CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2018-8911

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Note Station before 2.5.1-0844 allows remote authenticated users to inject arbitrary web script or HTML via malicious attachments.

    Published: 9 May 2018
    6.5
    Medium

    CVE-2018-8912

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Note in Synology Note Station before 2.5.1-0844 allows remote authenticated users to inject arbitrary web script or HTML via the commit_msg parameter.

    Published: 9 May 2018
    10
    Critical

    CVE-2016-9335

    Last Modified: 21 Nov 2024

    A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware Version 5.0.196 and Stride-Managed Ethernet Switches running firmware Version 5.0.190. Vulnerable versions of Stride-Managed Ethernet switches and Sixnet-Managed Industrial switches use hard-coded HTTP SSL/SSH keys for secure communication. Because these keys cannot be regenerated by users, all products use the same key. The attacker could disrupt communication or compromise the system. CVSS v3 base score: 10, CVSS vector string: (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Red Lion Controls recommends updating to SLX firmware Version 5.3.174.

    Published: 9 May 2018
    7.8
    High

    CVE-2018-10830

    Last Modified: 21 Nov 2024

    In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x002220e0.

    Published: 9 May 2018
    Unknown

    CVE-2018-1119

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10184. Reason: This candidate is a reservation duplicate of CVE-2018-10184. Notes: All CVE users should reference CVE-2018-10184 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 9 May 2018
    7.5
    High

    CVE-2018-10831

    Last Modified: 21 Nov 2024

    Z-NOMP before 2018-04-05 has an incorrect Equihash solution verifier that allows attackers to spoof mining shares, as demonstrated by providing a solution with {x1=1,x2=1,x3=1,...,x512=1} to bypass this verifier for any blockheader. This originally affected (for example) the Bitcoin Gold and Zcash cryptocurrencies, and continued to be exploited in the wild in May 2018 against smaller cryptocurrencies.

    Published: 9 May 2018
    7.5
    High

    CVE-2018-10827

    Last Modified: 21 Nov 2024

    LiteCart before 2.1.2 allows remote attackers to cause a denial of service (memory consumption) via URIs that do not exist, because public_html/logs/not_found.log grows without bound, and is loaded into memory for each request.

    Published: 9 May 2018
    6.1
    Medium

    CVE-2018-10817

    Last Modified: 21 Nov 2024

    Severalnines ClusterControl before 1.6.0-4699 allows XSS.

    Published: 9 May 2018
    7.5
    High

    CVE-2018-10705

    Last Modified: 21 Nov 2024

    The Owned smart contract implementation for Aurora DAO (AURA), an Ethereum ERC20 token, allows attackers to acquire contract ownership because the setOwner function is declared as public. An attacker can then conduct a lockBalances() denial of service attack.

    Published: 9 May 2018
    8.8
    High

    CVE-2018-1258

    Last Modified: 25 Aug 2026

    Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.

    Published: 9 May 2018
    7.5
    High

    CVE-2018-1259

    Last Modified: 15 Jun 2026

    Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.

    Published: 9 May 2018
    5.3
    Medium

    CVE-2018-5168

    Last Modified: 25 Nov 2025

    Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

    Published: 9 May 2018
    7.5
    High

    CVE-2018-5157

    Last Modified: 25 Nov 2025

    Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.

    Published: 9 May 2018
    9.8
    Critical

    CVE-2018-5154

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

    Published: 9 May 2018
    9.8
    Critical

    CVE-2018-5183

    Last Modified: 25 Nov 2025

    Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.

    Published: 9 May 2018
    7.5
    High

    CVE-2018-5174

    Last Modified: 25 Nov 2025

    In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with downloaded files and will not show any UI. Files that are unknown and potentially dangerous will be allowed to run because SmartScreen will not prompt the user for a decision, and if the user is offline all files will be allowed to be opened because Windows won't prompt the user to ask what to do. Firefox incorrectly sets this flag when downloading files, leading to less secure behavior from SmartScreen. Note: this issue only affects Windows 10 users running the April 2018 update or later. It does not affect other Windows users or other operating systems. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

    Published: 9 May 2018
    8.8
    High

    CVE-2018-6553

    Last Modified: 21 Nov 2024

    The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubuntu 18.04 LTS, prior to 2.2.4-7ubuntu3.1 in Ubuntu 17.10, prior to 2.1.3-4ubuntu0.5 in Ubuntu 16.04 LTS, and prior to 1.7.2-0ubuntu1.10 in Ubuntu 14.04 LTS.

    Published: 9 May 2018
    8.1
    High

    CVE-2018-5178

    Last Modified: 25 Nov 2025

    A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the use of a malicious or vulnerable legacy extension in order to occur. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.

    Published: 9 May 2018
    7.5
    High

    CVE-2018-5177

    Last Modified: 21 Nov 2024

    A vulnerability exists in XSLT during number formatting where a negative buffer size may be allocated in some instances, leading to a buffer overflow and crash if it occurs. This vulnerability affects Firefox < 60.

    Published: 9 May 2018
    9.8
    Critical

    CVE-2018-1000155

    Last Modified: 21 Nov 2024

    OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake: The DPID (DataPath IDentifier) in the features_reply message are inherently trusted by the controller. that can result in Denial of Service, Unauthorized Access, Network Instability. This attack appear to be exploitable via Network connectivity: the attacker must first establish a transport connection with the OpenFlow controller and then initiate the OpenFlow handshake.

    Published: 9 May 2018
    4.3
    Medium

    CVE-2018-1000193

    Last Modified: 21 Nov 2024

    A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to have the same name as other users, and cannot be deleted via the UI.

    Published: 9 May 2018
    8.1
    High

    CVE-2018-1000194

    Last Modified: 21 Nov 2024

    A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master security subsystem protection.

    Published: 9 May 2018
    7.8
    High

    CVE-2018-4180

    Last Modified: 21 Nov 2024

    In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.

    Published: 9 May 2018
    8.2
    High

    CVE-2018-4183

    Last Modified: 21 Nov 2024

    In macOS High Sierra before 10.13.5, an access issue was addressed with additional sandbox restrictions.

    Published: 9 May 2018
    9.8
    Critical

    CVE-2018-5151

    Last Modified: 21 Nov 2024

    Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 60.

    Published: 9 May 2018
    7.5
    High

    CVE-2018-5153

    Last Modified: 21 Nov 2024

    If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can result in an out-of-bounds read with the read memory sent to the originating server in response. This vulnerability affects Firefox < 60.

    Published: 9 May 2018
    9.8
    Critical

    CVE-2018-5155

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

    Published: 9 May 2018
    8.8
    High

    CVE-2018-5158

    Last Modified: 25 Nov 2025

    The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.

    Published: 9 May 2018
    8.1
    High

    CVE-2018-5163

    Last Modified: 21 Nov 2024

    If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code. If the parent process then runs this replaced code, the executed script would be run with the parent process' privileges, escaping the sandbox on content processes. This vulnerability affects Firefox < 60.

    Published: 9 May 2018
    5.3
    Medium

    CVE-2018-5165

    Last Modified: 21 Nov 2024

    In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by default even though the Adobe Flash sandbox is actually enabled. The displayed state is the reverse of the true setting, resulting in user confusion. This could cause users to select this setting intending to activate it and inadvertently turn protections off. This vulnerability affects Firefox < 60.

    Published: 9 May 2018
    6.5
    Medium

    CVE-2018-5169

    Last Modified: 21 Nov 2024

    If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home page can be reset to include a normally-unlinkable chrome page as one of the home page tabs. This vulnerability affects Firefox < 60.

    Published: 9 May 2018
    6.1
    Medium

    CVE-2018-5175

    Last Modified: 21 Nov 2024

    A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dynamic'". If a target website contains an HTML injection flaw an attacker could inject a reference to a copy of the "require.js" library that is part of Firefox's Developer Tools, and then use a known technique using that library to bypass the CSP restrictions on executing injected scripts. This vulnerability affects Firefox < 60.

    Published: 9 May 2018
    7.5
    High

    CVE-2018-5181

    Last Modified: 21 Nov 2024

    If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process the tab will open a local file corresponding to the dropped URL, contrary to policy. One way to make the target tab open more reliably in a separate process is to open it with the "noopener" keyword. This vulnerability affects Firefox < 60.

    Published: 9 May 2018
    4.3
    Medium

    CVE-2018-1000195

    Last Modified: 21 Nov 2024

    A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionInstaller.java that allows users with Overall/Read permission to have Jenkins submit a HTTP GET request to an arbitrary URL and learn whether the response is successful (200) or not.

    Published: 9 May 2018
    6.5
    Medium

    CVE-2018-10998

    Last Modified: 21 Nov 2024

    An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.

    Published: 9 May 2018
    5.5
    Medium

    CVE-2018-4181

    Last Modified: 21 Nov 2024

    In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.

    Published: 9 May 2018
    9.8
    Critical

    CVE-2018-5150

    Last Modified: 25 Nov 2025

    Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

    Published: 9 May 2018
    7.5
    High

    CVE-2018-5160

    Last Modified: 21 Nov 2024

    WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash. This vulnerability affects Firefox < 60.

    Published: 9 May 2018
    7.5
    High

    CVE-2018-5166

    Last Modified: 21 Nov 2024

    WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects Firefox < 60.

    Published: 9 May 2018
    5.3
    Medium

    CVE-2018-5173

    Last Modified: 21 Nov 2024

    The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially executable files from user view in the panel. Note: the dialog to open the file will show the full, correct filename and whether it is executable or not. This vulnerability affects Firefox < 60.

    Published: 9 May 2018
    6.1
    Medium

    CVE-2018-5176

    Last Modified: 21 Nov 2024

    The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If a JSON file contains malicious JavaScript script embedded as "javascript:" links, users may be tricked into clicking and running this code in the context of the JSON Viewer. This can allow for the theft of cookies and authorization tokens which are accessible to that context. This vulnerability affects Firefox < 60.

    Published: 9 May 2018
    7.5
    High

    CVE-2018-5180

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability can occur during WebGL operations. While this results in a potentially exploitable crash, the vulnerability is limited because the memory is freed and reused in a brief window of time during the freeing of the same callstack. This vulnerability affects Firefox < 60.

    Published: 9 May 2018
    7.5
    High

    CVE-2018-5182

    Last Modified: 21 Nov 2024

    If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the addressbar the specified local file will be opened. This is contrary to policy and is what would happen if the string were the equivalent "file:" URL. This vulnerability affects Firefox < 60.

    Published: 9 May 2018
    4.3
    Medium

    CVE-2018-1000192

    Last Modified: 21 Nov 2024

    A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.

    Published: 9 May 2018
    6.5
    Medium

    CVE-2018-10958

    Last Modified: 21 Nov 2024

    In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an attempt at memory allocation for an Exiv2::Internal::PngChunk::zlibUncompress call.

    Published: 9 May 2018
    6.5
    Medium

    CVE-2018-10963

    Last Modified: 21 Nov 2024

    The TIFFWriteDirectorySec() function in tif_dirwrite.c in LibTIFF through 4.0.9 allows remote attackers to cause a denial of service (assertion failure and application crash) via a crafted file, a different vulnerability than CVE-2017-13726.

    Published: 9 May 2018
    6.5
    Medium

    CVE-2018-1257

    Last Modified: 21 Nov 2024

    Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.

    Published: 9 May 2018
    9.8
    Critical

    CVE-2018-1260

    Last Modified: 21 Nov 2024

    Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization endpoint that can lead to remote code execution when the resource owner is forwarded to the approval endpoint.

    Published: 9 May 2018
    8.2
    High

    CVE-2018-4182

    Last Modified: 21 Nov 2024

    In macOS High Sierra before 10.13.5, an access issue was addressed with additional sandbox restrictions on CUPS.

    Published: 9 May 2018
    6.5
    Medium

    CVE-2018-5152

    Last Modified: 21 Nov 2024

    WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to network traffic to the site through the "webRequest" API. For example, this allows for the interception of username and an encrypted password during login to Firefox Accounts. This issue does not expose synchronization traffic directly and is limited to the process of user login to the website and the data displayed to the user once logged in. This vulnerability affects Firefox < 60.

    Published: 9 May 2018