CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-18133

    Last Modified: 21 Nov 2024

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835, an out of bound access for ebi channel array can potentially occur.

    Published: 11 Apr 2018
    9.8
    Critical

    CVE-2017-18136

    Last Modified: 21 Nov 2024

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDM9635M, MDM9640, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 820, SD 820A, SD 835, SD 845, in the omx aac component, a Use After Free condition may potentially occur.

    Published: 11 Apr 2018
    9.8
    Critical

    CVE-2017-18137

    Last Modified: 21 Nov 2024

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile MDM9640, MDM9645, MDM9650, MDM9655, SD 450, SD 625, SD 650/52, SD 810, SD 820, SD 835, while processing the IPv6 pdp address of the pdp context, a buffer overflow can occur.

    Published: 11 Apr 2018
    9.8
    Critical

    CVE-2017-18138

    Last Modified: 21 Nov 2024

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 835, SD 845, SD 850, in GERAN, a buffer overflow may potentially occur.

    Published: 11 Apr 2018
    9.8
    Critical

    CVE-2017-18140

    Last Modified: 21 Nov 2024

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, when processing a call disconnection, there is an attempt to print the RIL token-id to the debug log. If eMBMS service is enabled while processing the call disconnect, a Use After Free condition may potentially occur.

    Published: 11 Apr 2018
    9.8
    Critical

    CVE-2017-18142

    Last Modified: 21 Nov 2024

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile MDM9650, MDM9655, SD 835, SD 845, SD 850, while processing the IMS SIP username, a buffer overflow can occur.

    Published: 11 Apr 2018
    9.8
    Critical

    CVE-2017-18145

    Last Modified: 21 Nov 2024

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 835, SD 845, while the DPM native process is processing framework events, the iterator pointer is deleted after processing an event. When processing subsequent events, a Use After Condition will occur.

    Published: 11 Apr 2018
    9.8
    Critical

    CVE-2017-18146

    Last Modified: 21 Nov 2024

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, in some corner cases, ECDSA signature verification can fail.

    Published: 11 Apr 2018
    9.8
    Critical

    CVE-2017-8274

    Last Modified: 21 Nov 2024

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, an access control vulnerability exists in Core.

    Published: 11 Apr 2018
    9.8
    Critical

    CVE-2018-3589

    Last Modified: 21 Nov 2024

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile MDM9650, MDM9655, SD 835, SD 845, SD 850, the vswr capture size is larger than the maximum size of a diag logPacket, which can lead to a buffer overflow when the sample buffer is copied to the logPacket buffer.

    Published: 11 Apr 2018
    9.8
    Critical

    CVE-2018-3590

    Last Modified: 21 Nov 2024

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 835, SD 845, a Use After Free condition can occur in RIL while handling requests from Android.

    Published: 11 Apr 2018
    9.8
    Critical

    CVE-2018-3591

    Last Modified: 21 Nov 2024

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 835, SD 845, SDM630, SDM636, SDM660, Snapdragon_High_Med_2016, the default build configuration of deviceprogrammer in BOOT.BF.3.0 enables the flag SKIP_SECBOOT_CHECK_NOT_RECOMMENDED_BY_QUALCOMM which will open up the peek and poke commands to any memory location on the target.

    Published: 11 Apr 2018
    9.8
    Critical

    CVE-2018-3592

    Last Modified: 21 Nov 2024

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 835, SD 845, SD 850, added a change to check if the pointer has been reset to NULL or not, before writing to the memory pointed by the pointer.

    Published: 11 Apr 2018
    9.8
    Critical

    CVE-2018-3594

    Last Modified: 21 Nov 2024

    In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 820, SD 820A, SD 835, SD 845, while parsing a private frame in an ID3 tag, a buffer over-read can occur when comparing frame data with predefined owner identifier strings.

    Published: 11 Apr 2018
    6.8
    Medium

    CVE-2016-10258

    Last Modified: 21 Nov 2024

    Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code.

    Published: 11 Apr 2018
    7.5
    High

    CVE-2017-13677

    Last Modified: 21 Nov 2024

    Denial-of-service (DoS) vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A remote attacker can use crafted HTTP/HTTPS requests to cause denial-of-service through management console application crashes.

    Published: 11 Apr 2018
    4.8
    Medium

    CVE-2017-13678

    Last Modified: 21 Nov 2024

    Stored XSS vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can inject arbitrary JavaScript code in the management console web client application.

    Published: 11 Apr 2018
    5.4
    Medium

    CVE-2018-7659

    Last Modified: 21 Nov 2024

    In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Stored Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via a filename of an uploaded image file.

    Published: 11 Apr 2018
    5.4
    Medium

    CVE-2018-7660

    Last Modified: 21 Nov 2024

    In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Reflected Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via the servlet/Download _docbase or _username parameter.

    Published: 11 Apr 2018
    4.8
    Medium

    CVE-2018-9991

    Last Modified: 21 Nov 2024

    Frog CMS 0.9.5 has XSS via the /admin/?/user/add Name or Username parameter.

    Published: 11 Apr 2018
    4.8
    Medium

    CVE-2018-9992

    Last Modified: 21 Nov 2024

    Frog CMS 0.9.5 has XSS via the name field of a new "File" or "Directory" on the admin/?/plugin/file_manager/browse/ screen.

    Published: 11 Apr 2018
    6.5
    Medium

    CVE-2018-10017

    Last Modified: 21 Nov 2024

    soundlib/Snd_fx.cpp in OpenMPT before 1.27.07.00 and libopenmpt before 0.3.8 allows remote attackers to cause a denial of service (out-of-bounds read) via an IT or MO3 file with many nested pattern loops.

    Published: 11 Apr 2018
    6.5
    Medium

    CVE-2018-10001

    Last Modified: 21 Nov 2024

    The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) via an AVI file.

    Published: 11 Apr 2018
    8.8
    High

    CVE-2017-18260

    Last Modified: 21 Nov 2024

    Dolibarr ERP/CRM is affected by multiple SQL injection vulnerabilities in versions through 7.0.0 via comm/propal/list.php (viewstatut parameter) or comm/propal/list.php (propal_statut parameter, aka search_statut parameter).

    Published: 11 Apr 2018
    5.4
    Medium

    CVE-2017-18259

    Last Modified: 21 Nov 2024

    Dolibarr ERP/CRM is affected by stored Cross-Site Scripting (XSS) in versions through 7.0.0.

    Published: 11 Apr 2018
    8.8
    High

    CVE-2017-9839

    Last Modified: 21 Nov 2024

    Dolibarr ERP/CRM is affected by SQL injection in versions before 5.0.4 via product/stats/card.php (type parameter).

    Published: 11 Apr 2018
    5.4
    Medium

    CVE-2017-9838

    Last Modified: 21 Nov 2024

    Dolibarr ERP/CRM is affected by multiple reflected Cross-Site Scripting (XSS) vulnerabilities in versions before 5.0.4: index.php (leftmenu parameter), core/ajax/box.php (PATH_INFO), product/stats/card.php (type parameter), holiday/list.php (month_create, month_start, and month_end parameters), and don/card.php (societe, lastname, firstname, address, zipcode, town, and email parameters).

    Published: 11 Apr 2018
    6.1
    Medium

    CVE-2018-10000

    Last Modified: 21 Nov 2024

    The Video Downloader professional extension before 2018-04-05 for Chrome has Universal XSS (UXSS) via vectors related to a link64_msgAddLinks event.

    Published: 11 Apr 2018
    5.4
    Medium

    CVE-2018-1000170

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that allows attackers with Job/Configure and/or Job/Create permission to create an item name containing JavaScript that would be executed in another user's browser when that other user performs some UI actions.

    Published: 11 Apr 2018
    8.8
    High

    CVE-2018-10054

    Last Modified: 21 Nov 2024

    H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."

    Published: 11 Apr 2018
    6.6
    Medium

    CVE-2018-10840

    Last Modified: 21 Nov 2024

    Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by operating on a mounted crafted ext4 image.

    Published: 11 Apr 2018
    7.5
    High

    CVE-2018-12698

    Last Modified: 21 Nov 2024

    demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.

    Published: 11 Apr 2018
    9.8
    Critical

    CVE-2018-12699

    Last Modified: 21 Nov 2024

    finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.

    Published: 11 Apr 2018
    3.3
    Low

    CVE-2018-12700

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 11 Apr 2018
    5
    Medium

    CVE-2017-15138

    Last Modified: 21 Nov 2024

    The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook tokens.

    Published: 11 Apr 2018
    5.3
    Medium

    CVE-2018-1000169

    Last Modified: 21 Nov 2024

    An exposure of sensitive information vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in CLICommand.java and ViewOptionHandler.java that allows unauthorized attackers to confirm the existence of agents or views with an attacker-specified name by sending a CLI command to Jenkins.

    Published: 11 Apr 2018
    7.5
    High

    CVE-2018-12697

    Last Modified: 21 Nov 2024

    A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. This can occur during execution of objdump.

    Published: 11 Apr 2018
    7.5
    High

    CVE-2018-12934

    Last Modified: 21 Nov 2024

    remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt.

    Published: 11 Apr 2018
    6.5
    Medium

    CVE-2016-9645

    Last Modified: 21 Nov 2024

    The fix for ikiwiki for CVE-2016-10026 was incomplete resulting in editing restriction bypass for git revert when using git versions older than 2.8.0. This has been fixed in 3.20161229.

    Published: 10 Apr 2018
    9.8
    Critical

    CVE-2018-9995

    Last Modified: 21 Nov 2024

    TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.

    Published: 10 Apr 2018
    8.8
    High

    CVE-2018-3839

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.

    Published: 10 Apr 2018
    4.8
    Medium

    CVE-2018-9993

    Last Modified: 21 Nov 2024

    YUNUCMS 1.0.7 has XSS via the content title on an admin/content/addcontent/cid/## page (aka a news center page).

    Published: 10 Apr 2018
    5.5
    Medium

    CVE-2018-3837

    Last Modified: 21 Nov 2024

    An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted PCX image can cause an out-of-bounds read on the heap, resulting in information disclosure . An attacker can display a specially crafted image to trigger this vulnerability.

    Published: 10 Apr 2018
    6.5
    Medium

    CVE-2018-3838

    Last Modified: 21 Nov 2024

    An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds read on the heap, resulting in information disclosure. An attacker can display a specially crafted image to trigger this vulnerability.

    Published: 10 Apr 2018
    7.5
    High

    CVE-2018-9989

    Last Modified: 5 Jun 2026

    ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input.

    Published: 10 Apr 2018
    7.5
    High

    CVE-2018-9988

    Last Modified: 5 Jun 2026

    ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input.

    Published: 10 Apr 2018
    6.1
    Medium

    CVE-2018-8772

    Last Modified: 21 Nov 2024

    Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen.

    Published: 10 Apr 2018
    8.8
    High

    CVE-2018-9037

    Last Modified: 21 Nov 2024

    Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain .php files.

    Published: 10 Apr 2018
    6.5
    Medium

    CVE-2018-9038

    Last Modified: 21 Nov 2024

    Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.

    Published: 10 Apr 2018
    6.1
    Medium

    CVE-2018-9985

    Last Modified: 21 Nov 2024

    The front page of MetInfo 6.0 allows XSS by sending a feedback message to an administrator.

    Published: 10 Apr 2018