CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2018-15856

    Last Modified: 21 Nov 2024

    An infinite loop when reaching EOL unexpectedly in compose/parser.c (aka the keymap parser) in xkbcommon before 0.8.1 could be used by local attackers to cause a denial of service during parsing of crafted keymap files.

    Published: 12 Mar 2018
    8.8
    High

    CVE-2017-1002101

    Last Modified: 21 Nov 2024

    In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.

    Published: 12 Mar 2018
    7.5
    High

    CVE-2018-1077

    Last Modified: 21 Nov 2024

    Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.

    Published: 12 Mar 2018
    8.8
    High

    CVE-2018-8059

    Last Modified: 21 Nov 2024

    The Djelibeybi configuration examples for use of NGINX in SUSE Portus 2.3, when applied to certain configurations involving Docker Compose, have a Missing SSL Certificate Validation issue because no proxy_ssl_* directives are used.

    Published: 11 Mar 2018
    7.5
    High

    CVE-2018-8056

    Last Modified: 21 Nov 2024

    Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/manage/channel/addchannel or a direct request to /export.php.

    Published: 11 Mar 2018
    9.8
    Critical

    CVE-2018-8057

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/addchannel request, related to /application/controllers/manage/channel.php.

    Published: 11 Mar 2018
    6.5
    Medium

    CVE-2018-8050

    Last Modified: 21 Nov 2024

    The af_get_page() function in lib/afflib_pages.cpp in AFFLIB (aka AFFLIBv3) through 3.7.16 allows remote attackers to cause a denial of service (segmentation fault) via a corrupt AFF image that triggers an unexpected pagesize value.

    Published: 11 Mar 2018
    9.8
    Critical

    CVE-2018-7213

    Last Modified: 21 Nov 2024

    The Password Manager Extension in Abine Blur 7.8.242* before 7.8.2428 allows attackers to bypass the Multi-Factor Authentication and macOS disk-encryption protection mechanisms, and consequently exfiltrate secured data, because the right-click context menu is not secured.

    Published: 11 Mar 2018
    5.5
    Medium

    CVE-2018-15855

    Last Modified: 21 Nov 2024

    Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because the XkbFile for an xkb_geometry section was mishandled.

    Published: 11 Mar 2018
    7.2
    High

    CVE-2018-6312

    Last Modified: 21 Nov 2024

    A privileged account with a weak default password on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 can be used to turn on the TELNET service via the web interface, which allows root login without any password. This vulnerability will lead to full system compromise and disclosure of user communications. The foxconn account with an 8-character lowercase alphabetic password can be used.

    Published: 10 Mar 2018
    8.1
    High

    CVE-2017-18223

    Last Modified: 21 Nov 2024

    BMC Remedy AR System before 9.1 SP3, when Remedy AR Authentication is enabled, allows attackers to obtain administrative access.

    Published: 10 Mar 2018
    6.8
    Medium

    CVE-2018-6311

    Last Modified: 21 Nov 2024

    One can gain root access on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 via UART pins without any restrictions, which leads to full system compromise and disclosure of user communications.

    Published: 10 Mar 2018
    5.5
    Medium

    CVE-2018-15853

    Last Modified: 21 Nov 2024

    Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation.

    Published: 10 Mar 2018
    5.5
    Medium

    CVE-2018-15854

    Last Modified: 21 Nov 2024

    Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because geometry tokens were desupported incorrectly.

    Published: 10 Mar 2018
    8.8
    High

    CVE-2018-3846

    Last Modified: 21 Nov 2024

    In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.

    Published: 10 Mar 2018
    8.8
    High

    CVE-2018-3848

    Last Modified: 21 Nov 2024

    In the ffghbn function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.

    Published: 10 Mar 2018
    8.8
    High

    CVE-2018-3849

    Last Modified: 21 Nov 2024

    In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.

    Published: 10 Mar 2018
    8.8
    High

    CVE-2018-7230

    Last Modified: 21 Nov 2024

    A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67.

    Published: 9 Mar 2018
    9.8
    Critical

    CVE-2018-7233

    Last Modified: 21 Nov 2024

    A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'model_name' or 'mac_address'.

    Published: 9 Mar 2018
    7.5
    High

    CVE-2018-7234

    Last Modified: 21 Nov 2024

    A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of SSL certificate.

    Published: 9 Mar 2018
    7.5
    High

    CVE-2018-7235

    Last Modified: 21 Nov 2024

    A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of the shell meta characters with the value of 'system.download.sd_file'

    Published: 9 Mar 2018
    8.1
    High

    CVE-2018-7236

    Last Modified: 21 Nov 2024

    A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could enable SSH service due to lack of authentication for /login/bin/set_param could enable SSH service.

    Published: 9 Mar 2018
    9.8
    Critical

    CVE-2018-7238

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability exist in the web-based GUI of Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to execute arbitrary code.

    Published: 9 Mar 2018
    7.8
    High

    CVE-2018-7239

    Last Modified: 21 Nov 2024

    A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM software components in all versions prior to 2.6.2 which could allow an attacker to execute arbitrary code.

    Published: 9 Mar 2018
    5.3
    Medium

    CVE-2018-7227

    Last Modified: 21 Nov 2024

    A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow retrieving of specially crafted URLs without authentication that can reveal sensitive information to an attacker.

    Published: 9 Mar 2018
    9.8
    Critical

    CVE-2018-7229

    Last Modified: 21 Nov 2024

    A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and gain administrator privileges because the use of hardcoded credentials.

    Published: 9 Mar 2018
    9.8
    Critical

    CVE-2018-7231

    Last Modified: 21 Nov 2024

    A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'system.opkg.remove'.

    Published: 9 Mar 2018
    9.1
    Critical

    CVE-2018-7237

    Last Modified: 21 Nov 2024

    A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow a remote attacker to delete arbitrary system file due to lack of validation of the /login/bin/set_param to the file name with the value of 'system.delete.sd_file'

    Published: 9 Mar 2018
    9.8
    Critical

    CVE-2018-7228

    Last Modified: 21 Nov 2024

    A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and get the administrator privileges.

    Published: 9 Mar 2018
    9.8
    Critical

    CVE-2018-7232

    Last Modified: 21 Nov 2024

    A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'network.ieee8021x.delete_certs'.

    Published: 9 Mar 2018
    5.3
    Medium

    CVE-2016-8782

    Last Modified: 21 Nov 2024

    Huawei CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00 have a memory leak vulnerability. An unauthenticated attacker may send specific Label Distribution Protocol (LDP) packets to the devices repeatedly. Due to improper validation of some specific fields of the packet, the LDP processing module does not release the memory, resulting in memory leak.

    Published: 9 Mar 2018
    4.3
    Medium

    CVE-2016-8785

    Last Modified: 21 Nov 2024

    Huawei S12700 V200R007C00, V200R008C00, S5700 V200R007C00, S7700 V200R002C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, S9700 V200R007C00 have an input validation vulnerability. Due to the lack of input validation, an attacker may craft a malformed packet and send it to the device using VRP, causing the device to display additional memory data and possibly leading to sensitive information leakage.

    Published: 9 Mar 2018
    3.1
    Low

    CVE-2017-17282

    Last Modified: 21 Nov 2024

    SCCP (Signalling Connection Control Part) module in Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 has a buffer overflow vulnerability. An attacker has to find a way to send malformed packets to the affected products repeatedly. Due to insufficient input validation, successful exploit may cause some service abnormal.

    Published: 9 Mar 2018
    4.3
    Medium

    CVE-2016-8784

    Last Modified: 21 Nov 2024

    Huawei CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00 have a memory leak vulnerability. An unauthenticated attacker may send specific Label Distribution Protocol (LDP) packets to the devices. When the values of some parameters in the packet are abnormal, the LDP processing module does not release the memory to handle the packet, resulting in memory leak.

    Published: 9 Mar 2018
    7.8
    High

    CVE-2016-8783

    Last Modified: 21 Nov 2024

    Touchscreen drive in Huawei H60 (Honor 6) Versions earlier than H60-L02_6.12.16 and P9 Plus Versions earlier than VIE-AL10BC00B356 has a stack overflow vulnerabilities. An attacker tricks a user into installing a malicious application on the smart phone, and send given parameter to touchscreen drive to crash the system or escalate privilege.

    Published: 9 Mar 2018
    7.5
    High

    CVE-2016-8786

    Last Modified: 21 Nov 2024

    Huawei S12700 V200R005C00, V200R006C00, V200R007C00, V200R008C00, S5700 V200R006C00, V200R007C00, V200R008C00, S6700 V200R008C00, S7700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, S9700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00 have a denial of service (DoS) vulnerability. Due to the lack of input validation, a remote attacker may craft a malformed Resource Reservation Protocol (RSVP) packet and send it to the device, causing a few buffer overflows and occasional device restart.

    Published: 9 Mar 2018
    5.5
    Medium

    CVE-2017-15314

    Last Modified: 21 Nov 2024

    Huawei DP300 V500R002C00, RP200 V500R002C00SPC200, V600R006C00, TE30 V100R001C10SPC300, V100R001C10SPC500, V100R001C10SPC600, V100R001C10SPC700, V500R002C00SPC200, V500R002C00SPC500, V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPC900, V500R002C00SPCb00, V600R006C00, TE40 V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPC900, V500R002C00SPCb00, V600R006C00, TE50 V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPCb00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a memory leak vulnerability due to memory don't be released when the XML parser process some node fail. An attacker could exploit it to cause memory leak, which may further lead to system exceptions.

    Published: 9 Mar 2018
    6.5
    Medium

    CVE-2017-15315

    Last Modified: 21 Nov 2024

    Patch module of Huawei NIP6300 V500R001C20SPC100, V500R001C20SPC200, NIP6600 V500R001C20SPC100, V500R001C20SPC200, Secospace USG6300 V500R001C20SPC100, V500R001C20SPC200, Secospace USG6500 V500R001C20SPC100, V500R001C20SPC200 has a memory leak vulnerability. An authenticated attacker could execute special commands many times, the memory leaking happened, which would cause the device to reset finally.

    Published: 9 Mar 2018
    5.5
    Medium

    CVE-2017-15323

    Last Modified: 21 Nov 2024

    Huawei DP300 V500R002C00, NIP6600 V500R001C00, V500R001C20, V500R001C30, Secospace USG6500 V500R001C00, V500R001C20, V500R001C30, TE60 V100R001C01, V100R001C10, V100R003C00, V500R002C00, V600R006C00, TP3106 V100R001C06, V100R002C00, VP9660 V200R001C02, V200R001C30, V500R002C00, V500R002C10, ViewPoint 8660 V100R008C03, ViewPoint 9030 V100R011C02, V100R011C03, eCNS210_TD V100R004C10, eSpace U1981 V200R003C30 have a DoS vulnerability caused by memory exhaustion in some Huawei products. For lacking of adequate input validation, attackers can craft and send some malformed messages to the target device to exhaust the memory of the device and cause a Denial of Service (DoS).

    Published: 9 Mar 2018
    9.8
    Critical

    CVE-2014-2592

    Last Modified: 21 Nov 2024

    Unrestricted file upload vulnerability in Aruba Web Management portal allows remote attackers to execute arbitrary code by uploading a file with an executable extension.

    Published: 9 Mar 2018
    7.8
    High

    CVE-2018-7581

    Last Modified: 21 Nov 2024

    \ProgramData\WebLog Expert\WebServer\WebServer.cfg in WebLog Expert Web Server Enterprise 9.4 has weak permissions (BUILTIN\Users:(ID)C), which allows local users to set a cleartext password and login as admin.

    Published: 9 Mar 2018
    7.5
    High

    CVE-2018-7582

    Last Modified: 21 Nov 2024

    WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to TCP port 9991.

    Published: 9 Mar 2018
    9.8
    Critical

    CVE-2014-4861

    Last Modified: 21 Nov 2024

    The Remote Desktop Launcher in Thycotic Secret Server before 8.6.000010 does not properly cleanup a temporary file that contains an encrypted password once a session has ended.

    Published: 9 Mar 2018
    9.8
    Critical

    CVE-2014-6617

    Last Modified: 21 Nov 2024

    Softing FG-100 PB PROFIBUS firmware version FG-x00-PB_V2.02.0.00 contains a hardcoded password for the root account, which allows remote attackers to obtain administrative access via a TELNET session.

    Published: 9 Mar 2018
    5.4
    Medium

    CVE-2018-7290

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists in Tiki before 12.13, 15.6, 17.2, and 18.1.

    Published: 9 Mar 2018
    Unknown

    CVE-2018-7861

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 9 Mar 2018
    Unknown

    CVE-2018-7862

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 9 Mar 2018
    Unknown

    CVE-2018-7863

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 9 Mar 2018
    Unknown

    CVE-2018-7864

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 9 Mar 2018
    Unknown

    CVE-2018-7865

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 9 Mar 2018