

    In the MMM::Agent::Helpers::_execute function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1, a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm\_agentd process. An attacker that can initiate a TCP session with mmm\_agentd can trigger this vulnerability.

    Published: 9 May 2018
    4.7
    Medium

    CVE-2018-2415

    Last Modified: 21 Nov 2024

    SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; J2EE Engine Server Core 7.11, 7.30, 7.31, 7.40, 7.50) do not sufficiently encode user controlled inputs, resulting in a content spoofing vulnerability when error pages are displayed.

    Published: 9 May 2018
    3.7
    Low

    CVE-2018-2419

    Last Modified: 21 Nov 2024

    SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

    Published: 9 May 2018
    5.3
    Medium

    CVE-2018-2421

    Last Modified: 21 Nov 2024

    SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

    Published: 9 May 2018
    5.3
    Medium

    CVE-2018-2423

    Last Modified: 21 Nov 2024

    SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

    Published: 9 May 2018
    5.5
    Medium

    CVE-2018-2418

    Last Modified: 21 Nov 2024

    SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

    Published: 9 May 2018
    9.8
    Critical

    CVE-2017-14476

    Last Modified: 21 Nov 2024

    In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm\_agentd process. An attacker that can initiate a TCP session with mmm\_agentd can trigger this vulnerability.

    Published: 9 May 2018
    9.8
    Critical

    CVE-2017-14477

    Last Modified: 21 Nov 2024

    In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm\_agentd process. An attacker that can initiate a TCP session with mmm\_agentd can trigger this vulnerability.

    Published: 9 May 2018
    9.8
    Critical

    CVE-2017-14478

    Last Modified: 21 Nov 2024

    In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm\_agentd process. An attacker that can initiate a TCP session with mmm\_agentd can trigger this vulnerability.

    Published: 9 May 2018
    9.8
    Critical

    CVE-2017-14479

    Last Modified: 21 Nov 2024

    In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm\_agentd process. An attacker that can initiate a TCP session with mmm\_agentd can trigger this vulnerability.

    Published: 9 May 2018
    9.8
    Critical

    CVE-2017-14481

    Last Modified: 21 Nov 2024

    In the MMM::Agent::Helpers::Network::send_arp function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm\_agentd process. An attacker that can initiate a TCP session with mmm\_agentd can trigger this vulnerability.

    Published: 9 May 2018
    9.8
    Critical

    CVE-2017-14475

    Last Modified: 21 Nov 2024

    In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm\_agentd process. An attacker that can initiate a TCP session with mmm\_agentd can trigger this vulnerability.

    Published: 9 May 2018
    9.8
    Critical

    CVE-2017-14480

    Last Modified: 21 Nov 2024

    In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm\_agentd process. An attacker that can initiate a TCP session with mmm\_agentd can trigger this vulnerability.

    Published: 9 May 2018
    8.8
    High

    CVE-2018-0824

    Last Modified: 28 Oct 2025

    A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

    Published: 9 May 2018
    7.8
    High

    CVE-2018-8173

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft InfoPath when the software fails to properly handle objects in memory, aka "Microsoft InfoPath Remote Code Execution Vulnerability." This affects Microsoft Infopath.

    Published: 9 May 2018
    5.4
    Medium

    CVE-2018-8168

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8149, CVE-2018-8155, CVE-2018-8156.

    Published: 9 May 2018
    7
    High

    CVE-2018-8167

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka "Windows Common Log File System Driver Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

    Published: 9 May 2018
    5.3
    Medium

    CVE-2018-0854

    Last Modified: 21 Nov 2024

    A security feature bypass vulnerability exists in Windows Scripting Host which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0958, CVE-2018-8129, CVE-2018-8132.

    Published: 9 May 2018
    7.5
    High

    CVE-2018-0943

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8130, CVE-2018-8133, CVE-2018-8145, CVE-2018-8177.

    Published: 9 May 2018
    7.5
    High

    CVE-2018-0945

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0946, CVE-2018-0951, CVE-2018-0953, CVE-2018-0954, CVE-2018-0955, CVE-2018-1022, CVE-2018-8114, CVE-2018-8122, CVE-2018-8128, CVE-2018-8137, CVE-2018-8139.

    Published: 9 May 2018
    7.6
    High

    CVE-2018-0961

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate vSMB packet data, aka "Hyper-V vSMB Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.

    Published: 9 May 2018
    4.3
    Medium

    CVE-2018-1025

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge.

    Published: 9 May 2018
    4.3
    Medium

    CVE-2018-8112

    Last Modified: 21 Nov 2024

    A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge.

    Published: 9 May 2018
    8.8
    High

    CVE-2018-8126

    Last Modified: 21 Nov 2024

    A security feature bypass vulnerability exists when Internet Explorer fails to validate User Mode Code Integrity (UMCI) policies, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11.

    Published: 9 May 2018
    5.3
    Medium

    CVE-2018-8129

    Last Modified: 21 Nov 2024

    A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0854, CVE-2018-0958, CVE-2018-8132.

    Published: 9 May 2018
    7.5
    High

    CVE-2018-8130

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0943, CVE-2018-8133, CVE-2018-8145, CVE-2018-8177.

    Published: 9 May 2018
    5.3
    Medium

    CVE-2018-8132

    Last Modified: 21 Nov 2024

    A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0854, CVE-2018-0958, CVE-2018-8129.

    Published: 9 May 2018
    7.5
    High

    CVE-2018-8133

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0943, CVE-2018-8130, CVE-2018-8145, CVE-2018-8177.

    Published: 9 May 2018
    7
    High

    CVE-2018-8134

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.

    Published: 9 May 2018
    4.7
    Medium

    CVE-2018-8141

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8127.

    Published: 9 May 2018
    7.8
    High

    CVE-2018-8147

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8148, CVE-2018-8162.

    Published: 9 May 2018
    6.5
    Medium

    CVE-2018-8150

    Last Modified: 21 Nov 2024

    A security feature bypass vulnerability exists when the Microsoft Outlook attachment block filter does not properly handle attachments, aka "Microsoft Outlook Security Feature Bypass Vulnerability." This affects Microsoft Office.

    Published: 9 May 2018