CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-7640

    Last Modified: 21 Nov 2024

    An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. This is in a Monochrome case, aka case 1.

    Published: 2 Mar 2018
    7.8
    High

    CVE-2018-7641

    Last Modified: 21 Nov 2024

    An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image, a different vulnerability than CVE-2018-7588. This is in a "32 bits colors" case, aka case 32.

    Published: 2 Mar 2018
    8.8
    High

    CVE-2018-1169

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of URI handlers. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5521.

    Published: 2 Mar 2018
    8.8
    High

    CVE-2018-1170

    Last Modified: 21 Nov 2024

    This vulnerability allows adjacent attackers to inject arbitrary Controller Area Network messages on vulnerable installations of Volkswagen Customer-Link App 1.30 and HTC Customer-Link Bridge. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Customer-Link App and Customer-Link Bridge. The issue results from the lack of a proper protection mechanism against unauthorized firmware updates. An attacker can leverage this vulnerability to inject CAN messages. Was ZDI-CAN-5264.

    Published: 2 Mar 2018
    5.9
    Medium

    CVE-2018-6490

    Last Modified: 21 Nov 2024

    Denial of Service vulnerability in Micro Focus Operations Orchestration Software, version 10.x. This vulnerability could be remotely exploited to allow Denial of Service.

    Published: 2 Mar 2018
    7.5
    High

    CVE-2018-9256

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the LWAPP dissector could crash. This was addressed in epan/dissectors/packet-lwapp.c by limiting the encapsulation levels to restrict the recursion depth.

    Published: 2 Mar 2018
    7.5
    High

    CVE-2018-9258

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by preserving valid data sources.

    Published: 2 Mar 2018
    7.5
    High

    CVE-2018-9262

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the VLAN dissector could crash. This was addressed in epan/dissectors/packet-vlan.c by limiting VLAN tag nesting to restrict the recursion depth.

    Published: 2 Mar 2018
    8.8
    High

    CVE-2018-9135

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.7-24 Q16, there is a heap-based buffer over-read in IsWEBPImageLossless in coders/webp.c.

    Published: 2 Mar 2018
    7.5
    High

    CVE-2018-1000115

    Last Modified: 21 Nov 2024

    Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. This vulnerability appears to have been fixed in 1.5.6 due to the disabling of the UDP protocol by default.

    Published: 2 Mar 2018
    7.5
    High

    CVE-2018-9260

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the IEEE 802.15.4 dissector could crash. This was addressed in epan/dissectors/packet-ieee802154.c by ensuring that an allocation step occurs.

    Published: 2 Mar 2018
    7.5
    High

    CVE-2018-9261

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-nbap.c by prohibiting the self-linking of DCH-IDs.

    Published: 2 Mar 2018
    8.8
    High

    CVE-2018-7634

    Last Modified: 21 Nov 2024

    An issue was discovered in Enalean Tuleap 9.17. Lack of CSRF attack mitigation while changing an e-mail address makes it possible to abuse the functionality by attackers. By making a CSRF attack, an attacker could make a victim change his registered e-mail address on the application, leading to account takeover.

    Published: 1 Mar 2018
    8.1
    High

    CVE-2017-6930

    Last Modified: 21 Nov 2024

    In Drupal versions 8.4.x versions before 8.4.5 when using node access controls with a multilingual site, Drupal marks the untranslated version of a node as the default fallback for access queries. This fallback is used for languages that do not yet have a translated version of the created node. This can result in an access bypass vulnerability. This issue is mitigated by the fact that it only applies to sites that a) use the Content Translation module; and b) use a node access module such as Domain Access which implement hook_node_access_records().

    Published: 1 Mar 2018
    8.1
    High

    CVE-2017-6926

    Last Modified: 21 Nov 2024

    In Drupal versions 8.4.x versions before 8.4.5 users with permission to post comments are able to view content and comments they do not have access to, and are also able to add comments to this content. This vulnerability is mitigated by the fact that the comment system must be enabled and the attacker must have permission to post comments.

    Published: 1 Mar 2018
    5.3
    Medium

    CVE-2017-6928

    Last Modified: 21 Nov 2024

    Drupal core 7.x versions before 7.57 when using Drupal's private file system, Drupal will check to make sure a user has access to a file before allowing the user to view or download it. This check fails under certain conditions in which one module is trying to grant access to the file and another is trying to deny it, leading to an access bypass vulnerability. This vulnerability is mitigated by the fact that it only occurs for unusual site configurations.

    Published: 1 Mar 2018
    4.7
    Medium

    CVE-2017-6932

    Last Modified: 21 Nov 2024

    Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacker to trick users into unwillingly navigating to an external site.

    Published: 1 Mar 2018
    6.1
    Medium

    CVE-2017-6927

    Last Modified: 21 Nov 2024

    Drupal 8.4.x versions before 8.4.5 and Drupal 7.x versions before 7.57 has a Drupal.checkPlain() JavaScript function which is used to escape potentially dangerous text before outputting it to HTML (as JavaScript output does not typically go through Twig autoescaping). This function does not correctly handle all methods of injecting malicious HTML, leading to a cross-site scripting vulnerability under certain circumstances. The PHP functions which Drupal provides for HTML escaping are not affected.

    Published: 1 Mar 2018
    6.1
    Medium

    CVE-2017-6929

    Last Modified: 21 Nov 2024

    A jQuery cross site scripting vulnerability is present when making Ajax requests to untrusted domains. This vulnerability is mitigated by the fact that it requires contributed or custom modules in order to exploit. For Drupal 8, this vulnerability was already fixed in Drupal 8.4.0 in the Drupal core upgrade to jQuery 3. For Drupal 7, it is fixed in the current release (Drupal 7.57) for jQuery 1.4.4 (the version that ships with Drupal 7 core) as well as for other newer versions of jQuery that might be used on the site, for example using the jQuery Update module.

    Published: 1 Mar 2018
    6.5
    Medium

    CVE-2017-6931

    Last Modified: 21 Nov 2024

    In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not have the permissions for. If you have implemented a Settings Tray form in contrib or a custom module, the correct access checks should be added. This release fixes the only two implementations in core, but does not harden against other such bypasses. This vulnerability can be mitigated by disabling the Settings Tray module.

    Published: 1 Mar 2018
    7.8
    High

    CVE-2018-7587

    Last Modified: 21 Nov 2024

    An issue was discovered in CImg v.220. DoS occurs when loading a crafted bmp image that triggers an allocation failure in load_bmp in CImg.h.

    Published: 1 Mar 2018
    7.8
    High

    CVE-2018-7589

    Last Modified: 21 Nov 2024

    An issue was discovered in CImg v.220. A double free in load_bmp in CImg.h occurs when loading a crafted bmp image.

    Published: 1 Mar 2018
    8.8
    High

    CVE-2018-7590

    Last Modified: 21 Nov 2024

    CSRF exists in Hoosk 1.7.0 via /admin/users/new/add, resulting in account creation.

    Published: 1 Mar 2018
    9.8
    Critical

    CVE-2017-18212

    Last Modified: 21 Nov 2024

    An issue was discovered in JerryScript 1.0. There is a heap-based buffer over-read in the lit_read_code_unit_from_hex function in lit/lit-char-helpers.c via a RegExp("[\x0"); payload.

    Published: 1 Mar 2018
    7.8
    High

    CVE-2018-7588

    Last Modified: 21 Nov 2024

    An issue was discovered in CImg v.220. A heap-based buffer over-read in load_bmp in CImg.h occurs when loading a crafted bmp image.

    Published: 1 Mar 2018
    7.5
    High

    CVE-2018-7586

    Last Modified: 21 Nov 2024

    In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.

    Published: 1 Mar 2018
    9.8
    Critical

    CVE-2018-7047

    Last Modified: 21 Nov 2024

    An issue was discovered in the MBeans Server in Wowza Streaming Engine before 4.7.1. The file system may be read and written to via JMX using the default JMX credentials (remote code execution may be possible as well).

    Published: 1 Mar 2018
    7.5
    High

    CVE-2018-7048

    Last Modified: 21 Nov 2024

    An issue was discovered in Wowza Streaming Engine before 4.7.1. There is a denial of service (memory consumption) via a crafted HTTP request.

    Published: 1 Mar 2018
    6.1
    Medium

    CVE-2018-7049

    Last Modified: 21 Nov 2024

    An issue was discovered in Wowza Streaming Engine before 4.7.1. There is an XSS vulnerability in the HTTP providers (com.wowza.wms.http.HTTPProviderMediaList and com.wowza.wms.http.streammanager.HTTPStreamManager) causing script injection and/or reflection via a crafted HTTP request.

    Published: 1 Mar 2018
    9.9
    Critical

    CVE-2017-14804

    Last Modified: 21 Nov 2024

    The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.

    Published: 1 Mar 2018
    4.4
    Medium

    CVE-2017-9268

    Last Modified: 21 Nov 2024

    In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions leading to denial of service (resource consumption).

    Published: 1 Mar 2018
    7.3
    High

    CVE-2017-14798

    Last Modified: 21 Nov 2024

    A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.

    Published: 1 Mar 2018
    4.6
    Medium

    CVE-2017-14799

    Last Modified: 21 Nov 2024

    A cross site scripting attack in handling the ESP login parameter handling in NetIQ Access Manager before 4.3.3 could be used to inject javascript code into the login page.

    Published: 1 Mar 2018
    5.4
    Medium

    CVE-2017-14800

    Last Modified: 21 Nov 2024

    A reflected cross site scripting attack in the NetIQ Access Manager before 4.3.3 using the "typecontainerid" parameter of the policy editor could allowed code injection into pages of authenticated users.

    Published: 1 Mar 2018
    5
    Medium

    CVE-2017-5188

    Last Modified: 21 Nov 2024

    The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source directory during build, allowing leakage of private information.

    Published: 1 Mar 2018
    5.4
    Medium

    CVE-2017-7426

    Last Modified: 21 Nov 2024

    The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to leak information or cause denial of service attacks.

    Published: 1 Mar 2018
    8.1
    High

    CVE-2017-7435

    Last Modified: 21 Nov 2024

    In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.

    Published: 1 Mar 2018
    8.1
    High

    CVE-2017-7436

    Last Modified: 21 Nov 2024

    In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.

    Published: 1 Mar 2018
    3.3
    Low

    CVE-2017-9271

    Last Modified: 21 Nov 2024

    The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.

    Published: 1 Mar 2018
    7.8
    High

    CVE-2017-9274

    Last Modified: 21 Nov 2024

    A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs.

    Published: 1 Mar 2018
    8.7
    High

    CVE-2017-9270

    Last Modified: 21 Nov 2024

    In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryptctl key database.

    Published: 1 Mar 2018
    7.8
    High

    CVE-2017-9286

    Last Modified: 21 Nov 2024

    The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts running as wwwrun user to escalate privileges to root during nextcloud package upgrade.

    Published: 1 Mar 2018
    7.7
    High

    CVE-2017-9269

    Last Modified: 21 Nov 2024

    In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.

    Published: 1 Mar 2018
    7.2
    High

    CVE-2018-7579

    Last Modified: 21 Nov 2024

    \application\admin\controller\update_urls.class.php in YzmCMS 3.6 has SQL Injection via the catids array parameter to admin/update_urls/update_category_url.html.

    Published: 1 Mar 2018
    6.6
    Medium

    CVE-2018-2380

    Last Modified: 31 Oct 2025

    SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.

    Published: 1 Mar 2018
    6.1
    Medium

    CVE-2018-2365

    Last Modified: 21 Nov 2024

    SAP NetWeaver Portal, WebDynpro Java, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

    Published: 1 Mar 2018
    8.8
    High

    CVE-2018-2367

    Last Modified: 21 Nov 2024

    ABAP File Interface in, SAP BASIS, from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.

    Published: 1 Mar 2018
    9.8
    Critical

    CVE-2018-2368

    Last Modified: 21 Nov 2024

    SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity.

    Published: 1 Mar 2018
    7.5
    High

    CVE-2018-5314

    Last Modified: 21 Nov 2024

    Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote attackers to execute a system command or read arbitrary files via an SSH login prompt.

    Published: 1 Mar 2018
    9.8
    Critical

    CVE-2018-7573

    Last Modified: 21 Nov 2024

    An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with the FTP 220 response code to crash the application; after this overflow, one can run arbitrary code on the victim machine. This is similar to CVE-2009-3364 and CVE-2017-6465.

    Published: 1 Mar 2018