CVE Feed

    Dashboard / CVE

    9.9
    Critical

    CVE-2018-5225

    Last Modified: 21 Nov 2024

    In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 before 5.7.3 (the fixed version for 5.7.x), and 5.8.0 before 5.8.2 (the fixed version for 5.8.x), allows authenticated users to gain remote code execution using the in browser editing feature via editing a symbolic link within a repository.

    Published: 22 Mar 2018
    6.1
    Medium

    CVE-2018-0535

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in PHP 2chBBS version bbs18c allows an attacker to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Mar 2018
    7.8
    High

    CVE-2018-0552

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in The installer of PhishWall Client Firefox and Chrome edition for Windows Ver. 5.1.26 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 22 Mar 2018
    6.2
    Medium

    CVE-2018-1427

    Last Modified: 21 Nov 2024

    IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) contains several environment variables that a local attacker could overflow and cause a denial of service. IBM X-Force ID: 139072.

    Published: 22 Mar 2018
    6.2
    Medium

    CVE-2018-1428

    Last Modified: 21 Nov 2024

    IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 139073.

    Published: 22 Mar 2018
    7.7
    High

    CVE-2018-1448

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140043.

    Published: 22 Mar 2018
    7.4
    High

    CVE-2017-1677

    Last Modified: 21 Nov 2024

    IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes the contents of /tmp/connlicj.bin which leads to object injection and potentially arbitrary code execution depending on the classpath. IBM X-Force ID: 133999.

    Published: 22 Mar 2018
    7.4
    High

    CVE-2018-1426

    Last Modified: 21 Nov 2024

    IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multiple ICC instances are loaded which could result in duplicate Session IDs and a risk of duplicate key material. IBM X-Force ID: 139071.

    Published: 22 Mar 2018
    5.3
    Medium

    CVE-2016-9711

    Last Modified: 21 Nov 2024

    IBM Predictive Solutions Foundation (IBM Cognos Analytics 11.0) reveals sensitive information in detailed error messages that could aid an attacker in further attacks against the system. IBM X-Force ID: 119619.

    Published: 22 Mar 2018
    9.8
    Critical

    CVE-2017-1789

    Last Modified: 21 Nov 2024

    IBM Tivoli Monitoring V6 6.2.3 and 6.3.0 could allow an unauthenticated user to remotely execute code through unspecified methods. IBM X-Force ID: 137034.

    Published: 22 Mar 2018
    5.1
    Medium

    CVE-2017-1571

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853.

    Published: 22 Mar 2018
    5.3
    Medium

    CVE-2017-1788

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 9 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 137031.

    Published: 22 Mar 2018
    7.5
    High

    CVE-2018-8909

    Last Modified: 21 Nov 2024

    The Wire application before 2018-03-07 for Android allows attackers to write to pathnames outside of the downloads directory via a ../ in a filename of a received file, related to AssetService.scala.

    Published: 22 Mar 2018
    6.1
    Medium

    CVE-2018-8899

    Last Modified: 21 Nov 2024

    IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorization response page, which might lead to XSS in some configurations.

    Published: 22 Mar 2018
    6.7
    Medium

    CVE-2017-17743

    Last Modified: 21 Nov 2024

    Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.20, 5.0.x before 5.0.19, and 5.1.x before 5.1.11 allows authenticated remote attackers to escape the shell and escalate their privileges by uploading a .bashrc file containing the /bin/sh string. In some situations, authentication can be achieved via the bhu85tgb default password for the admin account.

    Published: 22 Mar 2018
    7.8
    High

    CVE-2018-8894

    Last Modified: 21 Nov 2024

    In 2345 Security Guard 3.6, the driver file (2345BdPcSafe.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222108.

    Published: 22 Mar 2018
    7.8
    High

    CVE-2018-8895

    Last Modified: 21 Nov 2024

    In 2345 Security Guard 3.6, the driver file (2345DumpBlock.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222040.

    Published: 22 Mar 2018
    7.8
    High

    CVE-2018-8896

    Last Modified: 21 Nov 2024

    In 2345 Security Guard 3.6, the driver file (2345DumpBlock.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222044.

    Published: 22 Mar 2018
    7.8
    High

    CVE-2018-8904

    Last Modified: 21 Nov 2024

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002000.

    Published: 22 Mar 2018
    6.1
    Medium

    CVE-2018-8906

    Last Modified: 21 Nov 2024

    dsmall v20180320 has XSS via a crafted street address to public/index.php/home/memberaddress/index.html, which is mishandled at public/index.php/home/memberaddress/edit/address_id/2.html.

    Published: 22 Mar 2018
    9.8
    Critical

    CVE-2014-4912

    Last Modified: 21 Nov 2024

    An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation.

    Published: 22 Mar 2018
    5.5
    Medium

    CVE-2018-1092

    Last Modified: 21 Nov 2024

    The ext4_iget function in fs/ext4/inode.c in the Linux kernel through 4.15.15 mishandles the case of a root directory with a zero i_links_count, which allows attackers to cause a denial of service (ext4_process_freed_data NULL pointer dereference and OOPS) via a crafted ext4 image.

    Published: 22 Mar 2018
    5.5
    Medium

    CVE-2018-1093

    Last Modified: 21 Nov 2024

    The ext4_valid_block_bitmap function in fs/ext4/balloc.c in the Linux kernel through 4.15.15 allows attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 image because balloc.c and ialloc.c do not validate bitmap block numbers.

    Published: 22 Mar 2018
    5.5
    Medium

    CVE-2018-1094

    Last Modified: 21 Nov 2024

    The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.15.15 does not always initialize the crc32c checksum driver, which allows attackers to cause a denial of service (ext4_xattr_inode_hash NULL pointer dereference and system crash) via a crafted ext4 image.

    Published: 22 Mar 2018
    5.5
    Medium

    CVE-2018-1095

    Last Modified: 21 Nov 2024

    The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate xattr sizes, which causes misinterpretation of a size as an error code, and consequently allows attackers to cause a denial of service (get_acl NULL pointer dereference and system crash) via a crafted ext4 image.

    Published: 22 Mar 2018
    7.8
    High

    CVE-2016-10717

    Last Modified: 21 Nov 2024

    A vulnerability in the encryption and permission implementation of Malwarebytes Anti-Malware consumer version 2.2.1 and prior (fixed in 3.0.4) allows an attacker to take control of the whitelisting feature (exclusions.dat under %SYSTEMDRIVE%\ProgramData) to permit execution of unauthorized applications including malware and malicious websites. Files blacklisted by Malwarebytes Malware Protect can be executed, and domains blacklisted by Malwarebytes Web Protect can be reached through HTTP.

    Published: 21 Mar 2018
    8.8
    High

    CVE-2018-1230

    Last Modified: 21 Nov 2024

    Pivotal Spring Batch Admin, all versions, does not contain cross site request forgery protection. A remote unauthenticated user could craft a malicious site that executes requests to Spring Batch Admin. This issue has not been patched because Spring Batch Admin has reached end of life.

    Published: 21 Mar 2018
    7.8
    High

    CVE-2018-3710

    Last Modified: 21 Nov 2024

    Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.

    Published: 21 Mar 2018
    5.3
    Medium

    CVE-2018-7513

    Last Modified: 21 Nov 2024

    In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a stack-based buffer overflow.

    Published: 21 Mar 2018
    5.3
    Medium

    CVE-2018-7517

    Last Modified: 21 Nov 2024

    In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause an out of bounds vulnerability.

    Published: 21 Mar 2018
    5.3
    Medium

    CVE-2018-7519

    Last Modified: 21 Nov 2024

    In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a heap-based buffer overflow.

    Published: 21 Mar 2018
    5.3
    Medium

    CVE-2018-7521

    Last Modified: 21 Nov 2024

    In Omron CX-Supervisor Versions 3.30 and prior, use after free vulnerabilities can be exploited when CX Supervisor parses a specially crafted project file.

    Published: 21 Mar 2018
    5.3
    Medium

    CVE-2018-7525

    Last Modified: 21 Nov 2024

    In Omron CX-Supervisor Versions 3.30 and prior, processing a malformed packet by a certain executable may cause an untrusted pointer dereference vulnerability.

    Published: 21 Mar 2018
    6.1
    Medium

    CVE-2018-1229

    Last Modified: 21 Nov 2024

    Pivotal Spring Batch Admin, all versions, contains a stored XSS vulnerability in the file upload feature. An unauthenticated malicious user with network access to Spring Batch Admin could store an arbitrary web script that would be executed by other users. This issue has not been patched because Spring Batch Admin has reached end of life.

    Published: 21 Mar 2018
    9.8
    Critical

    CVE-2017-0915

    Last Modified: 21 Nov 2024

    Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

    Published: 21 Mar 2018
    9.8
    Critical

    CVE-2017-0916

    Last Modified: 21 Nov 2024

    Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.

    Published: 21 Mar 2018
    6.1
    Medium

    CVE-2017-0917

    Last Modified: 21 Nov 2024

    Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.

    Published: 21 Mar 2018
    8.8
    High

    CVE-2017-0918

    Last Modified: 21 Nov 2024

    Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution.

    Published: 21 Mar 2018
    6.1
    Medium

    CVE-2017-0923

    Last Modified: 21 Nov 2024

    Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site scripting.

    Published: 21 Mar 2018
    6.1
    Medium

    CVE-2017-0924

    Last Modified: 21 Nov 2024

    Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the labels component resulting in persistent cross site scripting.

    Published: 21 Mar 2018
    7.2
    High

    CVE-2017-0925

    Last Modified: 21 Nov 2024

    Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.

    Published: 21 Mar 2018
    8.8
    High

    CVE-2017-0926

    Last Modified: 21 Nov 2024

    Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login.

    Published: 21 Mar 2018
    6.5
    Medium

    CVE-2017-0927

    Last Modified: 21 Nov 2024

    Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.

    Published: 21 Mar 2018
    7.5
    High

    CVE-2017-0922

    Last Modified: 21 Nov 2024

    Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object.

    Published: 21 Mar 2018
    7.5
    High

    CVE-2017-0914

    Last Modified: 21 Nov 2024

    Gitlab Community and Enterprise Editions version 10.1, 10.2, and 10.2.4 are vulnerable to a SQL injection in the MilestoneFinder component resulting in disclosure of all data in a GitLab instance's database.

    Published: 21 Mar 2018
    5.3
    Medium

    CVE-2018-7515

    Last Modified: 21 Nov 2024

    In Omron CX-Supervisor Versions 3.30 and prior, access of uninitialized pointer vulnerabilities can be exploited when CX Supervisor indirectly calls an initialized pointer when parsing malformed packets.

    Published: 21 Mar 2018
    5.3
    Medium

    CVE-2018-7523

    Last Modified: 21 Nov 2024

    In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a double free vulnerability.

    Published: 21 Mar 2018
    9.8
    Critical

    CVE-2018-7269

    Last Modified: 21 Nov 2024

    The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocumented need to sanitize array input.

    Published: 21 Mar 2018
    9.8
    Critical

    CVE-2018-8073

    Last Modified: 21 Nov 2024

    Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with the Redis extension.

    Published: 21 Mar 2018
    8.1
    High

    CVE-2018-8074

    Last Modified: 21 Nov 2024

    Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with the Elasticsearch extension.

    Published: 21 Mar 2018