CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-16873

    Last Modified: 21 Nov 2024

    It is possible to exploit an unsanitized PATH in the suid binary that ships with vagrant-vmware-fusion 4.0.25 through 5.0.4 in order to escalate to root privileges.

    Published: 29 Mar 2018
    10
    Critical

    CVE-2016-0898

    Last Modified: 21 Nov 2024

    MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM.

    Published: 29 Mar 2018
    7.8
    High

    CVE-2017-16512

    Last Modified: 21 Nov 2024

    The vagrant update process in Hashicorp vagrant-vmware-fusion 5.0.2 through 5.0.4 allows local users to steal root privileges via a crafted update request when no updates are available.

    Published: 29 Mar 2018
    7
    High

    CVE-2017-16839

    Last Modified: 21 Nov 2024

    Hashicorp vagrant-vmware-fusion 5.0.4 allows local users to steal root privileges if VMware Fusion is not installed.

    Published: 29 Mar 2018
    9.6
    Critical

    CVE-2016-6658

    Last Modified: 21 Nov 2024

    Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (basic auth or OAuth) to access the buildpack through the CLI. For example, the user could include a GitHub username and password in the URL to access a private repo. Because the URL to access the buildpack is stored unencrypted, an operator with privileged access to the Cloud Controller database could view these credentials.

    Published: 29 Mar 2018
    8.8
    High

    CVE-2018-1191

    Last Modified: 21 Nov 2024

    Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using those credentials.

    Published: 29 Mar 2018
    9.8
    Critical

    CVE-2014-5170

    Last Modified: 21 Nov 2024

    The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveraging failure to update .htaccess file contents after SA-CORE-2013-003.

    Published: 29 Mar 2018
    6.1
    Medium

    CVE-2014-6604

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in class-s2-list-table.php in the Subscribe2 plugin before 10.16 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ip parameter.

    Published: 29 Mar 2018
    9.8
    Critical

    CVE-2015-2001

    Last Modified: 21 Nov 2024

    The MetaIO SDK before 6.0.2.1 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.

    Published: 29 Mar 2018
    4.8
    Medium

    CVE-2015-4953

    Last Modified: 21 Nov 2024

    IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for man-in-the-middle attackers to decrypt traffic by leveraging a weakness in its encryption protocol. IBM X-Force ID: 105197.

    Published: 29 Mar 2018
    9.8
    Critical

    CVE-2015-2002

    Last Modified: 21 Nov 2024

    The ESRI ArcGis Runtime SDK before 10.2.6-2 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.

    Published: 29 Mar 2018
    8.8
    High

    CVE-2015-2009

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in the xmlrpc.cgi service in IBM QRadar SIEM 7.1 before MR2 Patch 11 Interim Fix 02 and 7.2.x before 7.2.5 Patch 4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences via vectors related to webmin. IBM X-Force ID: 103921.

    Published: 29 Mar 2018
    8.8
    High

    CVE-2015-4952

    Last Modified: 21 Nov 2024

    The on-demand plugin in IBM Endpoint Manager for Remote Control 9.0.1 and 9.1.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. IBM X-Force ID: 105196.

    Published: 29 Mar 2018
    6.5
    Medium

    CVE-2014-5028

    Last Modified: 21 Nov 2024

    The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids.

    Published: 29 Mar 2018
    9.8
    Critical

    CVE-2015-2000

    Last Modified: 21 Nov 2024

    The Jumio SDK before 1.5.0 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.

    Published: 29 Mar 2018
    9.8
    Critical

    CVE-2015-2003

    Last Modified: 21 Nov 2024

    The PJSIP PJSUA2 SDK before SVN Changeset 51322 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.

    Published: 29 Mar 2018
    9.8
    Critical

    CVE-2015-2004

    Last Modified: 21 Nov 2024

    The GraceNote GNSDK SDK before SVN Changeset 1.1.7 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.

    Published: 29 Mar 2018
    9.8
    Critical

    CVE-2015-2020

    Last Modified: 21 Nov 2024

    The MyScript SDK before 1.3 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.

    Published: 29 Mar 2018
    6.8
    Medium

    CVE-2017-5947

    Last Modified: 21 Nov 2024

    An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier. The attacker can reboot the device into the Qualcomm Emergency Download (EDL) mode through ADB or by using Volume-Up when connected to USB, which in turn could allow for downgrading partitions such as the Android Bootloader.

    Published: 29 Mar 2018
    9.8
    Critical

    CVE-2018-9031

    Last Modified: 21 Nov 2024

    The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd ==" line in the HTML source code. This means, in effect, that authentication occurs only on the client side.

    Published: 29 Mar 2018
    Unknown

    CVE-2017-3788

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 29 Mar 2018
    Unknown

    CVE-2017-3789

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 29 Mar 2018
    Unknown

    CVE-2017-3785

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 29 Mar 2018
    Unknown

    CVE-2017-3786

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 29 Mar 2018
    Unknown

    CVE-2017-3787

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 29 Mar 2018
    Unknown

    CVE-2017-3777

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 29 Mar 2018
    Unknown

    CVE-2017-3778

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 29 Mar 2018
    Unknown

    CVE-2017-3779

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 29 Mar 2018
    Unknown

    CVE-2017-3780

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 29 Mar 2018
    Unknown

    CVE-2017-3781

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 29 Mar 2018
    Unknown

    CVE-2017-3782

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 29 Mar 2018
    Unknown

    CVE-2017-3783

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 29 Mar 2018
    Unknown

    CVE-2017-3784

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 29 Mar 2018
    9.8
    Critical

    CVE-2018-4841

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1). A remote attacker with network access to port 80/tcp or port 443/tcp could perform administrative operations on the device without prior authentication. Successful exploitation could allow to cause a denial-of-service, or read and manipulate data as well as configuration settings of the affected device. At the stage of publishing this security advisory no public exploitation is known. Siemens provides mitigations to resolve it.

    Published: 29 Mar 2018
    6.1
    Medium

    CVE-2018-6586

    Last Modified: 21 Nov 2024

    CA API Developer Portal 3.5 up to and including 3.5 CR6 has a stored cross-site scripting vulnerability related to profile picture processing.

    Published: 29 Mar 2018
    6.1
    Medium

    CVE-2018-6587

    Last Modified: 21 Nov 2024

    CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to the widgetID variable.

    Published: 29 Mar 2018
    7.2
    High

    CVE-2018-5223

    Last Modified: 21 Nov 2024

    Fisheye and Crucible did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to add a repository in Fisheye or Crucible can execute code of their choice on systems that run a vulnerable version of Fisheye or Crucible on the Windows operating system. All versions of Fisheye and Crucible before 4.4.6 (the fixed version for 4.4.x) and from 4.5.0 before 4.5.3 (the fixed version for 4.5.x) are affected by this vulnerability.

    Published: 29 Mar 2018
    6.1
    Medium

    CVE-2018-6588

    Last Modified: 21 Nov 2024

    CA API Developer Portal 3.5 up to and including 3.5 CR5 has a reflected cross-site scripting vulnerability related to the apiExplorer.

    Published: 29 Mar 2018
    8.8
    High

    CVE-2018-5224

    Last Modified: 21 Nov 2024

    Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan in Bamboo that has a non-linked Mercurial repository, or create a plan in Bamboo either globally or in a project using Bamboo Specs can can execute code of their choice on systems that run a vulnerable version of Bamboo on the Windows operating system. All versions of Bamboo starting with 2.7.0 before 6.3.3 (the fixed version for 6.3.x) and from version 6.4.0 before 6.4.1 (the fixed version for 6.4.x) running on the Windows operating system are affected by this vulnerability.

    Published: 29 Mar 2018
    9.1
    Critical

    CVE-2018-9116

    Last Modified: 21 Nov 2024

    An XXE vulnerability within WireMock before 2.16.0 allows a remote unauthenticated attacker to access local files and internal resources and potentially cause a Denial of Service.

    Published: 29 Mar 2018
    5.3
    Medium

    CVE-2018-9117

    Last Modified: 21 Nov 2024

    WireMock before 2.16.0 contains a vulnerability that allows a remote unauthenticated attacker to access local files beyond the application directory via a specially crafted XML request, aka Directory Traversal.

    Published: 29 Mar 2018
    9.8
    Critical

    CVE-2018-7600

    Last Modified: 31 Oct 2025

    Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.

    Published: 29 Mar 2018
    5.4
    Medium

    CVE-2018-9120

    Last Modified: 21 Nov 2024

    In Crea8social 2018.2, there is Stored Cross-Site Scripting via a post.

    Published: 29 Mar 2018
    5.4
    Medium

    CVE-2018-9121

    Last Modified: 21 Nov 2024

    In Crea8social 2018.2, there is Stored Cross-Site Scripting via a post comment.

    Published: 29 Mar 2018
    5.4
    Medium

    CVE-2018-9122

    Last Modified: 21 Nov 2024

    In Crea8social 2018.2, there is Reflected Cross-Site Scripting via the term parameter to the /search URI.

    Published: 29 Mar 2018
    5.4
    Medium

    CVE-2018-9123

    Last Modified: 21 Nov 2024

    In Crea8social 2018.2, there is Stored Cross-Site Scripting via a User Profile.

    Published: 29 Mar 2018
    6.5
    Medium

    CVE-2018-9133

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.

    Published: 29 Mar 2018
    8.6
    High

    CVE-2018-0173

    Last Modified: 14 Jan 2026

    A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a Relay Reply denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of encapsulated option 82 information that it receives in DHCPOFFER messages from DHCPv4 servers. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device, which the device would then forward to a DHCPv4 server. When the affected software processes the option 82 information that is encapsulated in the response from the server, an error could occur. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvg62754.

    Published: 28 Mar 2018
    6.3
    Medium

    CVE-2018-0161

    Last Modified: 14 Jan 2026

    A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition, aka a GET MIB Object ID Denial of Service Vulnerability. The vulnerability is due to a condition that could occur when the affected software processes an SNMP read request that contains a request for the ciscoFlashMIB object ID (OID). An attacker could trigger this vulnerability by issuing an SNMP GET request for the ciscoFlashMIB OID on an affected device. A successful exploit could cause the affected device to restart due to a SYS-3-CPUHOG. This vulnerability affects the following Cisco devices if they are running a vulnerable release of Cisco IOS Software and are configured to use SNMP Version 2 (SNMPv2) or SNMP Version 3 (SNMPv3): Cisco Catalyst 2960-L Series Switches, Cisco Catalyst Digital Building Series Switches 8P, Cisco Catalyst Digital Building Series Switches 8U. Cisco Bug IDs: CSCvd89541.

    Published: 28 Mar 2018
    8.6
    High

    CVE-2018-0157

    Last Modified: 2 Dec 2024

    A vulnerability in the Zone-Based Firewall code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a device to reload. The vulnerability is due to the way fragmented packets are handled in the firewall code. An attacker could exploit this vulnerability by sending fragmented IP Version 4 or IP Version 6 packets through an affected device. An exploit could allow the attacker to cause the device to crash, resulting in a denial of service (DoS) condition. The following releases of Cisco IOS XE Software are vulnerable: Everest-16.4.1, Everest-16.4.2, Everest-16.5.1, Everest-16.5.1b, Everest-16.6.1, Everest-16.6.1a. Cisco Bug IDs: CSCvf60296.

    Published: 28 Mar 2018