CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-7714

    Last Modified: 21 Nov 2024

    The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cause a denial of service (assertion failure) because (pixels <= (1<<30)) may be false. Note: “OpenCV CV_Assert is not an assertion (C-like assert()), it is regular C++ exception which can raised in case of invalid or non-supported parameters.

    Published: 5 Mar 2018
    8.8
    High

    CVE-2018-7999

    Last Modified: 21 Nov 2024

    In libgraphite2 in graphite2 1.3.11, a NULL pointer dereference vulnerability was found in Segment.cpp during a dumbRendering operation, which may allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .ttf file.

    Published: 5 Mar 2018
    7.5
    High

    CVE-2018-1054

    Last Modified: 21 Nov 2024

    An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.

    Published: 5 Mar 2018
    6.7
    Medium

    CVE-2018-1068

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privileged user to arbitrarily write to a limited range of kernel memory.

    Published: 5 Mar 2018
    7.5
    High

    CVE-2018-1320

    Last Modified: 21 Nov 2024

    Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.

    Published: 5 Mar 2018
    5.3
    Medium

    CVE-2018-7662

    Last Modified: 21 Nov 2024

    Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.func.php or addons/phpmailer/phpmailer.php.

    Published: 4 Mar 2018
    5.3
    Medium

    CVE-2018-7661

    Last Modified: 21 Nov 2024

    Papenmeier WiFi Baby Monitor Free & Lite before 2.02.2 allows remote attackers to obtain audio data via certain requests to TCP ports 8258 and 8257.

    Published: 4 Mar 2018
    7.5
    High

    CVE-2018-7560

    Last Modified: 21 Nov 2024

    index.js in the Anton Myshenin aws-lambda-multipart-parser NPM package before 0.1.2 has a Regular Expression Denial of Service (ReDoS) issue via a crafted multipart/form-data boundary string.

    Published: 4 Mar 2018
    7.2
    High

    CVE-2018-7567

    Last Modified: 21 Nov 2024

    In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are able to exploit a Blind Remote Code Execution vulnerability by loading a crafted opm file with an embedded CodeInstall element to execute a command on the server during package installation. NOTE: the vendor disputes this issue stating "the behaviour is as designed and needed for different packages to be installed", "there is a security warning if the package is not verified by OTRS Group", and "there is the possibility and responsibility of an admin to check packages before installation which is possible as they are not binary.

    Published: 4 Mar 2018
    6.1
    Medium

    CVE-2018-7653

    Last Modified: 21 Nov 2024

    In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.

    Published: 4 Mar 2018
    7.2
    High

    CVE-2017-18213

    Last Modified: 21 Nov 2024

    In Exponent CMS before 2.4.1 Patch #6, certain admin users can elevate their privileges.

    Published: 4 Mar 2018
    5.9
    Medium

    CVE-2018-7651

    Last Modified: 21 Nov 2024

    index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in strict mode functionality via a long base64 hash string.

    Published: 4 Mar 2018
    6.1
    Medium

    CVE-2018-7652

    Last Modified: 21 Nov 2024

    lib/Zonemaster/GUI/Dancer/Export.pm in Zonemaster Web GUI before 1.0.11 has XSS.

    Published: 4 Mar 2018
    7.5
    High

    CVE-2018-7449

    Last Modified: 21 Nov 2024

    SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an invalid LIST, STOR, or RETR command.

    Published: 4 Mar 2018
    7.5
    High

    CVE-2018-7583

    Last Modified: 21 Nov 2024

    Proxy.exe in DualDesk 20 allows Remote Denial Of Service (daemon crash) via a long string to TCP port 5500.

    Published: 4 Mar 2018
    6.5
    Medium

    CVE-2018-7654

    Last Modified: 21 Nov 2024

    On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access to files on the server via path traversal.

    Published: 4 Mar 2018
    9.8
    Critical

    CVE-2018-1000613

    Last Modified: 12 May 2025

    Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.

    Published: 3 Mar 2018
    7.8
    High

    CVE-2015-7596

    Last Modified: 21 Nov 2024

    SafeNet Authentication Service End User Software Tools for Windows uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.

    Published: 2 Mar 2018
    7.8
    High

    CVE-2015-7962

    Last Modified: 21 Nov 2024

    SafeNet Authentication Service for Outlook Web App Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.

    Published: 2 Mar 2018
    7.8
    High

    CVE-2015-7597

    Last Modified: 21 Nov 2024

    SafeNet Authentication Service IIS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.

    Published: 2 Mar 2018
    7.8
    High

    CVE-2015-7963

    Last Modified: 21 Nov 2024

    SafeNet Authentication Service for AD FS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.

    Published: 2 Mar 2018
    7.8
    High

    CVE-2015-7598

    Last Modified: 21 Nov 2024

    SafeNet Authentication Service TokenValidator Proxy Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.

    Published: 2 Mar 2018
    7.8
    High

    CVE-2015-7961

    Last Modified: 21 Nov 2024

    SafeNet Authentication Service Remote Web Workplace Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.

    Published: 2 Mar 2018
    7.8
    High

    CVE-2015-7964

    Last Modified: 21 Nov 2024

    SafeNet Authentication Service for NPS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.

    Published: 2 Mar 2018
    7.8
    High

    CVE-2015-7965

    Last Modified: 21 Nov 2024

    SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module, a different vulnerability than CVE-2015-7966.

    Published: 2 Mar 2018
    7.8
    High

    CVE-2015-7966

    Last Modified: 21 Nov 2024

    SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module, a different vulnerability than CVE-2015-7965.

    Published: 2 Mar 2018
    7.8
    High

    CVE-2015-7967

    Last Modified: 21 Nov 2024

    SafeNet Authentication Service for Citrix Web Interface Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.

    Published: 2 Mar 2018
    6.3
    Medium

    CVE-2015-0796

    Last Modified: 21 Nov 2024

    In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files like symlinks or device nodes, which could allow buildservice users to break of confinement or cause denial of service attacks on the source service.

    Published: 2 Mar 2018
    4.6
    Medium

    CVE-2017-14801

    Last Modified: 21 Nov 2024

    Reflected XSS in the NetIQ Access Manager before 4.3.3 allowed attackers to reflect back xss into the called page using the url parameter.

    Published: 2 Mar 2018
    5.4
    Medium

    CVE-2017-14802

    Last Modified: 21 Nov 2024

    Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects to third party sites.

    Published: 2 Mar 2018
    4.6
    Medium

    CVE-2017-7438

    Last Modified: 21 Nov 2024

    NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via javascript DOM modification using the supplied cookie parameter.

    Published: 2 Mar 2018
    5.4
    Medium

    CVE-2017-9276

    Last Modified: 21 Nov 2024

    Novell Access Manager iManager before 4.3.3 did not validate parameters so that cross site scripting content could be reflected back into the result page using the "a" parameter.

    Published: 2 Mar 2018
    2
    Low

    CVE-2017-9279

    Last Modified: 21 Nov 2024

    NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Application Administration, allowing malicious user administrators to potentially execute code or mislead users.

    Published: 2 Mar 2018
    5.4
    Medium

    CVE-2017-9285

    Last Modified: 21 Nov 2024

    NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.

    Published: 2 Mar 2018
    4.3
    Medium

    CVE-2017-5189

    Last Modified: 21 Nov 2024

    NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.

    Published: 2 Mar 2018
    4.6
    Medium

    CVE-2017-7419

    Last Modified: 21 Nov 2024

    A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks due to unescaped "description" field that could be specified by the provider.

    Published: 2 Mar 2018
    8.8
    High

    CVE-2017-7429

    Last Modified: 21 Nov 2024

    The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.

    Published: 2 Mar 2018
    3.3
    Low

    CVE-2017-7434

    Last Modified: 21 Nov 2024

    In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles.

    Published: 2 Mar 2018
    6.5
    Medium

    CVE-2017-9267

    Last Modified: 21 Nov 2024

    In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations.

    Published: 2 Mar 2018
    3.3
    Low

    CVE-2017-9278

    Last Modified: 21 Nov 2024

    The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the EBS tables.

    Published: 2 Mar 2018
    4.3
    Medium

    CVE-2017-9280

    Last Modified: 21 Nov 2024

    Some NetIQ Identity Manager Applications before Identity Manager 4.5.6.1 included the session token in GET URLs, potentially allowing exposure of user sessions to untrusted third parties via proxies, referer urls or similar.

    Published: 2 Mar 2018
    4.2
    Medium

    CVE-2017-9277

    Last Modified: 21 Nov 2024

    The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open connections without EBA.

    Published: 2 Mar 2018
    7.5
    High

    CVE-2018-7433

    Last Modified: 21 Nov 2024

    The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.

    Published: 2 Mar 2018
    7.5
    High

    CVE-2018-1373

    Last Modified: 21 Nov 2024

    IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 137773.

    Published: 2 Mar 2018
    4.4
    Medium

    CVE-2017-1787

    Last Modified: 25 Mar 2025

    IBM Publishing Engine 2.1.2 and 6.0.5 contains an undisclosed vulnerability that could allow a local user with administrative privileges to obtain hard coded user credentials. IBM X-Force ID: 137022.

    Published: 2 Mar 2018
    4
    Medium

    CVE-2017-1654

    Last Modified: 21 Nov 2024

    IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data could be sent to IBM during service engagements. IBM X-Force ID: 133378.

    Published: 2 Mar 2018
    9.8
    Critical

    CVE-2018-7648

    Last Modified: 21 Nov 2024

    An issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output prefix was not checked for length, which could overflow a buffer, when providing a prefix with 50 or more characters on the command line.

    Published: 2 Mar 2018
    7.8
    High

    CVE-2018-7637

    Last Modified: 21 Nov 2024

    An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. This is in a "16 colors" case, aka case 4.

    Published: 2 Mar 2018
    7.8
    High

    CVE-2018-7638

    Last Modified: 21 Nov 2024

    An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. This is in a "256 colors" case, aka case 8.

    Published: 2 Mar 2018
    7.8
    High

    CVE-2018-7639

    Last Modified: 21 Nov 2024

    An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. This is in a "16 bits colors" case, aka case 16.

    Published: 2 Mar 2018