CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2018-12099

    Last Modified: 21 Nov 2024

    Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.

    Published: 8 May 2018
    7.5
    High

    CVE-2018-0765

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial of Service Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7/4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1, .NET Core 2.0, Microsoft .NET Framework 4.7.2.

    Published: 8 May 2018
    7.8
    High

    CVE-2018-1039

    Last Modified: 21 Nov 2024

    A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, aka ".NET Framework Device Guard Security Feature Bypass Vulnerability." This affects Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1, Microsoft .NET Framework 2.0, Microsoft .NET Framework 4.6/4.6.1/4.6.2.

    Published: 8 May 2018
    8
    High

    CVE-2018-1087

    Last Modified: 21 Nov 2024

    kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, the processor did not deliver interrupts and exceptions, rather they are delivered once the first instruction after the stack switch is executed. An unprivileged KVM guest user could use this flaw to crash the guest or, potentially, escalate their privileges in the guest.

    Published: 8 May 2018
    6.5
    Medium

    CVE-2018-10981

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infinite loop) in situations where a QEMU device model attempts to make invalid transitions between states of a request.

    Published: 8 May 2018
    8.8
    High

    CVE-2018-10982

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (unexpectedly high interrupt number, array overrun, and hypervisor crash) or possibly gain hypervisor privileges by setting up an HPET timer to deliver interrupts in IO-APIC mode, aka vHPET interrupt injection.

    Published: 8 May 2018
    4.2
    Medium

    CVE-2018-1127

    Last Modified: 21 Nov 2024

    Tendrl API in Red Hat Gluster Storage before 3.4.0 does not immediately remove session tokens after a user logs out. Session tokens remain active for a few minutes allowing attackers to replay tokens acquired via sniffing/MITM attacks and authenticate as the target user.

    Published: 8 May 2018
    6.3
    Medium

    CVE-2018-12633

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_linux.c reads the same user data twice with copy_from_user. The header part of the user data is double-fetched, and a malicious user thread can tamper with the critical variables (hdr.size_in and hdr.size_out) in the header between the two fetches because of a race condition, leading to severe kernel errors, such as buffer over-accesses. This bug can cause a local denial of service and information leakage.

    Published: 8 May 2018
    9.8
    Critical

    CVE-2018-4944

    Last Modified: 21 Nov 2024

    Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 8 May 2018
    7.8
    High

    CVE-2018-8897

    Last Modified: 21 Nov 2024

    A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example) privilege escalation in Windows, macOS, some Xen configurations, or FreeBSD, or a Linux kernel crash. The MOV to SS and POP SS instructions inhibit interrupts (including NMIs), data breakpoints, and single step trap exceptions until the instruction boundary following the next instruction (SDM Vol. 3A; section 6.8.3). (The inhibited data breakpoints are those on memory accessed by the MOV to SS or POP to SS instruction itself.) Note that debug exceptions are not inhibited by the interrupt enable (EFLAGS.IF) system flag (SDM Vol. 3A; section 2.3). If the instruction following the MOV to SS or POP to SS instruction is an instruction like SYSCALL, SYSENTER, INT 3, etc. that transfers control to the operating system at CPL < 3, the debug exception is delivered after the transfer to CPL < 3 is complete. OS kernels may not expect this order of events and may therefore experience unexpected behavior when it occurs.

    Published: 8 May 2018
    8.1
    High

    CVE-2018-1256

    Last Modified: 21 Nov 2024

    Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan.

    Published: 7 May 2018
    7.5
    High

    CVE-2018-1089

    Last Modified: 21 Nov 2024

    389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading to buffer overflows. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.

    Published: 7 May 2018
    7.8
    High

    CVE-2018-10796

    Last Modified: 21 Nov 2024

    In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222014.

    Published: 7 May 2018
    6.5
    Medium

    CVE-2018-10798

    Last Modified: 21 Nov 2024

    A hang issue was discovered in Brave before 0.14.0 (on, for example, Linux). The vulnerability is caused by mishandling of JavaScript code that triggers the reload of a page continuously with an interval of 1 second.

    Published: 7 May 2018
    6.5
    Medium

    CVE-2018-10799

    Last Modified: 21 Nov 2024

    A hang issue was discovered in Brave before 0.14.0 (on, for example, Linux). This vulnerability is caused by the mishandling of a long URL formed by window.location+='?\u202a\uFEFF\u202b'; concatenation in a SCRIPT element.

    Published: 7 May 2018
    9.8
    Critical

    CVE-2017-17539

    Last Modified: 21 Nov 2024

    The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier allows attackers to gain unauthorized read/write access via a remote shell.

    Published: 7 May 2018
    9.8
    Critical

    CVE-2017-17540

    Last Modified: 21 Nov 2024

    The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell.

    Published: 7 May 2018
    5.4
    Medium

    CVE-2018-1413

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138819.

    Published: 7 May 2018
    8.8
    High

    CVE-2018-10795

    Last Modified: 21 Nov 2024

    Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment via a browser/liferay/browser.html?Type= or html/js/editor/fckeditor/editor/filemanager/browser/liferay/browser.html URI. NOTE: the vendor disputes this issue because file upload is an expected feature, subject to Role Based Access Control checks where only authenticated users with proper permissions can upload files

    Published: 7 May 2018
    7.8
    High

    CVE-2018-10776

    Last Modified: 21 Nov 2024

    The getbits function in mpglibDBL/common.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (segmentation fault and application crash) or possibly have unspecified other impact.

    Published: 7 May 2018
    7.8
    High

    CVE-2018-10777

    Last Modified: 21 Nov 2024

    Buffer overflow in the WriteMP3GainAPETag function in apetag.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 7 May 2018
    7.8
    High

    CVE-2018-10778

    Last Modified: 21 Nov 2024

    Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, a different vulnerability than CVE-2017-9872 and CVE-2017-14409.

    Published: 7 May 2018
    9.8
    Critical

    CVE-2018-10771

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 7 May 2018
    6.5
    Medium

    CVE-2018-10774

    Last Modified: 21 Nov 2024

    Read access violation in the isiin_keyword function in isiin.c in libbibutils.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by isi2xml.

    Published: 7 May 2018
    6.5
    Medium

    CVE-2018-10779

    Last Modified: 21 Nov 2024

    TIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based buffer over-read, as demonstrated by bmp2tiff.

    Published: 7 May 2018
    6.5
    Medium

    CVE-2018-10773

    Last Modified: 21 Nov 2024

    NULL pointer deference in the addsn function in serialno.c in libbibcore.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by copac2xml.

    Published: 7 May 2018
    6.5
    Medium

    CVE-2018-10801

    Last Modified: 21 Nov 2024

    TIFFClientOpen in tif_unix.c in LibTIFF 3.8.2 has memory leaks, as demonstrated by bmp2tiff.

    Published: 7 May 2018
    8.8
    High

    CVE-2018-4200

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site that triggers a WebCore::jsElementScrollHeightGetter use-after-free.

    Published: 7 May 2018
    8.8
    High

    CVE-2018-4204

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. iOS before 11.4 is affected. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 7 May 2018
    6.1
    Medium

    CVE-2018-10686

    Last Modified: 21 Nov 2024

    An issue was discovered in Vesta Control Panel 0.9.8-20. There is Reflected XSS via $_REQUEST['path'] to the view/file/index.php URI, which can lead to remote PHP code execution via vectors involving a file_put_contents call in web/upload/UploadHandler.php.

    Published: 6 May 2018
    6.5
    Medium

    CVE-2018-0494

    Last Modified: 21 Nov 2024

    GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.

    Published: 6 May 2018
    9.8
    Critical

    CVE-2018-10723

    Last Modified: 21 Nov 2024

    Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.

    Published: 5 May 2018
    6.5
    Medium

    CVE-2018-10758

    Last Modified: 21 Nov 2024

    The edit/ URI in Datenstrom Yellow 0.7.3 has CSRF via a delete action that can delete articles.

    Published: 5 May 2018
    9.8
    Critical

    CVE-2018-10757

    Last Modified: 21 Nov 2024

    CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a login attempt.

    Published: 5 May 2018
    4.8
    Medium

    CVE-2018-10752

    Last Modified: 21 Nov 2024

    The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action.

    Published: 5 May 2018
    9.8
    Critical

    CVE-2018-10753

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 5 May 2018
    6.5
    Medium

    CVE-2018-10780

    Last Modified: 21 Nov 2024

    Exiv2::Image::byteSwap2 in image.cpp in Exiv2 0.26 has a heap-based buffer over-read.

    Published: 5 May 2018
    6.5
    Medium

    CVE-2018-10775

    Last Modified: 21 Nov 2024

    NULL pointer dereference in the _fields_add function in fields.c in libbibcore.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by end2xml.

    Published: 5 May 2018
    6.5
    Medium

    CVE-2018-10767

    Last Modified: 21 Nov 2024

    There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack.

    Published: 5 May 2018
    6.5
    Medium

    CVE-2018-10768

    Last Modified: 21 Nov 2024

    There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected.

    Published: 5 May 2018
    5.3
    Medium

    CVE-2018-1313

    Last Modified: 21 Nov 2024

    In Apache Derby 10.3.1.4 to 10.14.1.0, a specially-crafted network packet can be used to request the Derby Network Server to boot a database whose location and contents are under the user's control. If the Derby Network Server is not running with a Java Security Manager policy file, the attack is successful. If the server is using a policy file, the policy file must permit the database location to be read for the attack to work. The default Derby Network Server policy file distributed with the affected releases includes a permissive policy as the default Network Server policy, which allows the attack to work.

    Published: 5 May 2018
    4.8
    Medium

    CVE-2018-10229

    Last Modified: 21 Nov 2024

    A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API.

    Published: 4 May 2018
    7.4
    High

    CVE-2013-2233

    Last Modified: 21 Nov 2024

    Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.

    Published: 4 May 2018
    8.8
    High

    CVE-2017-15043

    Last Modified: 21 Nov 2024

    A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9 could allow an authenticated remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. This vulnerability is due to insufficient input validation on user-controlled input in an HTTP request to the targeted device. An attacker in possession of router login credentials could exploit this vulnerability by sending a crafted HTTP request to an affected system.

    Published: 4 May 2018
    9.8
    Critical

    CVE-2018-10251

    Last Modified: 21 Nov 2024

    A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 could allow an unauthenticated remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges.

    Published: 4 May 2018
    8.8
    High

    CVE-2018-7494

    Last Modified: 21 Nov 2024

    WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length stack buffer where a value larger than the buffer can be read from a file into the buffer, causing the buffer to be overwritten, which may allow remote code execution or cause the application to crash.

    Published: 4 May 2018
    8.8
    High

    CVE-2018-7507

    Last Modified: 21 Nov 2024

    WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length heap buffer where a value larger than the buffer can be read from a file into the buffer, causing the buffer to be overwritten, which may allow remote code execution or cause the application to crash.

    Published: 4 May 2018
    8.8
    High

    CVE-2018-7509

    Last Modified: 21 Nov 2024

    WPLSoft in Delta Electronics versions 2.45.0 and prior writes data from a file outside the bounds of the intended buffer space, which could cause memory corruption or may allow remote code execution.

    Published: 4 May 2018
    9.8
    Critical

    CVE-2018-10740

    Last Modified: 21 Nov 2024

    Axublog 1.1.0 allows remote Code Execution as demonstrated by injection of PHP code (contained in the webkeywords parameter) into the cmsconfig.php file.

    Published: 4 May 2018
    8.8
    High

    CVE-2018-10748

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'show' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'show <node_name>' function and cause memory corruption. Furthermore, it is possible to redirect the flow of the program and execute arbitrary code.

    Published: 4 May 2018