CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-9040

    Last Modified: 21 Nov 2024

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060c4.

    Published: 27 Mar 2018
    7.8
    High

    CVE-2018-9041

    Last Modified: 21 Nov 2024

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402004.

    Published: 27 Mar 2018
    7.8
    High

    CVE-2018-9042

    Last Modified: 21 Nov 2024

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402000.

    Published: 27 Mar 2018
    7.8
    High

    CVE-2018-9044

    Last Modified: 21 Nov 2024

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060cc.

    Published: 27 Mar 2018
    7.8
    High

    CVE-2018-9046

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100282d.

    Published: 27 Mar 2018
    7.8
    High

    CVE-2018-9047

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002841.

    Published: 27 Mar 2018
    7.8
    High

    CVE-2018-9048

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100282c.

    Published: 27 Mar 2018
    7.8
    High

    CVE-2018-9050

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100202d.

    Published: 27 Mar 2018
    7.8
    High

    CVE-2018-9051

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002021.

    Published: 27 Mar 2018
    7.8
    High

    CVE-2018-9052

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100283c.

    Published: 27 Mar 2018
    7.8
    High

    CVE-2018-9053

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf10026cc.

    Published: 27 Mar 2018
    7.8
    High

    CVE-2018-9054

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100284c.

    Published: 27 Mar 2018
    7.8
    High

    CVE-2018-9043

    Last Modified: 21 Nov 2024

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060d0.

    Published: 27 Mar 2018
    7.8
    High

    CVE-2018-9045

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002849.

    Published: 27 Mar 2018
    7.8
    High

    CVE-2018-9049

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002833.

    Published: 27 Mar 2018
    9.8
    Critical

    CVE-2018-1273

    Last Modified: 15 Jun 2026

    Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

    Published: 27 Mar 2018
    6.5
    Medium

    CVE-2018-0739

    Last Modified: 21 Nov 2024

    Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).

    Published: 27 Mar 2018
    5.9
    Medium

    CVE-2018-0733

    Last Modified: 21 Nov 2024

    Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least significant bit of each byte. This allows an attacker to forge messages that would be considered as authenticated in an amount of tries lower than that guaranteed by the security claims of the scheme. The module can only be compiled by the HP-UX assembler, so that only HP-UX PA-RISC targets are affected. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g).

    Published: 27 Mar 2018
    7.5
    High

    CVE-2018-1327

    Last Modified: 21 Nov 2024

    The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with specially crafted XML payload. Upgrade to the Apache Struts version 2.5.16 and switch to an optional Jackson XML handler as described here http://struts.apache.org/plugins/rest/#custom-contenttypehandlers. Another option is to implement a custom XML handler based on the Jackson XML handler from the Apache Struts 2.5.16.

    Published: 27 Mar 2018
    5.5
    Medium

    CVE-2018-9138

    Last Modified: 21 Nov 2024

    An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.29 and 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_nested_args, demangle_args, do_arg, and do_type.

    Published: 27 Mar 2018
    7.5
    High

    CVE-2018-7658

    Last Modified: 21 Nov 2024

    NTSServerSvc.exe in the server in Softros Network Time System 2.3.4 allows remote attackers to cause a denial of service (daemon crash) by sending exactly 11 bytes.

    Published: 26 Mar 2018
    7.4
    High

    CVE-2017-12410

    Last Modified: 21 Nov 2024

    It is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition when Kaseya Virtual System Administrator agent 9.3.0.11 and earlier tries to execute its binaries from working and/or temporary folders. Successful exploitation results in the execution of arbitrary programs with "NT AUTHORITY\SYSTEM" privileges.

    Published: 26 Mar 2018
    10
    Critical

    CVE-2017-12815

    Last Modified: 21 Nov 2024

    Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that it is vulnerable to a path traversal vulnerability. The archive can be downloaded from a given Bomgar Remote Support Portal deployment at https://domain/api/content/JavaStart.jar and is callable from an arbitrary website using <object> and/or <appletHTML> tags. Successful exploitation results in file creation/modification/deletion in the operating system and with privileges of the user that ran the Java applet.

    Published: 26 Mar 2018
    8.1
    High

    CVE-2018-8802

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the management interface in ePortal Manager allows remote attackers to execute arbitrary SQL commands via unspecified parameters.

    Published: 26 Mar 2018
    5.3
    Medium

    CVE-2018-1348

    Last Modified: 21 Nov 2024

    NetIQ Identity Manager driver, in versions prior to 4.7, allows for an SSL handshake renegotiation which could result in a MITM attack.

    Published: 26 Mar 2018
    2.3
    Low

    CVE-2018-1349

    Last Modified: 21 Nov 2024

    The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.

    Published: 26 Mar 2018
    2.3
    Low

    CVE-2018-1350

    Last Modified: 21 Nov 2024

    The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.

    Published: 26 Mar 2018
    5.1
    Medium

    CVE-2018-7673

    Last Modified: 21 Nov 2024

    The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack.

    Published: 26 Mar 2018
    8.8
    High

    CVE-2018-1213

    Last Modified: 21 Nov 2024

    Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 and 8.1.0.2 is affected by a cross-site request forgery vulnerability. A malicious user may potentially exploit this vulnerability to send unauthorized requests to the server on behalf of authenticated users of the application.

    Published: 26 Mar 2018
    4.8
    Medium

    CVE-2018-1189

    Last Modified: 21 Nov 2024

    Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Antivirus Page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.

    Published: 26 Mar 2018
    4.8
    Medium

    CVE-2018-1202

    Last Modified: 21 Nov 2024

    Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the NDMP Page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.

    Published: 26 Mar 2018
    6.7
    Medium

    CVE-2018-1204

    Last Modified: 21 Nov 2024

    Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a path traversal vulnerability in the isi_phone_home tool. A malicious compadmin may potentially exploit this vulnerability to execute arbitrary code with root privileges.

    Published: 26 Mar 2018
    9.8
    Critical

    CVE-2014-2293

    Last Modified: 21 Nov 2024

    Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary files or execute arbitrary PHP code via crafted serialized data in the (1) authentication_method_ser or (2) authentication_info_ser parameter to index.php, or (3) zikulaMobileTheme parameter to index.php.

    Published: 26 Mar 2018
    5.5
    Medium

    CVE-2014-2312

    Last Modified: 21 Nov 2024

    The main function in android_main.cpp in thermald allows local users to write to arbitrary files via a symlink attack on /tmp/thermald.pid.

    Published: 26 Mar 2018
    9.8
    Critical

    CVE-2014-2048

    Last Modified: 21 Nov 2024

    The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation.

    Published: 26 Mar 2018
    7.4
    High

    CVE-2015-5039

    Last Modified: 21 Nov 2024

    The Remote Client and change management integrations in IBM Rational ClearCase 7.1.x, 8.0.0.x before 8.0.0.18, and 8.0.1.x before 8.0.1.11 do not properly validate hostnames in X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive information or modify network traffic via a crafted certificate. IBM X-Force ID: 106715.

    Published: 26 Mar 2018
    3.3
    Low

    CVE-2015-5045

    Last Modified: 21 Nov 2024

    The Administration and Reporting tool in IBM Rational License Key Server (RLKS) before 8.1.4.9 iFix 04 allows local users to obtain sensitive information via unspecified vectors. IBM X-Force ID: 106938.

    Published: 26 Mar 2018
    5.4
    Medium

    CVE-2015-7423

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 107771.

    Published: 26 Mar 2018
    4.8
    Medium

    CVE-2018-1186

    Last Modified: 21 Nov 2024

    Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Cluster description of the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.

    Published: 26 Mar 2018
    4.8
    Medium

    CVE-2018-1187

    Last Modified: 21 Nov 2024

    Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6 is affected by a cross-site scripting vulnerability in the Network Configuration page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.

    Published: 26 Mar 2018
    4.8
    Medium

    CVE-2018-1201

    Last Modified: 21 Nov 2024

    Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Job Operations Page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.

    Published: 26 Mar 2018
    6.7
    Medium

    CVE-2018-1203

    Last Modified: 21 Nov 2024

    In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, the tcpdump binary, being run with sudo, may potentially be used by compadmin to execute arbitrary code with root privileges.

    Published: 26 Mar 2018
    4.3
    Medium

    CVE-2015-7401

    Last Modified: 21 Nov 2024

    IBM Curam Social Program Management 6.1.x before 6.1.1.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive document information by guessing the document id. IBM X-Force ID: 107106.

    Published: 26 Mar 2018
    4.3
    Medium

    CVE-2015-7424

    Last Modified: 21 Nov 2024

    IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, 11.4, and 11.5 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information by leveraging Catalogs access. IBM X-Force ID: 107780.

    Published: 26 Mar 2018
    7.8
    High

    CVE-2015-7432

    Last Modified: 21 Nov 2024

    IBM Capacity Management Analytics 2.1.0.0 allows local users to decrypt usernames and passwords by leveraging access to setenv.sh and parameter.txt. IBM X-Force ID: 107861.

    Published: 26 Mar 2018
    7.8
    High

    CVE-2015-7433

    Last Modified: 21 Nov 2024

    IBM Capacity Management Analytics 2.1.0.0 allows local users to discover cleartext usernames and passwords by leveraging access to the CMA install machine. IBM X-Force ID: 107862.

    Published: 26 Mar 2018
    7.8
    High

    CVE-2015-7434

    Last Modified: 21 Nov 2024

    IBM Capacity Management Analytics 2.1.0.0 allows local users to discover encrypted usernames and passwords by leveraging access to the CMA install machine. IBM X-Force ID: 107863.

    Published: 26 Mar 2018
    6.1
    Medium

    CVE-2018-7543

    Last Modified: 2 Feb 2026

    Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the json parameter.

    Published: 26 Mar 2018
    4.8
    Medium

    CVE-2018-1188

    Last Modified: 21 Nov 2024

    Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, and versions 7.2.1.x is affected by a cross-site scripting vulnerability in the Authorization Providers page within the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.

    Published: 26 Mar 2018
    6.1
    Medium

    CVE-2018-8937

    Last Modified: 21 Nov 2024

    An issue was discovered in Open-AudIT Professional 2.1. It is possible to inject a malicious payload in the redirect_url parameter to the /login URI to trigger an open redirect. A "data:text/html;base64," payload can be used with JavaScript code.

    Published: 26 Mar 2018