CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2018-8973

    Last Modified: 21 Nov 2024

    OTCMS 3.20 allows XSS by adding a keyword or link to an article, as demonstrated by an admin/keyWord_deal.php?mudi=add request.

    Published: 24 Mar 2018
    9.8
    Critical

    CVE-2018-8971

    Last Modified: 21 Nov 2024

    The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.

    Published: 24 Mar 2018
    7.4
    High

    CVE-2018-8970

    Last Modified: 21 Nov 2024

    The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a certain special case of a zero name length, which causes silent omission of hostname verification, and consequently allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. NOTE: the LibreSSL documentation indicates that this special case is supported, but the BoringSSL documentation does not.

    Published: 24 Mar 2018
    6.1
    Medium

    CVE-2015-9257

    Last Modified: 21 Nov 2024

    BMC Remedy Action Request (AR) System 9.0 before 9.0.00 Service Pack 2 hot fix 1 has persistent XSS.

    Published: 24 Mar 2018
    7.5
    High

    CVE-2018-8966

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.

    Published: 24 Mar 2018
    9.8
    Critical

    CVE-2018-8967

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request.

    Published: 24 Mar 2018
    7.5
    High

    CVE-2018-8968

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg or oldflv parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

    Published: 24 Mar 2018
    7.5
    High

    CVE-2018-8969

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

    Published: 24 Mar 2018
    7.5
    High

    CVE-2018-8965

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

    Published: 24 Mar 2018
    5.4
    Medium

    CVE-2017-17749

    Last Modified: 21 Nov 2024

    Bose SoundTouch devices allow XSS via crafted song data from a music service, as demonstrated by Pandora.

    Published: 24 Mar 2018
    5.4
    Medium

    CVE-2017-17750

    Last Modified: 21 Nov 2024

    Bose SoundTouch devices allow XSS via a crafted public playlist from Spotify.

    Published: 24 Mar 2018
    8.8
    High

    CVE-2017-17751

    Last Modified: 21 Nov 2024

    Bose SoundTouch devices allows remote attackers to achieve remote control via a crafted web site that uses the WebSocket Protocol.

    Published: 24 Mar 2018
    6.5
    Medium

    CVE-2018-10804

    Last Modified: 21 Nov 2024

    ImageMagick version 7.0.7-28 contains a memory leak in WriteTIFFImage in coders/tiff.c.

    Published: 24 Mar 2018
    6.5
    Medium

    CVE-2018-10805

    Last Modified: 21 Nov 2024

    ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.

    Published: 24 Mar 2018
    6.5
    Medium

    CVE-2018-17965

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.7-28 has a memory leak vulnerability in WriteSGIImage in coders/sgi.c.

    Published: 24 Mar 2018
    6.5
    Medium

    CVE-2018-17966

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.7-28 has a memory leak vulnerability in WritePDBImage in coders/pdb.c.

    Published: 24 Mar 2018
    6.5
    Medium

    CVE-2018-17967

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.7-28 has a memory leak vulnerability in ReadBGRImage in coders/bgr.c.

    Published: 24 Mar 2018
    9.8
    Critical

    CVE-2021-3538

    Last Modified: 21 Nov 2024

    A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630c8510268e75203009fe7daf2b8e1d60c45. Due to insecure randomness in the g.rand.Read function the generated UUIDs are predictable for an attacker.

    Published: 24 Mar 2018
    7.5
    High

    CVE-2017-15710

    Last Modified: 21 Nov 2024

    In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header value is not present in the charset conversion table, a fallback mechanism is used to truncate it to a two characters value to allow a quick retry (for example, 'en-US' is truncated to 'en'). A header value of less than two characters forces an out of bound write of one NUL byte to a memory location that is not part of the string. In the worst case, quite unlikely, the process would crash which could be used as a Denial of Service attack. In the more likely case, this memory is already reserved for future use and the issue has no effect at all.

    Published: 24 Mar 2018
    8.1
    High

    CVE-2017-15715

    Last Modified: 21 Nov 2024

    In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename.

    Published: 24 Mar 2018
    6.5
    Medium

    CVE-2018-18016

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.7-28 has a memory leak vulnerability in WritePCXImage in coders/pcx.c.

    Published: 24 Mar 2018
    6.1
    Medium

    CVE-2018-1000139

    Last Modified: 5 Dec 2025

    I, Librarian version 4.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in "id" parameter in stable.php that can result in an attacker using the XSS to send a malicious script to an unsuspecting user.

    Published: 23 Mar 2018
    5.4
    Medium

    CVE-2018-8957

    Last Modified: 21 Nov 2024

    CoverCMS v1.1.6 has XSS via the fourth input box to index.php, related to admina/mconfigs.inc.php.

    Published: 23 Mar 2018
    6.5
    Medium

    CVE-2018-8961

    Last Modified: 21 Nov 2024

    In libming 0.4.8, the decompilePUSHPARAM function of decompile.c has a use-after-free. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

    Published: 23 Mar 2018
    6.5
    Medium

    CVE-2018-8962

    Last Modified: 21 Nov 2024

    In libming 0.4.8, the decompileSingleArgBuiltInFunctionCall function of decompile.c has a use-after-free. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

    Published: 23 Mar 2018
    6.5
    Medium

    CVE-2018-8963

    Last Modified: 21 Nov 2024

    In libming 0.4.8, the decompileGETVARIABLE function of decompile.c has a use-after-free. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

    Published: 23 Mar 2018
    6.5
    Medium

    CVE-2018-8964

    Last Modified: 21 Nov 2024

    In libming 0.4.8, the decompileDELETE function of decompile.c has a use-after-free. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

    Published: 23 Mar 2018
    8.8
    High

    CVE-2018-1000137

    Last Modified: 5 Dec 2025

    I, Librarian version 4.8 and earlier contains a Cross site Request Forgery (CSRF) vulnerability in users.php that can result in the password of the admin being forced to be changed without the administrator's knowledge.

    Published: 23 Mar 2018
    9.1
    Critical

    CVE-2018-1000138

    Last Modified: 5 Dec 2025

    I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php that can result in the attacker abusing functionality on the server to read or update internal resources.

    Published: 23 Mar 2018
    9.1
    Critical

    CVE-2018-1000141

    Last Modified: 5 Dec 2025

    I, Librarian version 4.9 and earlier contains an Incorrect Access Control vulnerability in ajaxdiscussion.php that can result in any users gaining unauthorized access (read, write and delete) to project discussions.

    Published: 23 Mar 2018
    5.4
    Medium

    CVE-2018-1429

    Last Modified: 21 Nov 2024

    IBM MQ Appliance 9.0.1, 9.0.2, 9.0.3, amd 9.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139077.

    Published: 23 Mar 2018
    5.4
    Medium

    CVE-2017-1655

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133379.

    Published: 23 Mar 2018
    4.3
    Medium

    CVE-2017-1524

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request that could be used to aid future attacks. IBM X-Force ID: 129970.

    Published: 23 Mar 2018
    5.4
    Medium

    CVE-2017-1629

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133127.

    Published: 23 Mar 2018
    6.5
    Medium

    CVE-2017-18245

    Last Modified: 21 Nov 2024

    The mpc8_probe function in libavformat/mpc8.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted audio file.

    Published: 23 Mar 2018
    6.5
    Medium

    CVE-2017-18246

    Last Modified: 21 Nov 2024

    The pcm_encode_frame function in libavcodec/pcm.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted media file.

    Published: 23 Mar 2018
    6.5
    Medium

    CVE-2017-18247

    Last Modified: 21 Nov 2024

    The av_audio_fifo_size function in libavutil/audio_fifo.c in Libav 12.2 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted media file.

    Published: 23 Mar 2018
    4.3
    Medium

    CVE-2017-1602

    Last Modified: 21 Nov 2024

    IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access settings that they should not be able to using a specially crafted URL. IBM X-Force ID: 132625.

    Published: 23 Mar 2018
    5.4
    Medium

    CVE-2017-1762

    Last Modified: 21 Nov 2024

    IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136006.

    Published: 23 Mar 2018
    4.3
    Medium

    CVE-2018-8949

    Last Modified: 21 Nov 2024

    An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API integrity bug, potentially allowing users to delete attributes of other events. A crafted edit for an event (without attribute UUIDs but attribute IDs set) could overwrite an existing attribute.

    Published: 23 Mar 2018
    7.8
    High

    CVE-2018-7502

    Last Modified: 21 Nov 2024

    Kernel drivers in Beckhoff TwinCAT 3.1 Build 4022.4, TwinCAT 2.11 R3 2259, and TwinCAT 3.1 lack proper validation of user-supplied pointer values. An attacker who is able to execute code on the target may be able to exploit this vulnerability to obtain SYSTEM privileges.

    Published: 23 Mar 2018
    6.1
    Medium

    CVE-2018-8948

    Last Modified: 21 Nov 2024

    In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.

    Published: 23 Mar 2018
    7.8
    High

    CVE-2017-15325

    Last Modified: 21 Nov 2024

    The Bdat driver of Prague smart phones with software versions earlier than Prague-AL00AC00B211, versions earlier than Prague-AL00BC00B211, versions earlier than Prague-AL00CC00B211, versions earlier than Prague-TL00AC01B211, versions earlier than Prague-TL10AC01B211 has integer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious APP and execute it as a specific privilege; the APP can then send a specific parameter to the driver of the smart phone, causing arbitrary code execution.

    Published: 23 Mar 2018
    4.3
    Medium

    CVE-2017-15326

    Last Modified: 21 Nov 2024

    DBS3900 TDD LTE V100R003C00, V100R004C10 have a weak encryption algorithm security vulnerability. DBS3900 TDD LTE supports SSL/TLS protocol negotiation using insecure encryption algorithms. If an insecure encryption algorithm is negotiated in the communication, an unauthenticated remote attacker can exploit this vulnerability to crack the encrypted data and cause information leakage.

    Published: 23 Mar 2018
    9.8
    Critical

    CVE-2017-17736

    Last Modified: 19 Dec 2025

    Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.

    Published: 23 Mar 2018
    9.8
    Critical

    CVE-2018-1207

    Last Modified: 21 Nov 2024

    Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentially be able to use CGI variables to execute remote code.

    Published: 23 Mar 2018
    7.5
    High

    CVE-2018-1211

    Last Modified: 21 Nov 2024

    Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain a path traversal vulnerability in its Web server's URI parser which could be used to obtain specific sensitive data without authentication. A remote unauthenticated attacker may be able to read configuration settings from the iDRAC by querying specific URI strings.

    Published: 23 Mar 2018
    6.5
    Medium

    CVE-2018-8976

    Last Modified: 21 Nov 2024

    In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringFormat out-of-bounds read) via a crafted file.

    Published: 23 Mar 2018
    6.5
    Medium

    CVE-2018-8977

    Last Modified: 21 Nov 2024

    In Exiv2 0.26, the Exiv2::Internal::printCsLensFFFF function in canonmn_int.cpp allows remote attackers to cause a denial of service (invalid memory access) via a crafted file.

    Published: 23 Mar 2018
    8.1
    High

    CVE-2018-1000136

    Last Modified: 21 Nov 2024

    Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Webviews that can result in remote code execution. This attack appear to be exploitable via an app which allows execution of 3rd party code AND disallows node integration AND has not specified if webview is enabled/disabled. This vulnerability appears to have been fixed in 1.7.13, 1.8.4, 2.0.0-beta.4.

    Published: 23 Mar 2018