CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2018-8780

    Last Modified: 21 Nov 2024

    In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method, unintentional directory traversal may be performed.

    Published: 28 Mar 2018
    3.3
    Low

    CVE-2018-9146

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-17724. Reason: This candidate is a reservation duplicate of CVE-2017-17724. Notes: All CVE users should reference CVE-2017-17724 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Mar 2018
    5.3
    Medium

    CVE-2017-17742

    Last Modified: 21 Nov 2024

    Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 allows an HTTP Response Splitting attack. An attacker can inject a crafted key and value into an HTTP response for the HTTP server of WEBrick.

    Published: 28 Mar 2018
    7.5
    High

    CVE-2018-9263

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the Kerberos dissector could crash. This was addressed in epan/dissectors/packet-kerberos.c by ensuring a nonzero key length.

    Published: 28 Mar 2018
    4.3
    Medium

    CVE-2017-15137

    Last Modified: 21 Nov 2024

    The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be allowed.

    Published: 28 Mar 2018
    6.5
    Medium

    CVE-2018-1096

    Last Modified: 21 Nov 2024

    An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.

    Published: 28 Mar 2018
    7.5
    High

    CVE-2018-6914

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files via a .. (dot dot) in the prefix argument.

    Published: 28 Mar 2018
    7.5
    High

    CVE-2018-8777

    Last Modified: 21 Nov 2024

    In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with a crafted header to WEBrick server or a crafted body to WEBrick server/handler and cause a denial of service (memory consumption).

    Published: 28 Mar 2018
    7.5
    High

    CVE-2018-8778

    Last Modified: 21 Nov 2024

    In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-read in the String#unpack method, resulting in a massive and controlled information disclosure.

    Published: 28 Mar 2018
    7.5
    High

    CVE-2018-8779

    Last Modified: 21 Nov 2024

    In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open methods are not checked for null characters. It may be connected to an unintended socket.

    Published: 28 Mar 2018
    8.1
    High

    CVE-2018-9144

    Last Modified: 21 Nov 2024

    In Exiv2 0.26, there is an out-of-bounds read in Exiv2::Internal::binaryToString in image.cpp. It could result in denial of service or information disclosure.

    Published: 28 Mar 2018
    8.8
    High

    CVE-2018-9105

    Last Modified: 21 Nov 2024

    NordVPN 3.3.10 for macOS suffers from a root privilege escalation vulnerability. The vulnerability stems from its privileged helper tool's implemented XPC service. This XPC service is responsible for receiving and processing new OpenVPN connection requests from the main application. Unfortunately this XPC service is not protected, which allows arbitrary applications to connect and send it XPC messages. An attacker can send a crafted XPC message to the privileged helper tool requesting it make a new OpenVPN connection. Because he or she controls the contents of the XPC message, the attacker can specify the location of the openvpn executable, which could point to something malicious they control located on disk. Without validation of the openvpn executable, this will give the attacker code execution in the context of the privileged helper tool.

    Published: 27 Mar 2018
    8.8
    High

    CVE-2018-9092

    Last Modified: 21 Nov 2024

    There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.

    Published: 27 Mar 2018
    6.5
    Medium

    CVE-2014-5130

    Last Modified: 21 Nov 2024

    Avolve Software ProjectDox 8.1 allows remote authenticated users to obtain sensitive information from other users via vectors involving a direct access token.

    Published: 27 Mar 2018
    7.5
    High

    CVE-2018-1238

    Last Modified: 21 Nov 2024

    Dell EMC ScaleIO versions prior to 2.5, contain a command injection vulnerability in the Light Installation Agent (LIA). This component is used for central management of ScaleIO deployment and uses shell commands for certain actions. A remote malicious user, with network access to LIA and knowledge of the LIA administrative password, could potentially exploit this vulnerability to run arbitrary commands as root on the systems where LIAs are installed.

    Published: 27 Mar 2018
    5.5
    Medium

    CVE-2018-9058

    Last Modified: 21 Nov 2024

    In Long Range Zip (aka lrzip) 0.631, there is an infinite loop in the runzip_fd function of runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.

    Published: 27 Mar 2018
    6.5
    Medium

    CVE-2014-5131

    Last Modified: 21 Nov 2024

    Avolve Software ProjectDox 8.1 makes it easier for remote authenticated users to obtain sensitive information by leveraging ciphertext reuse.

    Published: 27 Mar 2018
    7.5
    High

    CVE-2018-1205

    Last Modified: 21 Nov 2024

    Dell EMC ScaleIO, versions prior to 2.5, do not properly handle some packet data in the MDM service. As a result, a remote attacker could potentially send specifically crafted packet data to the MDM service causing it to crash.

    Published: 27 Mar 2018
    4.3
    Medium

    CVE-2014-5132

    Last Modified: 21 Nov 2024

    Avolve Software ProjectDox 8.1 allows remote attackers to enumerate users via vectors related to email addresses.

    Published: 27 Mar 2018
    5.3
    Medium

    CVE-2017-7630

    Last Modified: 21 Nov 2024

    QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware version and running services) via a request to sysinfoReq.cgi.

    Published: 27 Mar 2018
    6.1
    Medium

    CVE-2017-7631

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the share link function of File Station of QNAP 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML.

    Published: 27 Mar 2018
    6.1
    Medium

    CVE-2017-7632

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in File Station of QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML.

    Published: 27 Mar 2018
    9.8
    Critical

    CVE-2018-1237

    Last Modified: 21 Nov 2024

    Dell EMC ScaleIO versions prior to 2.5, contain improper restriction of excessive authentication attempts on the Light installation Agent (LIA). This component is deployed on every server in the ScaleIO cluster and is used for central management of ScaleIO nodes. A remote malicious user, having network access to LIA, could potentially exploit this vulnerability to launch brute force guessing of user names and passwords of user accounts on the LIA.

    Published: 27 Mar 2018
    8.8
    High

    CVE-2018-7700

    Last Modified: 21 Nov 2024

    DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.

    Published: 27 Mar 2018
    9.8
    Critical

    CVE-2018-9057

    Last Modified: 21 Nov 2024

    aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG algorithm and seeding, which makes it easier for remote attackers to obtain access by leveraging an IAM account that was provisioned with a weak password.

    Published: 27 Mar 2018
    7.8
    High

    CVE-2018-6765

    Last Modified: 21 Nov 2024

    Swisscom MySwisscomAssistant 2.17.1.1065 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge. The specific flaw exists within the handling of several DLLs (dwmapi.dll, IPHLPAPI.DLL, WindowsCodecs.dll, RpcRtRemote.dll, CRYPTSP.dll, rasadhlp.dll, DNSAPI.dll, ntmarta.dll, netbios.dll, olepro32.dll, security.dll, winhttp.dll, WINSTA.dll) loaded by the MySwisscomAssistant_Setup.exe process.

    Published: 27 Mar 2018
    7.8
    High

    CVE-2018-6766

    Last Modified: 21 Nov 2024

    Swisscom TVMediaHelper 1.1.0.50 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge. The specific flaw exists within the handling of several DLLs (dwmapi.dll, PROPSYS.dll, cscapi.dll, SAMLIB.dll, netbios.dll, winhttp.dll, security.dll, ntmarta.dll, WindowsCodecs.dll, apphelp.dll) loaded by the SwisscomTVMediaHelper.exe process.

    Published: 27 Mar 2018
    6.1
    Medium

    CVE-2018-7192

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "message" parameter.

    Published: 27 Mar 2018
    6.1
    Medium

    CVE-2018-7193

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "order" parameter.

    Published: 27 Mar 2018
    4.9
    Medium

    CVE-2018-7194

    Last Modified: 21 Nov 2024

    Integer format vulnerability in the ticket number generator in Enhancesoft osTicket before 1.10.2 allows remote attackers to cause a denial-of-service (preventing the creation of new tickets) via a large number of digits in the ticket number format setting.

    Published: 27 Mar 2018
    8.1
    High

    CVE-2018-7195

    Last Modified: 21 Nov 2024

    Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging guest access and guessing a 6-digit number.

    Published: 27 Mar 2018
    6.1
    Medium

    CVE-2018-7196

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "sort" parameter.

    Published: 27 Mar 2018
    5.9
    Medium

    CVE-2015-4954

    Last Modified: 21 Nov 2024

    IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 improperly allows self-signed certificates, which might allow remote attackers to conduct spoofing attacks via unspecified vectors. IBM X-Force ID: 105200.

    Published: 27 Mar 2018
    6.5
    Medium

    CVE-2015-4987

    Last Modified: 21 Nov 2024

    The search and replay servers in IBM Tealeaf Customer Experience 8.0 through 9.0.2 allow remote attackers to bypass authentication via unspecified vectors. IBM X-Force ID: 105896.

    Published: 27 Mar 2018
    4.3
    Medium

    CVE-2015-5016

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 106460.

    Published: 27 Mar 2018
    5.6
    Medium

    CVE-2018-9056

    Last Modified: 21 Nov 2024

    Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on the directional branch predictor, as demonstrated by a pattern history table (PHT), aka BranchScope.

    Published: 27 Mar 2018
    8.8
    High

    CVE-2018-1231

    Last Modified: 21 Nov 2024

    Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH CLI can access the BOSH CLI configuration file and use its contents to perform authenticated requests to BOSH.

    Published: 27 Mar 2018
    8.1
    High

    CVE-2018-1266

    Last Modified: 21 Nov 2024

    Cloud Foundry Cloud Controller, versions prior to 1.52.0, contains information disclosure and path traversal vulnerabilities. An authenticated malicious user can predict the location of application blobs and leverage path traversal to create a malicious application that has the ability to overwrite arbitrary files on the Cloud Controller instance.

    Published: 27 Mar 2018
    8.8
    High

    CVE-2018-8764

    Last Modified: 21 Nov 2024

    Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.

    Published: 27 Mar 2018
    7.5
    High

    CVE-2014-0486

    Last Modified: 21 Nov 2024

    Knot DNS before 1.5.2 allows remote attackers to cause a denial of service (application crash) via a crafted DNS message.

    Published: 27 Mar 2018
    9.8
    Critical

    CVE-2014-4959

    Last Modified: 21 Nov 2024

    **DISPUTED** SQL injection vulnerability in SQLiteDatabase.java in the SQLi Api in Android allows remote attackers to execute arbitrary SQL commands via the delete method.

    Published: 27 Mar 2018
    8.1
    High

    CVE-2018-1267

    Last Modified: 21 Nov 2024

    Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control vulnerability. If the platform is configured with an application security group (ASG) that overlaps with the Silk overlay network, any applications can reach any other application on the network regardless of the configured routing policies.

    Published: 27 Mar 2018
    6.1
    Medium

    CVE-2018-6882

    Last Modified: 4 Nov 2025

    Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.

    Published: 27 Mar 2018
    6.1
    Medium

    CVE-2018-8763

    Last Modified: 21 Nov 2024

    Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI.

    Published: 27 Mar 2018
    5.3
    Medium

    CVE-2018-0198

    Last Modified: 2 Dec 2024

    A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitive data. The vulnerability is due to insufficient protection of database tables. An attacker could exploit this vulnerability by browsing to a specific URL. A successful exploit could allow the attacker to view data library information. Cisco Bug IDs: CSCvh66592.

    Published: 27 Mar 2018
    5.5
    Medium

    CVE-2018-0202

    Last Modified: 2 Dec 2024

    clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanisms when handling Portable Document Format (.pdf) files sent to an affected device. An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted .pdf file to an affected device. This action could cause an out-of-bounds read when ClamAV scans the malicious file, allowing the attacker to cause a DoS condition. This concerns pdf_parse_array and pdf_parse_string in libclamav/pdfng.c. Cisco Bug IDs: CSCvh91380, CSCvh91400.

    Published: 27 Mar 2018
    7.5
    High

    CVE-2017-12310

    Last Modified: 2 Dec 2024

    A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive information in the unencrypted headers of an HTTP method request. The attacker could use this information to conduct additional reconnaissance attacks leading to the disclosure of sensitive customer data. The vulnerability exists in the auto discovery phase because an unencrypted HTTP request is made due to requirements for implementing the Hybrid Calendar service. An attacker could exploit this vulnerability by monitoring the unencrypted traffic on the network. An exploit could allow the attacker to access sensitive customer data belonging to Office365 users, such as email and calendar events. Cisco Bug IDs: CSCvg35593.

    Published: 27 Mar 2018
    5.9
    Medium

    CVE-2017-12319

    Last Modified: 13 Jan 2026

    A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability. The vulnerability exists due to changes in the implementation of the BGP MPLS-Based Ethernet VPN RFC (RFC 7432) draft between IOS XE software releases. When the BGP Inclusive Multicast Ethernet Tag Route or BGP EVPN MAC/IP Advertisement Route update packet is received, it could be possible that the IP address length field is miscalculated. An attacker could exploit this vulnerability by sending a crafted BGP packet to an affected device after the BGP session was established. An exploit could allow the attacker to cause the affected device to reload or corrupt the BGP routing table; either outcome would result in a DoS. The vulnerability may be triggered when the router receives a crafted BGP message from a peer on an existing BGP session. This vulnerability affects all releases of Cisco IOS XE Software prior to software release 16.3 that support BGP EVPN configurations. If the device is not configured for EVPN, it is not vulnerable. Cisco Bug IDs: CSCui67191, CSCvg52875.

    Published: 27 Mar 2018
    9.8
    Critical

    CVE-2018-9032

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version : 1.02-2.06) devices potentially allows attackers to bypass SharePort Web Access Portal by directly visiting /category_view.php or /folder_view.php.

    Published: 27 Mar 2018
    6.5
    Medium

    CVE-2018-9039

    Last Modified: 21 Nov 2024

    In Octopus Deploy 2.0 and later before 2018.3.7, an authenticated user, with variable edit permissions, can scope some variables to targets greater than their permissions should allow. In other words, they can see machines beyond their team's scoped environments.

    Published: 27 Mar 2018