CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2017-13296

    Last Modified: 21 Nov 2024

    A information disclosure vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70897454.

    Published: 4 Apr 2018
    5.3
    Medium

    CVE-2017-13297

    Last Modified: 21 Nov 2024

    A information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71766721.

    Published: 4 Apr 2018
    5.3
    Medium

    CVE-2017-13298

    Last Modified: 21 Nov 2024

    A information disclosure vulnerability in the Android media framework (libhavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-72117051.

    Published: 4 Apr 2018
    7.5
    High

    CVE-2017-13299

    Last Modified: 21 Nov 2024

    A other vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70897394.

    Published: 4 Apr 2018
    5.3
    Medium

    CVE-2017-13303

    Last Modified: 21 Nov 2024

    A information disclosure vulnerability in the Broadcom bcmdhd driver. Product: Android. Versions: Android kernel. Android ID: A-71359108. References: B-V2018010501.

    Published: 4 Apr 2018
    5.3
    Medium

    CVE-2017-13304

    Last Modified: 21 Nov 2024

    A information disclosure vulnerability in the Upstream kernel mnh_sm driver. Product: Android. Versions: Android kernel. Android ID: A-70576999.

    Published: 4 Apr 2018
    7.3
    High

    CVE-2017-13306

    Last Modified: 21 Nov 2024

    A elevation of privilege vulnerability in the Upstream kernel mnh driver. Product: Android. Versions: Android kernel. Android ID: A-70295063.

    Published: 4 Apr 2018
    7.3
    High

    CVE-2017-13307

    Last Modified: 21 Nov 2024

    A elevation of privilege vulnerability in the Upstream kernel pci sysfs. Product: Android. Versions: Android kernel. Android ID: A-69128924.

    Published: 4 Apr 2018
    6.5
    Medium

    CVE-2018-8814

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that modify plugin/[pluginname]/settings by crafting a malicious request.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2018-9248

    Last Modified: 21 Nov 2024

    FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2018-9249

    Last Modified: 21 Nov 2024

    FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to an unauthenticated request.

    Published: 4 Apr 2018
    7.5
    High

    CVE-2018-9205

    Last Modified: 21 Nov 2024

    Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.

    Published: 4 Apr 2018
    4.8
    Medium

    CVE-2018-8813

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL.

    Published: 4 Apr 2018
    7.5
    High

    CVE-2018-6918

    Last Modified: 21 Nov 2024

    In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, the length field of the ipsec option header does not count the size of the option header itself, causing an infinite loop when the length is zero. This issue can allow a remote attacker who is able to send an arbitrary packet to cause the machine to crash.

    Published: 4 Apr 2018
    7.5
    High

    CVE-2018-6917

    Last Modified: 21 Nov 2024

    In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, insufficient validation of user-provided font parameters can result in an integer overflow, leading to the use of arbitrary kernel memory as glyph data. Unprivileged users may be able to access privileged kernel data.

    Published: 4 Apr 2018
    7.5
    High

    CVE-2018-6919

    Last Modified: 21 Nov 2024

    In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, due to insufficient initialization of memory copied to userland, small amounts of kernel memory may be disclosed to userland processes. Unprivileged users may be able to access small amounts privileged kernel data.

    Published: 4 Apr 2018
    6.4
    Medium

    CVE-2017-3966

    Last Modified: 21 Nov 2024

    Exploitation of session variables, resource IDs and other trusted credentials vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to exploit or harm a user's browser via reusing the exposed session token in the application URL.

    Published: 4 Apr 2018
    3.5
    Low

    CVE-2017-3964

    Last Modified: 21 Nov 2024

    Reflective Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to inject arbitrary web script or HTML via a URL parameter.

    Published: 4 Apr 2018
    8.2
    High

    CVE-2017-3969

    Last Modified: 21 Nov 2024

    Abuse of communication channels vulnerability in the server in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows man-in-the-middle attackers to decrypt messages via an inadequate implementation of SSL.

    Published: 4 Apr 2018
    8.8
    High

    CVE-2017-3965

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to perform unauthorized tasks such as retrieving internal system information or manipulating the database via specially crafted URLs.

    Published: 4 Apr 2018
    6.1
    Medium

    CVE-2017-3967

    Last Modified: 21 Nov 2024

    Target influence via framing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to inject arbitrary web script or HTML via application pages inability to break out of 3rd party HTML frames.

    Published: 4 Apr 2018
    8.2
    High

    CVE-2017-3971

    Last Modified: 21 Nov 2024

    Cryptanalysis vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to view confidential information via insecure use of RC4 encryption cyphers.

    Published: 4 Apr 2018
    7.2
    High

    CVE-2017-18096

    Last Modified: 21 Nov 2024

    The OAuth status rest resource in Atlassian Application Links before version 5.2.7, from 5.3.0 before 5.3.4 and from 5.4.0 before 5.4.3 allows remote attackers with administrative rights to access the content of internal network resources via a Server Side Request Forgery (SSRF) by creating an OAuth application link to a location they control and then redirecting access from the linked location's OAuth status rest resource to an internal location. When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information.

    Published: 4 Apr 2018
    5.4
    Medium

    CVE-2018-9236

    Last Modified: 21 Nov 2024

    iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field.

    Published: 4 Apr 2018
    5.4
    Medium

    CVE-2018-9237

    Last Modified: 21 Nov 2024

    iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.

    Published: 4 Apr 2018
    6.1
    Medium

    CVE-2018-9238

    Last Modified: 21 Nov 2024

    proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.

    Published: 4 Apr 2018
    6.1
    Medium

    CVE-2018-9235

    Last Modified: 21 Nov 2024

    iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.

    Published: 4 Apr 2018
    6.5
    Medium

    CVE-2017-18256

    Last Modified: 21 Nov 2024

    Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert() argument in JavaScript code, because window dialogs are mishandled.

    Published: 4 Apr 2018
    7.5
    High

    CVE-2016-10718

    Last Modified: 21 Nov 2024

    Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial of service.

    Published: 4 Apr 2018
    7.5
    High

    CVE-2018-1274

    Last Modified: 15 Jun 2026

    Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).

    Published: 4 Apr 2018
    6.5
    Medium

    CVE-2018-9303

    Last Modified: 21 Nov 2024

    In Exiv2 0.26, an assertion failure in BigTiffImage::readData in bigtiffimage.cpp results in an abort.

    Published: 4 Apr 2018
    6.5
    Medium

    CVE-2018-9304

    Last Modified: 21 Nov 2024

    In Exiv2 0.26, a divide by zero in BigTiffImage::printIFD in bigtiffimage.cpp could result in denial of service.

    Published: 4 Apr 2018
    8.1
    High

    CVE-2018-9305

    Last Modified: 21 Nov 2024

    In Exiv2 0.26, an out-of-bounds read in IptcData::printStructure in iptc.c could result in a crash or information leak, related to the "== 0x1c" case.

    Published: 4 Apr 2018
    4.4
    Medium

    CVE-2018-9306

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-17724. Reason: This candidate is a reservation duplicate of CVE-2017-17724. Notes: All CVE users should reference CVE-2017-17724 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 4 Apr 2018
    6.1
    Medium

    CVE-2018-9119

    Last Modified: 21 Nov 2024

    An attacker with physical access to a BrilliantTS FUZE card (MCU firmware 0.1.73, BLE firmware 0.7.4) can unlock the card, extract credit card numbers, and tamper with data on the card via Bluetooth because no authentication is needed, as demonstrated by gatttool.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2018-9247

    Last Modified: 21 Nov 2024

    The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execute arbitrary SQL statements via the sql parameter. Consequently, an attacker can execute arbitrary PHP code by placing it after a <?php substring, and then using INTO OUTFILE with a .php filename.

    Published: 4 Apr 2018
    8.8
    High

    CVE-2018-8941

    Last Modified: 21 Nov 2024

    Diagnostics functionality on D-Link DSL-3782 devices with firmware EU v. 1.01 has a buffer overflow, allowing authenticated remote attackers to execute arbitrary code via a long Addr value to the 'set Diagnostics_Entry' function in an HTTP request, related to /userfs/bin/tcapi.

    Published: 3 Apr 2018
    7.5
    High

    CVE-2018-8049

    Last Modified: 21 Nov 2024

    The Stealth endpoint in Unisys Stealth SVG 2.8.x, 3.0.x before 3.0.1999, 3.1.x, 3.2.x before 3.2.030, and 3.3.x before 3.3.016, when running on Linux and AIX, allows remote attackers to cause a denial of service (crash) via crafted packets.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2015-1975

    Last Modified: 21 Nov 2024

    The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 37 and IBM Security Directory Server 6.3.1 before iFix 11 and 6.4 before iFix 2 allows local users to gain privileges via vectors related to argument injection. IBM X-Force ID: 103694.

    Published: 3 Apr 2018
    7.5
    High

    CVE-2018-9240

    Last Modified: 21 Nov 2024

    ncmpc through 0.29 is prone to a NULL pointer dereference flaw. If a user uses the chat screen and another client sends a long chat message, a crash and denial of service could occur.

    Published: 3 Apr 2018
    8.3
    High

    CVE-2017-3972

    Last Modified: 21 Nov 2024

    Infrastructure-based foot printing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to execute arbitrary code via the server banner leaking potentially sensitive or security relevant information.

    Published: 3 Apr 2018
    5
    Medium

    CVE-2017-4028

    Last Modified: 21 Nov 2024

    Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2018-3638

    Last Modified: 21 Nov 2024

    Escalation of privilege in all versions of the Intel Remote Keyboard allows an authorized local attacker to execute arbitrary code as a privileged user.

    Published: 3 Apr 2018
    9.8
    Critical

    CVE-2018-3641

    Last Modified: 21 Nov 2024

    Escalation of privilege in all versions of the Intel Remote Keyboard allows a network attacker to inject keystrokes as a local user.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2018-3645

    Last Modified: 21 Nov 2024

    Escalation of privilege in all versions of the Intel Remote Keyboard allows a local attacker to inject keystrokes into another remote keyboard session.

    Published: 3 Apr 2018
    6
    Medium

    CVE-2017-5703

    Last Modified: 21 Nov 2024

    Configuration of SPI Flash in platforms based on multiple Intel platforms allow a local attacker to alter the behavior of the SPI flash potentially leading to a Denial of Service.

    Published: 3 Apr 2018
    Unknown

    CVE-2017-3773

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Apr 2018
    7.3
    High

    CVE-2017-15836

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, if the firmware sends a service ready event to the host with a large number in the num_hw_modes or num_phy, then it could result in an integer overflow which may potentially lead to a buffer overflow.

    Published: 3 Apr 2018
    7.8
    High

    CVE-2018-3563

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, untrusted pointer dereference in apr_cb_func can lead to an arbitrary code execution.

    Published: 3 Apr 2018
    7.5
    High

    CVE-2018-3584

    Last Modified: 21 Nov 2024

    In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a Use After Free condition can occur in the function rmnet_usb_ctrl_init().

    Published: 3 Apr 2018