CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2017-6150

    Last Modified: 21 Nov 2024

    Under certain conditions for F5 BIG-IP systems 13.0.0 or 12.1.0 - 12.1.3.1, using FastL4 profiles, when the Reassemble IP Fragments option is disabled (default), some specific large fragmented packets may restart the Traffic Management Microkernel (TMM).

    Published: 1 Mar 2018
    7.5
    High

    CVE-2017-6154

    Last Modified: 21 Nov 2024

    On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, the BIG-IP ASM bd daemon may core dump memory under some circumstances when processing undisclosed types of data on systems with 48 or more CPU cores.

    Published: 1 Mar 2018
    5.9
    Medium

    CVE-2018-5501

    Last Modified: 21 Nov 2024

    In some circumstances, on F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, any 11.6.x or 11.5.x release, or 11.2.1, TCP DNS profile allows excessive buffering due to lack of flow control.

    Published: 1 Mar 2018
    5.9
    Medium

    CVE-2018-5500

    Last Modified: 21 Nov 2024

    On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, every Multipath TCP (MCTCP) connection established leaks a small amount of memory. Virtual server using TCP profile with Multipath TCP (MCTCP) feature enabled will be affected by this issue.

    Published: 1 Mar 2018
    9.8
    Critical

    CVE-2018-7561

    Last Modified: 21 Nov 2024

    Stack-based Buffer Overflow in httpd on Tenda AC9 devices V15.03.05.14_EN allows remote attackers to cause a denial of service or possibly have unspecified other impact.

    Published: 1 Mar 2018
    6.5
    Medium

    CVE-2017-18207

    Last Modified: 21 Nov 2024

    The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and exception) via a crafted wav format audio file. NOTE: the vendor disputes this issue because Python applications "need to be prepared to handle a wide variety of exceptions.

    Published: 1 Mar 2018
    5.3
    Medium

    CVE-2018-6653

    Last Modified: 21 Nov 2024

    comforte SWAP 1049 through 1069 and 20.0.0 through 21.5.3 (as used in SSLOBJ on HPE NonStop SSL T0910, and in the comforte SecurCS, SecurFTP, SecurLib/SSL-AT, and SecurTN products), after executing the RELOAD CERTIFICATES command, does not ensure that clients use a strong TLS cipher suite, which makes it easier for remote attackers to defeat intended cryptographic protection mechanisms by sniffing the network. This is fixed in 21.6.0.

    Published: 1 Mar 2018
    8.8
    High

    CVE-2018-1058

    Last Modified: 21 Nov 2024

    A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.

    Published: 1 Mar 2018
    7.8
    High

    CVE-2018-7643

    Last Modified: 21 Nov 2024

    The display_debug_ranges function in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact via a crafted ELF file, as demonstrated by objdump.

    Published: 1 Mar 2018
    9.8
    Critical

    CVE-2017-12627

    Last Modified: 21 Nov 2024

    In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.

    Published: 1 Mar 2018
    4.7
    Medium

    CVE-2018-5729

    Last Modified: 5 May 2025

    MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to cause a denial of service (NULL pointer dereference) or bypass a DN container check by supplying tagged data that is internal to the database module.

    Published: 1 Mar 2018
    3.8
    Low

    CVE-2018-5730

    Last Modified: 5 May 2025

    MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.

    Published: 1 Mar 2018
    8.8
    High

    CVE-2015-4117

    Last Modified: 21 Nov 2024

    Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.

    Published: 28 Feb 2018
    7.5
    High

    CVE-2015-5079

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the dl parameter.

    Published: 28 Feb 2018
    7.8
    High

    CVE-2018-6947

    Last Modified: 21 Nov 2024

    An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2 and earlier allows a local low privileged user to gain elevation of privileges on Windows 7 (32 and 64bit), and denial of service for Windows 8 and 10.

    Published: 28 Feb 2018
    6.1
    Medium

    CVE-2015-3898

    Last Modified: 21 Nov 2024

    Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the redirectUrl parameter to (1) bonita/login.jsp or (2) bonita/loginservice.

    Published: 28 Feb 2018
    6.5
    Medium

    CVE-2018-1286

    Last Modified: 21 Nov 2024

    In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users.

    Published: 28 Feb 2018
    8.8
    High

    CVE-2016-0291

    Last Modified: 21 Nov 2024

    IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access. IBM X-Force ID: 111302.

    Published: 28 Feb 2018
    8.8
    High

    CVE-2016-0295

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111363.

    Published: 28 Feb 2018
    5.3
    Medium

    CVE-2016-0299

    Last Modified: 21 Nov 2024

    IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to obtain sensitive information via vectors involving a database query. IBM X-Force ID: 111382.

    Published: 28 Feb 2018
    9.8
    Critical

    CVE-2018-7264

    Last Modified: 21 Nov 2024

    The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF Toolkit to process untrusted images.

    Published: 28 Feb 2018
    4.8
    Medium

    CVE-2018-7469

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Entrepreneur Job Portal Script 2.0.9 has XSS via the p_name (aka Edit Category Name) field to admin/categories_industry.php (aka Categories - Industry Type).

    Published: 28 Feb 2018
    7.5
    High

    CVE-2017-9447

    Last Modified: 21 Nov 2024

    In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due to improper validation of the file path when requesting a resource under the "RASHTML5Gateway" directory. A remote, unauthenticated attacker could exploit this weakness to read arbitrary files from the vulnerable system using path traversal sequences.

    Published: 28 Feb 2018
    9.8
    Critical

    CVE-2018-7477

    Last Modified: 21 Nov 2024

    SQL Injection exists in PHP Scripts Mall School Management Script 3.0.4 via the Username and Password fields to parents/Parent_module/parent_login.php.

    Published: 28 Feb 2018
    9.1
    Critical

    CVE-2018-7556

    Last Modified: 21 Nov 2024

    LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerController.php after installation, which allows remote attackers to access the configuration file.

    Published: 28 Feb 2018
    6.5
    Medium

    CVE-2018-7557

    Last Modified: 21 Nov 2024

    The decode_init function in libavcodec/utvideodec.c in FFmpeg 2.8 through 3.4.2 allows remote attackers to cause a denial of service (Out of array read) via an AVI file with crafted dimensions within chroma subsampling data.

    Published: 28 Feb 2018
    7.5
    High

    CVE-2018-7482

    Last Modified: 21 Nov 2024

    The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demonstrated by a view=media&task=connector&cmd=file&target=l1_../configuration.php&download=1 request. The specific pathname ../configuration.php should be base64 encoded for a valid attack. NOTE: the vendor disputes this issue because only files under the media-manager path can be downloaded, and the documentation indicates that sensitive information does not belong there. Nonetheless, 2.8.1 has additional blocking of .php downloads

    Published: 28 Feb 2018
    9.8
    Critical

    CVE-2018-7551

    Last Modified: 21 Nov 2024

    There is an invalid free in MiniPS::delete0 in minips.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

    Published: 28 Feb 2018
    9.8
    Critical

    CVE-2018-7552

    Last Modified: 21 Nov 2024

    There is an invalid free in Mapping::DoubleHash::clear in mapping.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

    Published: 28 Feb 2018
    9.8
    Critical

    CVE-2018-7554

    Last Modified: 21 Nov 2024

    There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

    Published: 28 Feb 2018
    9.8
    Critical

    CVE-2018-7553

    Last Modified: 21 Nov 2024

    There is a heap-based buffer overflow in the pcxLoadRaster function of in_pcx.cpp in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

    Published: 28 Feb 2018
    9.8
    Critical

    CVE-2018-6638

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. This occurs in a function call in which the first argument is a corrupted offset value and the second argument is a stack buffer. This is fixed in 6.9d.

    Published: 28 Feb 2018
    9.8
    Critical

    CVE-2018-6639

    Last Modified: 21 Nov 2024

    An out-of-bounds write (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. A size used by memmove is read from the input file. This is fixed in 6.9d.

    Published: 28 Feb 2018
    9.8
    Critical

    CVE-2018-6640

    Last Modified: 21 Nov 2024

    A Heap Overflow (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can modify the next pointer of a linked list. This is fixed in 6.9d.

    Published: 28 Feb 2018
    9.8
    Critical

    CVE-2018-6641

    Last Modified: 21 Nov 2024

    An Arbitrary Free (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can overwrite a structure, leading to a function call with an invalid parameter, and a subsequent free of important data such as a function pointer or list pointer. This is fixed in 6.9d.

    Published: 28 Feb 2018
    7.5
    High

    CVE-2018-5732

    Last Modified: 21 Nov 2024

    Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause a buffer overflow (and resulting crash) in dhclient by sending a response containing a specially constructed options section. Affects ISC DHCP versions 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0

    Published: 28 Feb 2018
    5.9
    Medium

    CVE-2017-14461

    Last Modified: 21 Nov 2024

    A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive information disclosure and denial of service. In order to trigger this vulnerability, an attacker needs to send a specially crafted email message to the server.

    Published: 28 Feb 2018
    5.9
    Medium

    CVE-2017-15130

    Last Modified: 21 Nov 2024

    A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart.

    Published: 28 Feb 2018
    4.4
    Medium

    CVE-2018-1063

    Last Modified: 21 Nov 2024

    Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity to change the SELinux context of an arbitrary file to a context with few restrictions. This only happens when the relabeling process is done, usually when taking SELinux state from disabled to enable (permissive or enforcing). The issue was found in policycoreutils 2.5-11.

    Published: 28 Feb 2018
    7.5
    High

    CVE-2018-5733

    Last Modified: 25 Apr 2025

    A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash. Affects ISC DHCP 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0.

    Published: 28 Feb 2018
    7.5
    High

    CVE-2018-5734

    Last Modified: 21 Nov 2024

    While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode. If the receiving view has the SERVFAIL cache feature enabled, this can trigger an assertion failure in badcache.c when the request doesn't contain all of the expected information. Affects BIND 9.10.5-S1 to 9.10.5-S4, 9.10.6-S1, 9.10.6-S2.

    Published: 28 Feb 2018
    7.5
    High

    CVE-2018-7467

    Last Modified: 21 Nov 2024

    AxxonSoft Axxon Next has Directory Traversal via an initial /css//..%2f substring in a URI.

    Published: 27 Feb 2018
    4.8
    Medium

    CVE-2018-7547

    Last Modified: 21 Nov 2024

    lyadmin 1.x has XSS via the config[WEB_SITE_TITLE] parameter to the /admin.php?s=/admin/config/groupsave.html URI.

    Published: 27 Feb 2018
    7.5
    High

    CVE-2017-7671

    Last Modified: 21 Nov 2024

    There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can cause the server to coredump.

    Published: 27 Feb 2018
    8.6
    High

    CVE-2017-5660

    Last Modified: 21 Nov 2024

    There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issues when interacting with upstream proxies and the wrong host being used.

    Published: 27 Feb 2018
    9.8
    Critical

    CVE-2018-6481

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to TCP port 9124.

    Published: 27 Feb 2018
    7.5
    High

    CVE-2018-6532

    Last Modified: 21 Nov 2024

    An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted (authenticated and unauthenticated) requests, an attacker can exhaust a lot of memory on the server side, triggering the OOM killer.

    Published: 27 Feb 2018
    7.8
    High

    CVE-2018-6533

    Last Modified: 21 Nov 2024

    An issue was discovered in Icinga 2.x through 2.8.1. By editing the init.conf file, Icinga 2 can be run as root. Following this the program can be used to run arbitrary code as root. This was fixed by no longer using init.conf to determine account information for any root-executed code (a larger issue than CVE-2017-16933).

    Published: 27 Feb 2018
    6.5
    Medium

    CVE-2018-6534

    Last Modified: 21 Nov 2024

    An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted messages, an attacker can cause a NULL pointer dereference, which can cause the product to crash.

    Published: 27 Feb 2018
    8.1
    High

    CVE-2018-6535

    Last Modified: 21 Nov 2024

    An issue was discovered in Icinga 2.x through 2.8.1. The lack of a constant-time password comparison function can disclose the password to an attacker.

    Published: 27 Feb 2018