CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2018-0941

    Last Modified: 21 Nov 2024

    Microsoft Exchange Server 2016 Cumulative Update 7 and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how data is imported, aka "Microsoft Exchange Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0924.

    Published: 14 Mar 2018
    8.8
    High

    CVE-2018-0947

    Last Modified: 21 Nov 2024

    Microsoft SharePoint Foundation 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914, CVE-2018-0915, CVE-2018-0916, CVE-2018-0917, CVE-2018-0921, CVE-2018-0923 and CVE-2018-0944.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-5779

    Last Modified: 21 Nov 2024

    A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to copy a malicious script into a newly generated PHP file and then execute the generated file using specially crafted requests. Successful exploit could allow an attacker to execute arbitrary code within the context of the application.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-5780

    Last Modified: 21 Nov 2024

    A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vnewmeeting.php page. Successful exploit could allow an attacker to execute arbitrary PHP code within the context of the application.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-5781

    Last Modified: 21 Nov 2024

    A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vendrecording.php page. Successful exploit could allow an attacker to execute arbitrary PHP code within the context of the application.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-5782

    Last Modified: 21 Nov 2024

    A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vsethost.php page. Successful exploit could allow an attacker to execute arbitrary PHP code within the context of the application.

    Published: 14 Mar 2018
    3.5
    Low

    CVE-2018-7677

    Last Modified: 21 Nov 2024

    A CSRF exposure exists in NetIQ Access Manager (NAM) 4.4 Identity Server component.

    Published: 14 Mar 2018
    3.5
    Low

    CVE-2018-7678

    Last Modified: 21 Nov 2024

    A cross site scripting vulnerability exist in the Administration Console in NetIQ Access Manager (NAM) 4.3 and 4.4.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-7474

    Last Modified: 21 Nov 2024

    An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-1000131

    Last Modified: 21 Nov 2024

    Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This vulnerability appears to have been fixed in 9.0.3 and later.

    Published: 14 Mar 2018
    7.5
    High

    CVE-2018-6875

    Last Modified: 21 Nov 2024

    Format String vulnerability in KeepKey version 4.0.0 allows attackers to trigger information display (of information that should not be accessible), related to text containing characters that the device's font lacks.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-7279

    Last Modified: 21 Nov 2024

    A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-8097

    Last Modified: 21 Nov 2024

    io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where parameter.

    Published: 14 Mar 2018
    6.1
    Medium

    CVE-2018-8108

    Last Modified: 21 Nov 2024

    The select component in bui through 2018-03-13 has XSS because it performs an escape operation on already-escaped text, as demonstrated by workGroupList text.

    Published: 14 Mar 2018
    7.8
    High

    CVE-2018-8100

    Last Modified: 21 Nov 2024

    The JPXStream::readTilePart function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a specific pdf file, as demonstrated by pdftohtml.

    Published: 14 Mar 2018
    5.5
    Medium

    CVE-2018-8101

    Last Modified: 21 Nov 2024

    The JPXStream::inverseTransformLevel function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

    Published: 14 Mar 2018
    5.5
    Medium

    CVE-2018-8102

    Last Modified: 21 Nov 2024

    The JBIG2MMRDecoder::getBlackCode function in JBIG2Stream.cc in xpdf 4.00 allows attackers to launch denial of service (buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

    Published: 14 Mar 2018
    5.5
    Medium

    CVE-2018-8103

    Last Modified: 21 Nov 2024

    The JBIG2Stream::readGenericBitmap function in JBIG2Stream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

    Published: 14 Mar 2018
    5.5
    Medium

    CVE-2018-8104

    Last Modified: 21 Nov 2024

    The BufStream::lookChar function in Stream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

    Published: 14 Mar 2018
    5.5
    Medium

    CVE-2018-8106

    Last Modified: 21 Nov 2024

    The JPXStream::readTilePartData function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

    Published: 14 Mar 2018
    5.5
    Medium

    CVE-2018-8107

    Last Modified: 21 Nov 2024

    The JPXStream::close function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

    Published: 14 Mar 2018
    5.5
    Medium

    CVE-2018-8105

    Last Modified: 21 Nov 2024

    The JPXStream::fillReadBuf function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read and application crash) via a specific pdf file, as demonstrated by pdftohtml.

    Published: 14 Mar 2018
    8.8
    High

    CVE-2018-5130

    Last Modified: 25 Nov 2025

    When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.

    Published: 14 Mar 2018
    8.6
    High

    CVE-2018-5129

    Last Modified: 25 Nov 2025

    A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.

    Published: 14 Mar 2018
    8.8
    High

    CVE-2018-5127

    Last Modified: 25 Nov 2025

    A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-8096

    Last Modified: 21 Nov 2024

    Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name":"isauthenticationenabled","Value":false' in an api/settings/setting-isauthenticationenabled PUT request.

    Published: 14 Mar 2018
    5.9
    Medium

    CVE-2018-5131

    Last Modified: 25 Nov 2025

    Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a copy from the network as it should. This can result in previously stored, locally cached data of a website being accessible to users if they share a common profile while browsing. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.

    Published: 14 Mar 2018
    7.5
    High

    CVE-2018-1060

    Last Modified: 21 Nov 2024

    python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.

    Published: 14 Mar 2018
    7.8
    High

    CVE-2018-1386

    Last Modified: 21 Nov 2024

    IBM Tivoli Workload Automation for AIX (IBM Workload Scheduler 8.6, 9.1, 9.2, 9.3, and 9.4) contains directories with improper permissions that could allow a local user to with special access to gain root privileges. IBM X-Force ID: 138208.

    Published: 14 Mar 2018
    7.8
    High

    CVE-2018-1435

    Last Modified: 21 Nov 2024

    IBM Notes 8.5 and 9.0 is vulnerable to a DLL hijacking attack. A remote attacker could trick a user to double click a malicious executable in an attacker-controlled directory, which could result in code execution. IBM X-Force ID: 139563.

    Published: 14 Mar 2018
    7.8
    High

    CVE-2018-1437

    Last Modified: 21 Nov 2024

    IBM Notes 8.5 and 9.0 could allow an attacker to execute arbitrary code on the system, caused by an error related to multiple untrusted search path. A local attacker could exploit this vulnerability to DLL hijacking to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 139565.

    Published: 14 Mar 2018
    6.1
    Medium

    CVE-2018-1441

    Last Modified: 21 Nov 2024

    IBM Application Performance Management - Response Time Monitoring Agent (IBM Monitoring 8.1.3 and 8.1.4) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139597.

    Published: 14 Mar 2018
    6.5
    Medium

    CVE-2018-5804

    Last Modified: 21 Nov 2024

    A type confusion error within the "identify()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a division by zero.

    Published: 14 Mar 2018
    8.8
    High

    CVE-2018-5805

    Last Modified: 21 Nov 2024

    A boundary error within the "quicktake_100_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to cause a stack-based buffer overflow and subsequently cause a crash.

    Published: 14 Mar 2018
    Unknown

    CVE-2018-8661

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 14 Mar 2018
    7.5
    High

    CVE-2018-9257

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5, the CQL dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-cql.c by checking for a nonzero number of columns.

    Published: 14 Mar 2018
    4.3
    Medium

    CVE-2019-16680

    Last Modified: 21 Nov 2024

    An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.

    Published: 14 Mar 2018
    4.3
    Medium

    CVE-2017-1741

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console panel fields. When exploited an attacker could read files on the file system. IBM X-Force ID: 134931.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-1000120

    Last Modified: 21 Nov 2024

    A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse.

    Published: 14 Mar 2018
    6.5
    Medium

    CVE-2018-1061

    Last Modified: 21 Nov 2024

    python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.

    Published: 14 Mar 2018
    7.5
    High

    CVE-2018-1064

    Last Modified: 21 Nov 2024

    libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2017-12194

    Last Modified: 21 Nov 2024

    A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-5145

    Last Modified: 25 Nov 2025

    Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.

    Published: 14 Mar 2018
    7.3
    High

    CVE-2018-5144

    Last Modified: 25 Nov 2025

    An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.

    Published: 14 Mar 2018
    6.5
    Medium

    CVE-2018-5806

    Last Modified: 21 Nov 2024

    An error within the "leaf_hdr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to trigger a NULL pointer dereference.

    Published: 14 Mar 2018
    7.5
    High

    CVE-2018-1000121

    Last Modified: 21 Nov 2024

    A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service

    Published: 14 Mar 2018
    9.1
    Critical

    CVE-2018-1000122

    Last Modified: 21 Nov 2024

    A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage

    Published: 14 Mar 2018
    5.4
    Medium

    CVE-2018-1444

    Last Modified: 21 Nov 2024

    IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 139906.

    Published: 14 Mar 2018
    8.8
    High

    CVE-2018-5125

    Last Modified: 25 Nov 2025

    Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.

    Published: 14 Mar 2018
    10
    Critical

    CVE-2018-1000124

    Last Modified: 5 Dec 2025

    I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the contents of a file and SSRF. This attack appear to be exploitable via posting xml in the Parameter form_import_textarea.

    Published: 13 Mar 2018