CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-6546

    Last Modified: 21 Nov 2024

    plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, executes code at a user-defined (local or SMB) path as SYSTEM when the execute_installer parameter is used in an HTTP message. This occurs without properly authenticating the user.

    Published: 13 Apr 2018
    9.1
    Critical

    CVE-2018-6547

    Last Modified: 21 Nov 2024

    plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, contains an HTTP message parsing function that takes a user-defined path and writes non-user controlled data as SYSTEM to the file when the extract_files parameter is used. This occurs without properly authenticating the user.

    Published: 13 Apr 2018
    9.8
    Critical

    CVE-2017-0359

    Last Modified: 21 Nov 2024

    diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.

    Published: 13 Apr 2018
    9.8
    Critical

    CVE-2017-0372

    Last Modified: 21 Nov 2024

    Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.

    Published: 13 Apr 2018
    4.8
    Medium

    CVE-2018-10096

    Last Modified: 21 Nov 2024

    joyplus-cms 1.6.0 has XSS via the device_name parameter in a manager/admin_ajax.php?action=save flag=add request.

    Published: 13 Apr 2018
    7.8
    High

    CVE-2017-0358

    Last Modified: 4 Dec 2025

    Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.

    Published: 13 Apr 2018
    5.3
    Medium

    CVE-2016-9646

    Last Modified: 21 Nov 2024

    ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata forgery.

    Published: 13 Apr 2018
    9.8
    Critical

    CVE-2017-0356

    Last Modified: 21 Nov 2024

    A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.

    Published: 13 Apr 2018
    9.8
    Critical

    CVE-2017-0357

    Last Modified: 21 Nov 2024

    A heap-overflow flaw exists in the -tr loader of iucode-tool starting with v1.4 and before v2.1.1, potentially leading to SIGSEGV, or heap corruption.

    Published: 13 Apr 2018
    5.9
    Medium

    CVE-2018-5508

    Last Modified: 21 Nov 2024

    On F5 BIG-IP PEM versions 13.0.0, 12.0.0-12.1.3.1, 11.6.0-11.6.2, 11.5.1-11.5.5, or 11.2.1, under certain conditions, TMM may crash when processing compressed data though a Virtual Server with an associated PEM profile using the content insertion option.

    Published: 13 Apr 2018
    6.1
    Medium

    CVE-2018-6958

    Last Modified: 21 Nov 2024

    VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. Exploitation of this issue may lead to the compromise of the vRA user's workstation.

    Published: 13 Apr 2018
    6.4
    Medium

    CVE-2017-6156

    Last Modified: 21 Nov 2024

    When the F5 BIG-IP 12.1.0-12.1.1, 11.6.0-11.6.1, 11.5.1-11.5.5, or 11.2.1 system is configured with a wildcard IPSec tunnel endpoint, it may allow a remote attacker to disrupt or impersonate the tunnels that have completed phase 1 IPSec negotiations. The attacker must possess the necessary credentials to negotiate the phase 1 of the IPSec exchange to exploit this vulnerability; in many environment this limits the attack surface to other endpoints under the same administration.

    Published: 13 Apr 2018
    5.4
    Medium

    CVE-2017-6143

    Last Modified: 21 Nov 2024

    X509 certificate verification was not correctly implemented in the IP Intelligence Subscription and IP Intelligence feed-list features, and thus the remote server's identity is not properly validated in F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.2, or 11.5.0-11.5.5.

    Published: 13 Apr 2018
    7.5
    High

    CVE-2017-6155

    Last Modified: 21 Nov 2024

    On F5 BIG-IP 13.0.0, 12.0.0-12.1.3.1, 11.6.0-11.6.2, 11.4.1-11.5.5, or 11.2.1, malformed SPDY or HTTP/2 requests may result in a disruption of service to TMM. Data plane is only exposed when a SPDY or HTTP/2 profile is attached to a virtual server. There is no control plane exposure.

    Published: 13 Apr 2018
    6.5
    Medium

    CVE-2017-6158

    Last Modified: 21 Nov 2024

    In F5 BIG-IP 12.0.0-12.1.2, 11.6.0-11.6.1, 11.5.1-11.5.5, or 11.2.1 there is a vulnerability in TMM related to handling of invalid IP addresses.

    Published: 13 Apr 2018
    9.8
    Critical

    CVE-2018-5506

    Last Modified: 21 Nov 2024

    In F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.1, 11.5.1-11.5.5, or 11.2.1 the Apache modules apache_auth_token_mod and mod_auth_f5_auth_token.cpp allow possible unauthenticated bruteforce on the em_server_ip authorization parameter to obtain which SSL client certificates used for mutual authentication between BIG-IQ or Enterprise Manager (EM) and managed BIG-IP devices.

    Published: 13 Apr 2018
    7.5
    High

    CVE-2018-5510

    Last Modified: 21 Nov 2024

    On F5 BIG-IP 11.5.4 HF4-11.5.5, the Traffic Management Microkernel (TMM) may restart when processing a specific sequence of packets on IPv6 virtual servers.

    Published: 13 Apr 2018
    9.8
    Critical

    CVE-2018-6959

    Last Modified: 21 Nov 2024

    VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs. Exploitation of this issue may lead to the hijacking of a valid vRA user's session.

    Published: 13 Apr 2018
    7.5
    High

    CVE-2017-6148

    Last Modified: 21 Nov 2024

    Responses to SOCKS proxy requests made through F5 BIG-IP version 13.0.0, 12.0.0-12.1.3.1, 11.6.1-11.6.2, or 11.5.1-11.5.5 may cause a disruption of services provided by TMM. The data plane is impacted and exposed only when a SOCKS proxy profile is attached to a Virtual Server. The control plane is not impacted by this vulnerability.

    Published: 13 Apr 2018
    8.1
    High

    CVE-2018-10066

    Last Modified: 21 Nov 2024

    An issue was discovered in MikroTik RouterOS 6.41.4. Missing OpenVPN server certificate verification allows a remote unauthenticated attacker capable of intercepting client traffic to act as a malicious OpenVPN server. This may allow the attacker to gain access to the client's internal network (for example, at site-to-site tunnels).

    Published: 13 Apr 2018
    7.5
    High

    CVE-2018-5507

    Last Modified: 21 Nov 2024

    On F5 BIG-IP versions 13.0.0, 12.1.0-12.1.3.1, 11.6.1-11.6.2, or 11.5.1-11.5.5, vCMP guests running on VIPRION 2100, 4200 and 4300 series blades cannot correctly decrypt ciphertext from established SSL sessions with small MTU.

    Published: 13 Apr 2018
    7.2
    High

    CVE-2018-5511

    Last Modified: 21 Nov 2024

    On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.

    Published: 13 Apr 2018
    9.8
    Critical

    CVE-2018-10081

    Last Modified: 21 Nov 2024

    CMS Made Simple (CMSMS) through 2.2.6 contains an admin password reset vulnerability because data values are improperly compared, as demonstrated by a hash beginning with the "0e" substring.

    Published: 13 Apr 2018
    5.3
    Medium

    CVE-2018-10082

    Last Modified: 21 Nov 2024

    CMS Made Simple (CMSMS) through 2.2.7 allows physical path leakage via an invalid /index.php?page= value, a crafted URI starting with /index.php?mact=Search, or a direct request to /admin/header.php, /admin/footer.php, /lib/tasks/class.ClearCache.task.php, or /lib/tasks/class.CmsSecurityCheck.task.php.

    Published: 13 Apr 2018
    7.5
    High

    CVE-2018-10083

    Last Modified: 21 Nov 2024

    CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary file deletion vulnerability in the admin dashboard via directory traversal sequences in the val parameter within a cmd=del request, because code under modules\FilePicker does not restrict the val parameter.

    Published: 13 Apr 2018
    8.8
    High

    CVE-2018-10084

    Last Modified: 21 Nov 2024

    CMS Made Simple (CMSMS) through 2.2.6 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value within $_COOKIE[$this->_loginkey] to equal 1, because an SHA-1 cryptographic protection mechanism can be bypassed.

    Published: 13 Apr 2018
    9.8
    Critical

    CVE-2018-10085

    Last Modified: 21 Nov 2024

    CMS Made Simple (CMSMS) through 2.2.6 allows PHP object injection because of an unserialize call in the _get_data function of \lib\classes\internal\class.LoginOperations.php. By sending a crafted cookie, a remote attacker can upload and execute code, or delete files.

    Published: 13 Apr 2018
    7.2
    High

    CVE-2018-10086

    Last Modified: 21 Nov 2024

    CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because the implementation uses "eval('function testfunction'.rand()" and it is possible to bypass certain restrictions on these "testfunction" functions.

    Published: 13 Apr 2018
    8.6
    High

    CVE-2018-10080

    Last Modified: 21 Nov 2024

    Secutech RiS-11, RiS-22, and RiS-33 devices with firmware V5.07.52_es_FRI01 allow DNS settings changes via a goform/AdvSetDns?GO=wan_dns.asp request in conjunction with a crafted admin cookie.

    Published: 13 Apr 2018
    5.5
    Medium

    CVE-2018-12641

    Last Modified: 21 Nov 2024

    An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_arm_hp_template, demangle_class_name, demangle_fund_type, do_type, do_arg, demangle_args, and demangle_nested_args. This can occur during execution of nm-new.

    Published: 13 Apr 2018
    6.1
    Medium

    CVE-2018-6870

    Last Modified: 21 Nov 2024

    Reflected XSS exists in PHP Scripts Mall Website Seller Script 2.0.3 via the Listings Search feature.

    Published: 12 Apr 2018
    8.8
    High

    CVE-2018-6879

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Website Seller Script 2.0.3 uses the client side to enforce validation of an e-mail address, which allows remote attackers to modify a registered e-mail address by removing the validation code.

    Published: 12 Apr 2018
    5.4
    Medium

    CVE-2018-6900

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Website Broker Script 3.0.6 has XSS via the Last Name field on the My Profile page.

    Published: 12 Apr 2018
    5.4
    Medium

    CVE-2018-6902

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Image Sharing Script 1.3.3 has XSS via the Full Name field in an Edit Profile action.

    Published: 12 Apr 2018
    8.8
    High

    CVE-2018-6903

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Hot Scripts Clone Script Classified v3.1 uses the client side to enforce validation of an e-mail address, which allows remote attackers to modify a registered e-mail address by removing the validation code.

    Published: 12 Apr 2018
    5.4
    Medium

    CVE-2018-6904

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the User Name field in an Edit Profile action.

    Published: 12 Apr 2018
    5.4
    Medium

    CVE-2018-6935

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Student Profile Management System Script v2.0.6 has XSS via the Name field to list_student.php.

    Published: 12 Apr 2018
    8.8
    High

    CVE-2018-6934

    Last Modified: 21 Nov 2024

    CSRF exists in student/personal-info in PHP Scripts Mall Online Tutoring Script 2.0.3.

    Published: 12 Apr 2018
    5.4
    Medium

    CVE-2014-6169

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.0 and 8.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 97777.

    Published: 12 Apr 2018
    7.5
    High

    CVE-2018-5254

    Last Modified: 21 Nov 2024

    Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message.

    Published: 12 Apr 2018
    9.8
    Critical

    CVE-2015-0152

    Last Modified: 21 Nov 2024

    D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the administrative password.

    Published: 12 Apr 2018
    7.5
    High

    CVE-2014-8421

    Last Modified: 21 Nov 2024

    Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gain super-user privileges by leveraging SSH access and incorrect ownership of (1) ConfigureCoreFile.sh, (2) Traceroute.sh, (3) apps.sh, (4) conversion_java2native.sh, (5) coreCompression.sh, (6) deletePasswd.sh, (7) findHealthSvcFDs.sh, (8) fw_printenv.sh, (9) fw_setenv.sh, (10) hw_wd_kicker.sh, (11) new_rootfs.sh, (12) opera_killSnmpd.sh, (13) opera_startSnmpd.sh, (14) rebootOperaSoftware.sh, (15) removeLogFiles.sh, (16) runOperaServices.sh, (17) setPasswd.sh, (18) startAccTestSvcs.sh, (19) usbNotification.sh, or (20) appWeb in /Opera_Deploy.

    Published: 12 Apr 2018
    8.1
    High

    CVE-2014-8422

    Last Modified: 21 Nov 2024

    The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generates session cookies with insufficient entropy, which makes it easier for remote attackers to hijack sessions via a brute-force attack.

    Published: 12 Apr 2018
    9.8
    Critical

    CVE-2014-6120

    Last Modified: 21 Nov 2024

    IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow remote attackers to execute arbitrary commands on the installation server via unspecified vectors. IBM X-Force ID: 96721.

    Published: 12 Apr 2018
    4.9
    Medium

    CVE-2014-9563

    Last Modified: 21 Nov 2024

    CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allows remote authenticated users to modify the root password and consequently access the debug port using the serial interface via the ssh-password parameter to page.cmd.

    Published: 12 Apr 2018
    7.5
    High

    CVE-2015-0153

    Last Modified: 21 Nov 2024

    D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the wireless key.

    Published: 12 Apr 2018
    8.1
    High

    CVE-2014-6412

    Last Modified: 21 Nov 2024

    WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

    Published: 12 Apr 2018
    9.8
    Critical

    CVE-2014-8888

    Last Modified: 21 Nov 2024

    The remote administration interface in D-Link DIR-815 devices with firmware before 2.03.B02 allows remote attackers to execute arbitrary commands via vectors related to an "HTTP command injection issue."

    Published: 12 Apr 2018
    9.8
    Critical

    CVE-2015-0150

    Last Modified: 21 Nov 2024

    The remote administration UI in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to bypass intended access restrictions via unspecified vectors.

    Published: 12 Apr 2018
    8.8
    High

    CVE-2015-0151

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 12 Apr 2018