CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2017-15534

    Last Modified: 21 Nov 2024

    The Norton App Lock prior to version 1.3.0.13 can be susceptible to an authentication bypass exploit. In this type of circumstance, the exploit can allow the user to kill the app to prevent it from locking the device, thereby allowing the individual to gain device access.

    Published: 26 Mar 2018
    7.8
    High

    CVE-2017-6278

    Last Modified: 21 Nov 2024

    NVIDIA Tegra kernel contains a vulnerability in the CORE DVFS Thermal driver where there is the potential to read or write a buffer using an index or pointer that references a memory location after the end of the buffer, which may lead to a denial of service or possible escalation of privileges.

    Published: 26 Mar 2018
    8.1
    High

    CVE-2018-5454

    Last Modified: 21 Nov 2024

    Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability where code debugging methods are enabled, which could allow an attacker to remotely execute arbitrary code during runtime.

    Published: 26 Mar 2018
    7.5
    High

    CVE-2018-5462

    Last Modified: 21 Nov 2024

    Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an SSL incorrect hostname certificate vulnerability this could allow an attacker to gain unauthorized access to resources and information.

    Published: 26 Mar 2018
    7.5
    High

    CVE-2018-5466

    Last Modified: 21 Nov 2024

    Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a self-signed SSL certificate vulnerability this could allow an attacker to gain unauthorized access to resources and information.

    Published: 26 Mar 2018
    9.8
    Critical

    CVE-2018-5468

    Last Modified: 21 Nov 2024

    Philips Intellispace Portal all versions 7.0.x and 8.0.x have a remote desktop access vulnerability that could allow an attacker to gain unauthorized access and in some cases escalate their level of privilege or execute arbitrary code

    Published: 26 Mar 2018
    9.8
    Critical

    CVE-2018-5472

    Last Modified: 21 Nov 2024

    Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could allow an attacker to gain unauthorized access and in some cases escalate their level of privilege or execute arbitrary code.

    Published: 26 Mar 2018
    9.8
    Critical

    CVE-2018-5474

    Last Modified: 21 Nov 2024

    Philips Intellispace Portal all versions 7.0.x and 8.0.x have an input validation vulnerability that could allow a remote attacker to execute arbitrary code or cause the application to crash.

    Published: 26 Mar 2018
    7.5
    High

    CVE-2018-5458

    Last Modified: 21 Nov 2024

    Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability using SSL legacy encryption that could allow an attacker to gain unauthorized access to resources and information.

    Published: 26 Mar 2018
    7.5
    High

    CVE-2018-5464

    Last Modified: 21 Nov 2024

    Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an untrusted SSL certificate vulnerability this could allow an attacker to gain unauthorized access to resources and information.

    Published: 26 Mar 2018
    7.8
    High

    CVE-2018-5470

    Last Modified: 21 Nov 2024

    Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an unquoted search path or element vulnerability that has been identified, which may allow an authorized local user to execute arbitrary code and escalate their level of privileges.

    Published: 26 Mar 2018
    5.4
    Medium

    CVE-2018-9020

    Last Modified: 21 Nov 2024

    The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.

    Published: 26 Mar 2018
    9.8
    Critical

    CVE-2018-20060

    Last Modified: 27 Dec 2024

    urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.

    Published: 26 Mar 2018
    5.5
    Medium

    CVE-2018-9055

    Last Modified: 21 Nov 2024

    JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_firstone in libjasper/jpc/jpc_math.c.

    Published: 26 Mar 2018
    7.8
    High

    CVE-2018-1083

    Last Modified: 21 Nov 2024

    Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the context of the user who tries to use autocomplete to traverse the before mentioned path. If the user affected is privileged, this leads to privilege escalation.

    Published: 26 Mar 2018
    8
    High

    CVE-2018-8718

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mail as an arbitrary user via a /descriptorByName/hudson.tasks.Mailer/sendTestMail request.

    Published: 26 Mar 2018
    9.8
    Critical

    CVE-2018-5148

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.7.3 and Firefox < 59.0.2.

    Published: 26 Mar 2018
    8.8
    High

    CVE-2018-8817

    Last Modified: 21 Nov 2024

    Wampserver before 3.1.3 has CSRF in add_vhost.php.

    Published: 25 Mar 2018
    5.4
    Medium

    CVE-2018-8978

    Last Modified: 21 Nov 2024

    Open-AudIT Professional 2.1 has XSS via a crafted src attribute of an IMG element within a URI.

    Published: 25 Mar 2018
    8.8
    High

    CVE-2018-8979

    Last Modified: 21 Nov 2024

    Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI.

    Published: 25 Mar 2018
    7.2
    High

    CVE-2018-9010

    Last Modified: 21 Nov 2024

    Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via the /cgi-bin/cgiServer.exx page parameter, aka absolute path traversal. In some cases, authentication can be achieved via the admin account with its default admin password.

    Published: 25 Mar 2018
    7.5
    High

    CVE-2018-9014

    Last Modified: 21 Nov 2024

    dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request.

    Published: 25 Mar 2018
    5.4
    Medium

    CVE-2018-9015

    Last Modified: 21 Nov 2024

    dsmall v20180320 allows XSS via the public/index.php/home/predeposit/index.html pdr_sn parameter (aka the CMS search box).

    Published: 25 Mar 2018
    6.1
    Medium

    CVE-2018-9016

    Last Modified: 21 Nov 2024

    dsmall v20180320 allows XSS via the main page search box at the public/index.php/home URI.

    Published: 25 Mar 2018
    5.4
    Medium

    CVE-2018-9017

    Last Modified: 21 Nov 2024

    dsmall v20180320 allows XSS via the member search box at the public/index.php/home/membersnsfriend/findlist.html URI.

    Published: 25 Mar 2018
    7.5
    High

    CVE-2018-7719

    Last Modified: 21 Nov 2024

    Acrolinx Server before 5.2.5 on Windows allows Directory Traversal.

    Published: 25 Mar 2018
    7.5
    High

    CVE-2018-8947

    Last Modified: 21 Nov 2024

    rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl request.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-8989

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002006.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-8990

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002010.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-8991

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002009.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-8992

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002005.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-8993

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002001.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-8994

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002003.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-8996

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002007.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-9000

    Last Modified: 21 Nov 2024

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_x86.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402004.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-9001

    Last Modified: 21 Nov 2024

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win7_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402000.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-9002

    Last Modified: 21 Nov 2024

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win7_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060cc.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-9003

    Last Modified: 21 Nov 2024

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_x86.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402000.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-9004

    Last Modified: 21 Nov 2024

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_x86.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060d0.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-9005

    Last Modified: 21 Nov 2024

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win7_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060d0.

    Published: 25 Mar 2018
    8.8
    High

    CVE-2018-9009

    Last Modified: 21 Nov 2024

    In libming 0.4.8, there is a use-after-free in the decompileJUMP function of the decompile.c file.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-8995

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002002.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-8997

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002004.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-8998

    Last Modified: 21 Nov 2024

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_x86.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060cc.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-9006

    Last Modified: 21 Nov 2024

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win7_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402004.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-8988

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002008.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-8999

    Last Modified: 21 Nov 2024

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win7_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060c4.

    Published: 25 Mar 2018
    7.8
    High

    CVE-2018-9007

    Last Modified: 21 Nov 2024

    In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_x86.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060c4.

    Published: 25 Mar 2018
    6.5
    Medium

    CVE-2018-9018

    Last Modified: 21 Nov 2024

    In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c. Remote attackers could leverage this vulnerability to cause a crash and denial of service via a crafted mng file.

    Published: 25 Mar 2018
    8.8
    High

    CVE-2018-8972

    Last Modified: 21 Nov 2024

    Creditwest Bank CMS Project (aka CWCMS) through 2017-07-28 has CSRF in the functionality for updating the site configuration, which allows remote attackers to inject arbitrary PHP code, as demonstrated by a PHP shell that calls eval on request parameters.

    Published: 24 Mar 2018