CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2018-8809

    Last Modified: 21 Nov 2024

    In radare2 2.4.0, there is a heap-based buffer over-read in the dalvik_op function of anal_dalvik.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted dex file.

    Published: 20 Mar 2018
    5.5
    Medium

    CVE-2018-8810

    Last Modified: 21 Nov 2024

    In radare2 2.4.0, there is a heap-based buffer over-read in the get_ivar_list_t function of mach0_classes.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted Mach-O file.

    Published: 20 Mar 2018
    7.8
    High

    CVE-2018-8822

    Last Modified: 21 Nov 2024

    Incorrect buffer length handling in the ncp_read_kernel function in fs/ncpfs/ncplib_kernel.c in the Linux kernel through 4.15.11, and in drivers/staging/ncpfs/ncplib_kernel.c in the Linux kernel 4.16-rc through 4.16-rc6, could be exploited by malicious NCPFS servers to crash the kernel or execute code.

    Published: 20 Mar 2018
    7.5
    High

    CVE-2018-1000135

    Last Modified: 21 Nov 2024

    GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DNS queries leaked to local network's DNS servers, while on VPN. This vulnerability appears to have been fixed in Some Ubuntu 16.04 packages were fixed, but later updates removed the fix. cf. https://bugs.launchpad.net/ubuntu/+bug/1754671 an upstream fix does not appear to be available at this time.

    Published: 20 Mar 2018
    5.7
    Medium

    CVE-2018-1000161

    Last Modified: 21 Nov 2024

    nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a victim that runs NSE script http-fetch against a malicious web site. This vulnerability appears to have been fixed in 7.7.

    Published: 20 Mar 2018
    6.1
    Medium

    CVE-2018-5233

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/tools.

    Published: 19 Mar 2018
    8.8
    High

    CVE-2014-2550

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in the Disable Comments plugin before 1.0.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that enable comments via a request to the disable_comments_settings page to wp-admin/options-general.php.

    Published: 19 Mar 2018
    9.8
    Critical

    CVE-2014-2652

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in OpenScape Deployment Service (DLS) before 6.x and 7.x before R1.11.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 19 Mar 2018
    7.1
    High

    CVE-2014-2885

    Last Modified: 21 Nov 2024

    Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) obtain sensitive information via vectors involving a crafted item->OriginalLength value in the MainThreadProc function in EncryptedIoQueue.c or (2) cause a denial of service (memory consumption) via vectors involving large StartingOffset and Length values in the ProcessVolumeDeviceControlIrp function in Ntdriver.c.

    Published: 19 Mar 2018
    5.5
    Medium

    CVE-2014-5450

    Last Modified: 21 Nov 2024

    Zarafa Collaboration Platform 4.1 uses world-readable permissions for /etc/zarafa/license, which allows local users to obtain sensitive information by reading license files.

    Published: 19 Mar 2018
    3.3
    Low

    CVE-2014-2884

    Last Modified: 21 Nov 2024

    The ProcessVolumeDeviceControlIrp function in Ntdriver.c in TrueCrypt 7.1a allows local users to bypass access restrictions and obtain sensitive information about arbitrary files via a (1) TC_IOCTL_OPEN_TEST or (2) TC_IOCTL_GET_SYSTEM_DRIVE_CONFIG IOCTL call.

    Published: 19 Mar 2018
    8.8
    High

    CVE-2014-2274

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via a request to the subscribe-to-comments-reloaded/options/index.php page to wp-admin/admin.php.

    Published: 19 Mar 2018
    6.1
    Medium

    CVE-2014-2297

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin 4.29.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to ls/htmlchat.php or (2) bgcolor parameter to ls/index.php. NOTE: vector 1 may overlap CVE-2014-1906.4.

    Published: 19 Mar 2018
    6.5
    Medium

    CVE-2014-2675

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in inc/AdminPage.php in the WP HTML Sitemap plugin 1.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete the sitemap via a request to the wp-html-sitemap page in wp-admin/options-general.php.

    Published: 19 Mar 2018
    7.5
    High

    CVE-2014-2674

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in the Ajax Pagination (twitter Style) plugin 1.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the loop parameter in an ajax_navigation action to wp-admin/admin-ajax.php.

    Published: 19 Mar 2018
    7.8
    High

    CVE-2014-5443

    Last Modified: 21 Nov 2024

    Seafile Server before 3.1.2 and Server Professional Edition before 3.1.0 allow local users to gain privileges via vectors related to ccnet handling user accounts.

    Published: 19 Mar 2018
    5.9
    Medium

    CVE-2014-4024

    Last Modified: 21 Nov 2024

    SSL virtual servers in F5 BIG-IP systems 10.x before 10.2.4 HF9, 11.x before 11.2.1 HF12, 11.3.0 before HF10, 11.4.0 before HF8, 11.4.1 before HF5, 11.5.0 before HF5, and 11.5.1 before HF5, when used with third-party Secure Sockets Layer (SSL) accelerator cards, might allow remote attackers to have unspecified impact via a timing side-channel attack.

    Published: 19 Mar 2018
    9.8
    Critical

    CVE-2018-7445

    Last Modified: 7 Nov 2025

    A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable.

    Published: 19 Mar 2018
    Unknown

    CVE-2018-1224

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 19 Mar 2018
    Unknown

    CVE-2018-1225

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 19 Mar 2018
    Unknown

    CVE-2018-1226

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 19 Mar 2018
    5.4
    Medium

    CVE-2018-8732

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_del parameter.

    Published: 19 Mar 2018
    8.8
    High

    CVE-2018-1195

    Last Modified: 21 Nov 2024

    In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected. This exposes a vulnerability where a refresh token that would otherwise be insufficient to obtain an access token, either due to lack of client credentials or revocation, would allow authentication.

    Published: 19 Mar 2018
    8.5
    High

    CVE-2018-1197

    Last Modified: 21 Nov 2024

    In Windows Stemcells versions prior to 1200.14, apps running inside containers in Windows on Google Cloud Platform are able to access the metadata endpoint. A malicious developer could use this access to gain privileged credentials.

    Published: 19 Mar 2018
    7.5
    High

    CVE-2018-1218

    Last Modified: 21 Nov 2024

    In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the 'nsrd' daemon causes a buffer overflow condition when handling certain messages. A remote unauthenticated attacker could potentially exploit this vulnerability to cause a denial of service to the users of NetWorker systems.

    Published: 19 Mar 2018
    7
    High

    CVE-2018-1171

    Last Modified: 21 Nov 2024

    This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the DTrace DOF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code under the context of the host OS. Was ZDI-CAN-5106.

    Published: 19 Mar 2018
    8.1
    High

    CVE-2018-1221

    Last Modified: 21 Nov 2024

    In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers. A user with developer privileges could use this vulnerability to steal data or cause denial of service.

    Published: 19 Mar 2018
    2.9
    Low

    CVE-2018-5552

    Last Modified: 21 Nov 2024

    Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contains a hard-coded cryptographic salt, "S@l+&pepper".

    Published: 19 Mar 2018
    9
    Critical

    CVE-2018-5551

    Last Modified: 21 Nov 2024

    Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contain three credentials with known passwords: QDMaster, OTMaster, and sa.

    Published: 19 Mar 2018
    7.2
    High

    CVE-2018-6843

    Last Modified: 19 Dec 2025

    Kentico 10 before 10.0.50 and 11 before 11.0.3 has SQL injection in the administration interface.

    Published: 19 Mar 2018
    5.4
    Medium

    CVE-2018-6842

    Last Modified: 19 Dec 2025

    Kentico 10 before 10.0.50 and 11 before 11.0.3 has XSS in which a crafted URL results in improper construction of a system page.

    Published: 19 Mar 2018
    7.5
    High

    CVE-2018-7422

    Last Modified: 21 Nov 2024

    A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve arbitrary files via the ajax_path parameter to editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php, aka absolute path traversal.

    Published: 19 Mar 2018
    7.5
    High

    CVE-2018-8761

    Last Modified: 21 Nov 2024

    protected\apps\member\controller\shopcarController.php in Yxcms building system (compatible cell phone) v1.4.7 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture.

    Published: 19 Mar 2018
    7.5
    High

    CVE-2014-3626

    Last Modified: 21 Nov 2024

    The Grails Resource Plugin often has to exchange URIs for resources with other internal components. Those other components will decode any URI passed to them. To protect against directory traversal the Grails Resource Plugin did the following: normalized the URI, checked the normalized URI did not step outside the appropriate root directory (e.g. the web application root), decoded the URI and checked that this did not introduce additional /../ (and similar) sequences. A bug was introduced where the Grails Resource Plugin before 1.2.13 returned the decoded version of the URI rather than the normalized version of the URI after the directory traversal check. This exposed a double decoding vulnerability. To address this issue, the Grails Resource Plugin now repeatedly decodes the URI up to three times or until decoding no longer changes the URI. If the decode limit of 3 is exceeded the URI is rejected. A side-effect of this is that the Grails Resource Plugin is unable to serve a resource that includes a '%' character in the full path to the resource. Not all environments are vulnerable because of the differences in URL resolving in different servlet containers. Applications deployed to Tomcat 8 and Jetty 9 were found not not be vulnerable, however applications deployed to JBoss EAP 6.3 / JBoss AS 7.4 and JBoss AS 7.1 were found to be vulnerable (other JBoss versions weren't tested). In certain cases JBoss returns JBoss specific vfs protocol urls from URL resolution methods (ClassLoader.getResources). The JBoss vfs URL protocol supports resolving any file on the filesystem. This made the directory traversal possible. There may be other containers, in addition to JBoss, on which this vulnerability is exposed.

    Published: 19 Mar 2018
    7.5
    High

    CVE-2015-5350

    Last Modified: 21 Nov 2024

    In Garden versions 0.22.0-0.329.0, a vulnerability has been discovered in the garden-linux nstar executable that allows access to files on the host system. By staging an application on Cloud Foundry using Diego and Garden installations with a malicious custom buildpack an end user could read files on the host system that the BOSH-created vcap user has permissions to read and then package them into their app droplet.

    Published: 19 Mar 2018
    5.5
    Medium

    CVE-2017-18240

    Last Modified: 21 Nov 2024

    The Gentoo app-admin/collectd package before 5.7.2-r1 sets the ownership of PID file directory to the collectd account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL (when the service is stopped).

    Published: 19 Mar 2018
    7.5
    High

    CVE-2018-9234

    Last Modified: 21 Nov 2024

    GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

    Published: 19 Mar 2018
    9.8
    Critical

    CVE-2018-8766

    Last Modified: 21 Nov 2024

    joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, related to manager/admin_vod.php?action=add.

    Published: 18 Mar 2018
    4.8
    Medium

    CVE-2018-8767

    Last Modified: 21 Nov 2024

    joyplus-cms 1.6.0 has XSS in manager/admin_ajax.php?action=save&tab={pre}vod_type via the t_name parameter.

    Published: 18 Mar 2018
    7.8
    High

    CVE-2018-8768

    Last Modified: 21 Nov 2024

    In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.

    Published: 18 Mar 2018
    7.2
    High

    CVE-2018-8756

    Last Modified: 21 Nov 2024

    Eval injection in yzmphp/core/function/global.func.php in YzmCMS v3.7.1 allows remote attackers to achieve arbitrary code execution via PHP code in the POST data of an index.php?m=member&c=member_content&a=init request.

    Published: 18 Mar 2018
    7.8
    High

    CVE-2018-8765

    Last Modified: 21 Nov 2024

    In 2345 Security Guard 3.6, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222018.

    Published: 18 Mar 2018
    5.3
    Medium

    CVE-2018-8770

    Last Modified: 21 Nov 2024

    Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, controllers/postclientdataTest.php, controllers/posterrorTest.php, controllers/posteventTest.php, controllers/posttagTest.php, controllers/postusinglogTest.php, fixtures/Controller_fixt.php, fixtures/Controller_fixt2.php, fixtures/view_fixt2.php, libs/ipTest.php, or models/commonDbfix.php in tests/.

    Published: 18 Mar 2018
    5.5
    Medium

    CVE-2018-8754

    Last Modified: 21 Nov 2024

    The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly check for out-of-bounds values of user SID data size, strings size, or data size. NOTE: the vendor has disputed this as described in libyal/libevt issue 5 on GitHub

    Published: 18 Mar 2018
    9.8
    Critical

    CVE-2017-18239

    Last Modified: 21 Nov 2024

    A time-sensitive equality check on the JWT signature in the JsonWebToken.validate method in main/scala/authentikat/jwt/JsonWebToken.scala in authentikat-jwt (aka com.jason-goodwin/authentikat-jwt) version 0.4.5 and earlier allows the supplier of a JWT token to guess bit after bit of the signature by repeating validation requests.

    Published: 18 Mar 2018
    7.8
    High

    CVE-2018-8769

    Last Modified: 21 Nov 2024

    elfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_SHNDX is unsupported.

    Published: 18 Mar 2018
    5.4
    Medium

    CVE-2018-8737

    Last Modified: 21 Nov 2024

    Bookme Control Panel 2.0 Application is vulnerable to stored XSS within the Customers "Book Me" function. Within the Name and Note (aka custName and custNote) sections of the Customers screen, the application does not sanitize user-supplied input and renders injected JavaScript code to the user's browser.

    Published: 17 Mar 2018
    4.2
    Medium

    CVE-2018-1002100

    Last Modified: 21 Nov 2024

    In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.

    Published: 17 Mar 2018
    8.8
    High

    CVE-2018-8905

    Last Modified: 21 Nov 2024

    In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF file, as demonstrated by tiff2ps.

    Published: 17 Mar 2018
    7.5
    High

    CVE-2018-8740

    Last Modified: 21 Nov 2024

    In SQLite through 3.22.0, databases whose schema is corrupted using a CREATE TABLE AS statement could cause a NULL pointer dereference, related to build.c and prepare.c.

    Published: 17 Mar 2018