CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2018-1059

    Last Modified: 21 Nov 2024

    The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.

    Published: 23 Apr 2018
    2.3
    Low

    CVE-2018-1118

    Last Modified: 21 Nov 2024

    Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This can allow local privileged users to read some kernel memory contents when reading from the /dev/vhost-net device file.

    Published: 23 Apr 2018
    5.4
    Medium

    CVE-2018-10298

    Last Modified: 21 Nov 2024

    Discuz! DiscuzX through X3.4 has reflected XSS via forum.php?mod=post&action=newthread because data/template/1_diy_portal_view.tpl.php does not restrict the content.

    Published: 22 Apr 2018
    5.4
    Medium

    CVE-2017-17889

    Last Modified: 21 Nov 2024

    Kliqqi CMS 3.5.2 has XSS via a crafted group name in pligg/groups.php, a crafted Homepage string in a profile, or a crafted string in Tags or Description within pligg/submit.php.

    Published: 22 Apr 2018
    9.8
    Critical

    CVE-2017-17902

    Last Modified: 21 Nov 2024

    SQL Injection exists in Kliqqi CMS 3.5.2 via the randkey parameter of a new story at the pligg/story.php?title= URI.

    Published: 22 Apr 2018
    5.4
    Medium

    CVE-2018-10297

    Last Modified: 21 Nov 2024

    Discuz! DiscuzX through X3.4 has stored XSS via the portal.php?mod=portalcp&ac=article URI, related to mishandling of IMG elements associated with remote images.

    Published: 22 Apr 2018
    8.8
    High

    CVE-2018-10295

    Last Modified: 21 Nov 2024

    ChemCMS v1.0.6 has CSRF by using public/admin/user/addpost.html to add an administrator account.

    Published: 22 Apr 2018
    6.1
    Medium

    CVE-2018-10296

    Last Modified: 21 Nov 2024

    MiniCMS V1.10 has XSS via the mc-admin/post-edit.php title parameter.

    Published: 22 Apr 2018
    9.8
    Critical

    CVE-2018-10285

    Last Modified: 21 Nov 2024

    The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attacker might bypass authentication.

    Published: 22 Apr 2018
    8.8
    High

    CVE-2018-10286

    Last Modified: 21 Nov 2024

    The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the responses to certain HTTP POST requests. In order to be able to see the credentials in cleartext, an attacker needs to be authenticated.

    Published: 22 Apr 2018
    9.8
    Critical

    CVE-2018-9245

    Last Modified: 21 Nov 2024

    The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the login page and execute remote code on the operating system.

    Published: 22 Apr 2018
    5.5
    Medium

    CVE-2018-10289

    Last Modified: 21 Nov 2024

    In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary could leverage this vulnerability to cause a denial of service via a crafted pdf file.

    Published: 22 Apr 2018
    7.8
    High

    CVE-2018-10536

    Last Modified: 21 Nov 2024

    An issue was discovered in WavPack 5.1.0 and earlier. The WAV parser component contains a vulnerability that allows writing to memory because ParseRiffHeaderConfig in riff.c does not reject multiple format chunks.

    Published: 22 Apr 2018
    7.8
    High

    CVE-2018-10537

    Last Modified: 21 Nov 2024

    An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerability that allows writing to memory because ParseWave64HeaderConfig in wave64.c does not reject multiple format chunks.

    Published: 22 Apr 2018
    5.5
    Medium

    CVE-2018-10539

    Last Modified: 21 Nov 2024

    An issue was discovered in WavPack 5.1.0 and earlier for DSDiff input. Out-of-bounds writes can occur because ParseDsdiffHeaderConfig in dsdiff.c does not validate the sizes of unknown chunks before attempting memory allocation, related to a lack of integer-overflow protection within a bytes_to_copy calculation and subsequent malloc call, leading to insufficient memory allocation.

    Published: 22 Apr 2018
    9.8
    Critical

    CVE-2018-11531

    Last Modified: 21 Nov 2024

    Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.

    Published: 22 Apr 2018
    5.5
    Medium

    CVE-2018-10538

    Last Modified: 21 Nov 2024

    An issue was discovered in WavPack 5.1.0 and earlier for WAV input. Out-of-bounds writes can occur because ParseRiffHeaderConfig in riff.c does not validate the sizes of unknown chunks before attempting memory allocation, related to a lack of integer-overflow protection within a bytes_to_copy calculation and subsequent malloc call, leading to insufficient memory allocation.

    Published: 22 Apr 2018
    5.5
    Medium

    CVE-2018-10540

    Last Modified: 21 Nov 2024

    An issue was discovered in WavPack 5.1.0 and earlier for W64 input. Out-of-bounds writes can occur because ParseWave64HeaderConfig in wave64.c does not validate the sizes of unknown chunks before attempting memory allocation, related to a lack of integer-overflow protection within a bytes_to_copy calculation and subsequent malloc call, leading to insufficient memory allocation.

    Published: 22 Apr 2018
    5.4
    Medium

    CVE-2017-15640

    Last Modified: 21 Nov 2024

    app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter.

    Published: 21 Apr 2018
    9.8
    Critical

    CVE-2018-10283

    Last Modified: 21 Nov 2024

    CliqueMania loja virtual 14 has SQL Injection via the patch/remote.php id parameter in a recomendar action.

    Published: 21 Apr 2018
    9.8
    Critical

    CVE-2018-10284

    Last Modified: 21 Nov 2024

    Adaltech G-Ticket v70 EME104 has SQL Injection via the mobile-loja/mensagem.asp eve_cod parameter.

    Published: 21 Apr 2018
    8.8
    High

    CVE-2018-10265

    Last Modified: 21 Nov 2024

    An issue was discovered in HongCMS v3.0.0. There is a CSRF vulnerability that can add an administrator account via the admin/index.php/users/save URI.

    Published: 21 Apr 2018
    8.8
    High

    CVE-2018-10266

    Last Modified: 21 Nov 2024

    BEESCMS 4.0 has a CSRF vulnerability to add an administrator account via the admin/admin_admin.php?nav=list_admin_user&admin_p_nav=user URI.

    Published: 21 Apr 2018
    5.4
    Medium

    CVE-2018-10268

    Last Modified: 21 Nov 2024

    An issue was discovered in FastAdmin V1.0.0.20180417_beta. There is XSS via the application\api\controller\User.php avatar parameter.

    Published: 21 Apr 2018
    8.8
    High

    CVE-2018-10267

    Last Modified: 21 Nov 2024

    WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI.

    Published: 21 Apr 2018
    7.5
    High

    CVE-2018-10253

    Last Modified: 21 Nov 2024

    Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.

    Published: 21 Apr 2018
    7.8
    High

    CVE-2018-10254

    Last Modified: 21 Nov 2024

    Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file. Remote attackers could leverage this vulnerability to cause a denial of service or possibly have unspecified other impact via a crafted ELF file.

    Published: 21 Apr 2018
    6.5
    Medium

    CVE-2018-1114

    Last Modified: 21 Nov 2024

    It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.

    Published: 21 Apr 2018
    8.8
    High

    CVE-2014-0900

    Last Modified: 21 Nov 2024

    The Device Administrator code in Android before 4.4.1_r1 might allow attackers to spoof device administrators and consequently bypass MDM restrictions by leveraging failure to update the mAdminMap data structure.

    Published: 20 Apr 2018
    8.1
    High

    CVE-2014-0927

    Last Modified: 21 Nov 2024

    The ActiveMQ admin user interface in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to bypass authentication by leveraging knowledge of the port number and webapp path. IBM X-Force ID: 92259.

    Published: 20 Apr 2018
    7.1
    High

    CVE-2014-0950

    Last Modified: 21 Nov 2024

    Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQuest Eclipse client, and (4) ClearQuest Eclipse Designer components in IBM Rational ClearQuest 7.1.1 through 7.1.1.9, 7.1.2 through 7.1.2.13, 8.0.0 through 8.0.0.10, and 8.0.1 through 8.0.1.3 allow remote attackers to cause a denial of service or access other servers via crafted XML data. IBM X-Force ID: 92623.

    Published: 20 Apr 2018
    4.9
    Medium

    CVE-2018-10077

    Last Modified: 21 Nov 2024

    XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to read arbitrary files via crafted XML data.

    Published: 20 Apr 2018
    4.8
    Medium

    CVE-2018-10078

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via a server description.

    Published: 20 Apr 2018
    7.8
    High

    CVE-2018-10079

    Last Modified: 21 Nov 2024

    Geist WatchDog Console 3.2.2 uses a weak ACL for the C:\ProgramData\WatchDog Console directory, which allows local users to modify configuration data by updating (1) config.xml or (2) servers.xml.

    Published: 20 Apr 2018
    8.8
    High

    CVE-2018-10173

    Last Modified: 21 Nov 2024

    Digital Guardian Management Console 7.1.2.0015 allows authenticated remote code execution because of Arbitrary File Upload functionality.

    Published: 20 Apr 2018
    6.5
    Medium

    CVE-2018-10175

    Last Modified: 21 Nov 2024

    Digital Guardian Management Console 7.1.2.0015 has an XXE issue.

    Published: 20 Apr 2018
    6.5
    Medium

    CVE-2018-10176

    Last Modified: 21 Nov 2024

    Digital Guardian Management Console 7.1.2.0015 has a Directory Traversal issue.

    Published: 20 Apr 2018
    6.1
    Medium

    CVE-2014-0883

    Last Modified: 21 Nov 2024

    IBM Power HMC 7.1.0 through 7.8.0 and 7.3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.  IBM X-Force ID:  91163.

    Published: 20 Apr 2018
    5.3
    Medium

    CVE-2014-0912

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive product information via vectors related to an error page. IBM X-Force ID: 92072.

    Published: 20 Apr 2018
    9.1
    Critical

    CVE-2014-0931

    Last Modified: 21 Nov 2024

    Multiple XML external entity (XXE) vulnerabilities in the (1) CCRC WAN Server / CM Server, (2) Perl CC/CQ integration trigger scripts, (3) CMAPI Java interface, (4) ClearCase remote client, and (5) CMI and OSLC-based ClearQuest integrations components in IBM Rational ClearCase 7.1.0.x, 7.1.1.x, 7.1.2 through 7.1.2.13, 8.0 through 8.0.0.10, and 8.0.1 through 8.0.1.3 allow remote attackers to cause a denial of service or access other servers via crafted XML data. IBM X-Force ID: 92263.

    Published: 20 Apr 2018
    7
    High

    CVE-2017-2825

    Last Modified: 21 Nov 2024

    In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active Zabbix proxy and Server to trigger this vulnerability.

    Published: 20 Apr 2018
    4.8
    Medium

    CVE-2018-7747

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a greeting message, (2) the email transaction log, or (3) an imported form.

    Published: 20 Apr 2018
    6.5
    Medium

    CVE-2018-10174

    Last Modified: 21 Nov 2024

    Digital Guardian Management Console 7.1.2.0015 has an SSRF issue that allows remote attackers to read arbitrary files via file:// URLs, send TCP traffic to intranet hosts, or obtain an NTLM hash. This can occur even if the logged-in user has a read-only role.

    Published: 20 Apr 2018
    9.8
    Critical

    CVE-2018-9059

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code via a malicious login request to forum.ghp. NOTE: this may overlap CVE-2014-3791.

    Published: 20 Apr 2018
    5.9
    Medium

    CVE-2014-6112

    Last Modified: 21 Nov 2024

    IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 make it easier for remote attackers to obtain sensitive information by leveraging support for weak SSL ciphers. IBM X-Force ID: 96184.

    Published: 20 Apr 2018
    7.5
    High

    CVE-2014-10073

    Last Modified: 21 Nov 2024

    The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a check for whether a file is under the webserver directory.

    Published: 20 Apr 2018
    5.9
    Medium

    CVE-2014-6108

    Last Modified: 21 Nov 2024

    IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 might allow man-in-the-middle attackers to obtain sensitive information by leveraging an unencrypted connection for interfaces. IBM X-Force ID: 96172.

    Published: 20 Apr 2018
    5.3
    Medium

    CVE-2014-6109

    Last Modified: 21 Nov 2024

    IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information via vectors related to server side LDAP queries. IBM X-Force ID: 96173.

    Published: 20 Apr 2018
    7.8
    High

    CVE-2014-6111

    Last Modified: 21 Nov 2024

    IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 store encrypted user credentials and the keystore password in cleartext in configuration files, which allows local users to decrypt SIM credentials via unspecified vectors. IBM X-Force ID: 96180.

    Published: 20 Apr 2018
    6.5
    Medium

    CVE-2014-4782

    Last Modified: 21 Nov 2024

    IBM InfoSphere BigInsights 2.1.2 allows remote authenticated users to discover SMTP server credentials via vectors related to the Alert management service. IBM X-Force ID: 95029.

    Published: 20 Apr 2018