CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2018-10206

    Last Modified: 30 May 2025

    An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS via the optional message field of a file request.

    Published: 25 Apr 2018
    5.3
    Medium

    CVE-2018-10210

    Last Modified: 30 May 2025

    An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. Enumeration of users is possible through the password-reset feature.

    Published: 25 Apr 2018
    5.3
    Medium

    CVE-2018-10211

    Last Modified: 30 May 2025

    An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization when listing the history of another user via a modified "vaultize_session_id" value in a cookie.

    Published: 25 Apr 2018
    5.4
    Medium

    CVE-2018-10212

    Last Modified: 30 May 2025

    An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization leading to creation of folders within another account via a modified device value.

    Published: 25 Apr 2018
    5.4
    Medium

    CVE-2018-10213

    Last Modified: 30 May 2025

    An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is XSS in invitation mail received from a different user, who can modify the HTML in that mail before sending it.

    Published: 25 Apr 2018
    5.3
    Medium

    CVE-2018-10207

    Last Modified: 30 May 2025

    An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. An attacker can exploit Missing Authorization on the FlexPaperViewer SWF reader, and export files that should have been restricted, via vectors involving page-by-page access to a document in SWF format.

    Published: 25 Apr 2018
    6.1
    Medium

    CVE-2018-10208

    Last Modified: 30 May 2025

    An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is anonymous reflected XSS on the error page via a /share/error?message= URI.

    Published: 25 Apr 2018
    5.4
    Medium

    CVE-2018-10209

    Last Modified: 30 May 2025

    An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS on the file or folder download pop-up via a crafted file or folder name.

    Published: 25 Apr 2018
    6.1
    Medium

    CVE-2018-1067

    Last Modified: 21 Nov 2024

    In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.

    Published: 25 Apr 2018
    9.8
    Critical

    CVE-2014-5014

    Last Modified: 21 Nov 2024

    The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path.

    Published: 25 Apr 2018
    5.4
    Medium

    CVE-2018-1363

    Last Modified: 21 Nov 2024

    IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137448.

    Published: 25 Apr 2018
    5.4
    Medium

    CVE-2017-1750

    Last Modified: 21 Nov 2024

    IBM Jazz Reporting Service (JRS) 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 135523.

    Published: 25 Apr 2018
    8.8
    High

    CVE-2017-12712

    Last Modified: 21 Nov 2024

    The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, which involves an authentication key and time stamp, can be compromised or bypassed, which may allow a nearby attacker to issue unauthorized commands to the pacemaker via RF communications. CVSS v3 base score: 7.5, CVSS vector string: AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Abbott has developed a firmware update to help mitigate the identified vulnerabilities.

    Published: 25 Apr 2018
    6.5
    Medium

    CVE-2017-12714

    Last Modified: 21 Nov 2024

    Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017 do not restrict or limit the number of correctly formatted "RF wake-up" commands that can be received, which may allow a nearby attacker to repeatedly send commands to reduce pacemaker battery life. CVSS v3 base score: 5.3, CVSS vector string: AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H. Abbott has developed a firmware update to help mitigate the identified vulnerabilities.

    Published: 25 Apr 2018
    6.5
    Medium

    CVE-2017-12716

    Last Modified: 21 Nov 2024

    Abbott Laboratories Accent and Anthem pacemakers manufactured prior to Aug 28, 2017 transmit unencrypted patient information via RF communications to programmers and home monitoring units. Additionally, the Accent and Anthem pacemakers store the optional patient information without encryption. CVSS v3 base score: 3.1, CVSS vector string: AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N. Abbott has developed a firmware update to help mitigate the identified vulnerabilities.

    Published: 25 Apr 2018
    7.5
    High

    CVE-2017-7652

    Last Modified: 21 Nov 2024

    In Eclipse Mosquitto 1.4.14, if a Mosquitto instance is set running with a configuration file, then sending a HUP signal to server triggers the configuration to be reloaded from disk. If there are lots of clients connected so that there are no more file descriptors/sockets available (default limit typically 1024 file descriptors on Linux), then opening the configuration file will fail.

    Published: 25 Apr 2018
    6.5
    Medium

    CVE-2018-10471

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor crash) via unexpected INT 80 processing, because of an incorrect fix for CVE-2017-5754.

    Published: 25 Apr 2018
    5.6
    Medium

    CVE-2018-10472

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.

    Published: 25 Apr 2018
    6.1
    Medium

    CVE-2018-10366

    Last Modified: 21 Nov 2024

    An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the name field.

    Published: 25 Apr 2018
    4.8
    Medium

    CVE-2018-10367

    Last Modified: 5 May 2025

    An issue was discovered in WUZHI CMS 4.1.0. The content-management feature has Stored XSS via the title or content section.

    Published: 25 Apr 2018
    4.8
    Medium

    CVE-2018-10368

    Last Modified: 5 May 2025

    An issue was discovered in WUZHI CMS 4.1.0. The "Extension Module -> System Announcement" feature has Stored XSS via an announcement.

    Published: 25 Apr 2018
    6.1
    Medium

    CVE-2018-10374

    Last Modified: 21 Nov 2024

    EasyCMS 1.3 has XSS via the s POST parameter (aka a search box value) in an index.php?s=/index/search/index.html request.

    Published: 25 Apr 2018
    9.8
    Critical

    CVE-2018-10375

    Last Modified: 21 Nov 2024

    A file uploading vulnerability exists in /include/helpers/upload.helper.php in DedeCMS V5.7 SP2, which can be utilized by attackers to upload and execute arbitrary PHP code via the /dede/archives_do.php?dopost=uploadLitpic litpic parameter when "Content-Type: image/jpeg" is sent, but the filename ends in .php and contains PHP code.

    Published: 25 Apr 2018
    7.5
    High

    CVE-2018-10376

    Last Modified: 21 Nov 2024

    An integer overflow in the transferProxy function of a smart contract implementation for SmartMesh (aka SMT), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets via crafted _fee and _value parameters, as exploited in the wild in April 2018, aka the "proxyOverflow" issue.

    Published: 25 Apr 2018
    6.5
    Medium

    CVE-2018-8801

    Last Modified: 21 Nov 2024

    GitLab Community and Enterprise Editions version 8.3 up to 10.x before 10.3 are vulnerable to SSRF in the Services and webhooks component.

    Published: 25 Apr 2018
    5.4
    Medium

    CVE-2018-10310

    Last Modified: 21 Nov 2024

    A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Consent plugin before 2.3.10 for WordPress that allows the execution of arbitrary HTML/script code in the context of a victim's browser.

    Published: 25 Apr 2018
    9.8
    Critical

    CVE-2018-10362

    Last Modified: 21 Nov 2024

    An issue was discovered in phpLiteAdmin 1.9.5 through 1.9.7.1. Due to loose comparison with '==' instead of '===' in classes/Authorization.php for the user-provided login password, it is possible to login with a simpler password if the password has the form of a power in scientific notation (like '2e2' for '200' or '0e1234' for '0'). This is possible because, in the loose comparison case, PHP interprets the string as a number in scientific notation, and thus converts it to a number. After that, the comparison with '==' casts the user input (e.g., the string '200' or '0') to a number, too. Hence the attacker can login with just a '0' or a simple number he has to brute force. Strong comparison with '===' prevents the cast into numbers.

    Published: 25 Apr 2018
    7.8
    High

    CVE-2018-10361

    Last Modified: 21 Nov 2024

    An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper service (as utilized in the Kate text editor) can allow other unprivileged users on the local system to gain root privileges. The attack occurs when one user (who has an unprivileged account but is also able to authenticate as root) writes a text file using Kate into a directory owned by a another unprivileged user. The latter unprivileged user conducts a symlink attack to achieve privilege escalation.

    Published: 25 Apr 2018
    5.5
    Medium

    CVE-2018-1339

    Last Modified: 21 Nov 2024

    A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.

    Published: 25 Apr 2018
    7.5
    High

    CVE-2018-10393

    Last Modified: 21 Nov 2024

    bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.

    Published: 25 Apr 2018
    8.8
    High

    CVE-2018-3719

    Last Modified: 21 Nov 2024

    mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

    Published: 25 Apr 2018
    5.9
    Medium

    CVE-2018-10237

    Last Modified: 21 Nov 2024

    Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.

    Published: 25 Apr 2018
    8.8
    High

    CVE-2018-10392

    Last Modified: 21 Nov 2024

    mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file.

    Published: 25 Apr 2018
    8.1
    High

    CVE-2018-1335

    Last Modified: 21 Nov 2024

    From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.

    Published: 25 Apr 2018
    5.5
    Medium

    CVE-2018-1338

    Last Modified: 21 Nov 2024

    A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.

    Published: 25 Apr 2018
    7.8
    High

    CVE-2013-3947

    Last Modified: 21 Nov 2024

    Buffer overflow in MedCoreD.sys in AhnLab V3 Internet Security 8.0.7.5 (Build 1373) allows local users to gain privileges via a crafted 0xA3350014 IOCTL call.

    Published: 24 Apr 2018
    7.5
    High

    CVE-2013-7245

    Last Modified: 21 Nov 2024

    The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and perform database dumps by leveraging failure to validate credentials, aka SAP Security Note 1927859.

    Published: 24 Apr 2018
    8.8
    High

    CVE-2017-17557

    Last Modified: 21 Nov 2024

    In Foxit Reader before 9.1 and Foxit PhantomPDF before 9.1, a flaw exists within the parsing of the BITMAPINFOHEADER record in BMP files. The issue results from the lack of proper validation of the biSize member, which can result in a heap based buffer overflow. An attacker can leverage this to execute code in the context of the current process.

    Published: 24 Apr 2018
    7.8
    High

    CVE-2017-12086

    Last Modified: 21 Nov 2024

    An exploitable integer overflow exists in the 'BKE_mesh_calc_normals_tessface' functionality of the Blender open-source 3d creation suite. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open a .blend file in order to trigger this vulnerability.

    Published: 24 Apr 2018
    7.8
    High

    CVE-2018-3836

    Last Modified: 21 Nov 2024

    An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially crafted gplot rootname argument can cause a command injection resulting in arbitrary code execution. An attacker can provide a malicious path as input to an application that passes attacker data to this function to trigger this vulnerability.

    Published: 24 Apr 2018
    8.8
    High

    CVE-2016-8384

    Last Modified: 21 Nov 2024

    An exploitable heap corruption vulnerability exists in the DHFSummary functionality of AntennaHouse DMC HTMLFilter.

    Published: 24 Apr 2018
    7.8
    High

    CVE-2017-12099

    Last Modified: 21 Nov 2024

    An exploitable integer overflow exists in the upgrade of the legacy Mesh attribute 'tface' of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use it as a library in order to trigger this vulnerability.

    Published: 24 Apr 2018
    7.8
    High

    CVE-2017-12100

    Last Modified: 21 Nov 2024

    An exploitable integer overflow exists in the 'multires_load_old_dm' functionality of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open a .blend file in order to trigger this vulnerability.

    Published: 24 Apr 2018
    8.8
    High

    CVE-2017-14442

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the BMP image rendering functionality of SDL2_image-2.0.2. A specially crafted BMP image can cause a stack overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.

    Published: 24 Apr 2018
    8.8
    High

    CVE-2017-14448

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can cause a heap overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.

    Published: 24 Apr 2018
    7.8
    High

    CVE-2016-8728

    Last Modified: 21 Nov 2024

    An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A specially crafted PDF file can cause a out of bounds write resulting in heap metadata and sensitive process memory corruption leading to potential code execution. Victim needs to open the specially crafted file in a vulnerable reader in order to trigger this vulnerability.

    Published: 24 Apr 2018
    7.8
    High

    CVE-2016-8732

    Last Modified: 21 Nov 2024

    Multiple security flaws exists in InvProtectDrv.sys which is a part of Invincea Dell Protected Workspace 5.1.1-22303. Weak restrictions on the driver communication channel and additional insufficient checks allow any application to turn off some of the protection mechanisms provided by the Invincea product.

    Published: 24 Apr 2018
    7.5
    High

    CVE-2017-14449

    Last Modified: 21 Nov 2024

    A double-Free vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can cause a Double-Free situation to occur. An attacker can display a specially crafted image to trigger this vulnerability.

    Published: 24 Apr 2018
    7.8
    High

    CVE-2016-9038

    Last Modified: 21 Nov 2024

    An exploitable double fetch vulnerability exists in the SboxDrv.sys driver functionality of Invincea-X 6.1.3-24058. A specially crafted input buffer and race condition can result in kernel memory corruption, which could result in privilege escalation. An attacker needs to execute a special application locally to trigger this vulnerability.

    Published: 24 Apr 2018
    7.8
    High

    CVE-2016-9043

    Last Modified: 21 Nov 2024

    An out of bound write vulnerability exists in the EMF parsing functionality of CorelDRAW X8 (CdrGfx - Corel Graphics Engine (64-Bit) - 18.1.0.661). A specially crafted EMF file can cause a vulnerability resulting in potential code execution. An attacker can send the victim a specific EMF file to trigger this vulnerability.

    Published: 24 Apr 2018