CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2018-4901

    Last Modified: 21 Nov 2024

    An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the document identity representation. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.

    Published: 27 Feb 2018
    6.5
    Medium

    CVE-2018-4903

    Last Modified: 21 Nov 2024

    An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the TIFF processing within the XPS module. A successful attack can lead to sensitive data exposure.

    Published: 27 Feb 2018
    8.8
    High

    CVE-2018-4904

    Last Modified: 21 Nov 2024

    An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability is an instance of a heap overflow vulnerability. The vulnerability is triggered by crafted TIFF data within an XPS file, which causes an out of bounds memory access. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.

    Published: 27 Feb 2018
    6.5
    Medium

    CVE-2018-4909

    Last Modified: 21 Nov 2024

    An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module when processing metadata in JPEG images. A successful attack can lead to sensitive data exposure.

    Published: 27 Feb 2018
    8.8
    High

    CVE-2018-4915

    Last Modified: 21 Nov 2024

    An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the JavaScript API related to color conversion. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.

    Published: 27 Feb 2018
    7.5
    High

    CVE-2018-13863

    Last Modified: 21 Nov 2024

    The MongoDB bson JavaScript module (also known as js-bson) versions 0.5.0 to 1.0.x before 1.0.5 is vulnerable to a Regular Expression Denial of Service (ReDoS) in lib/bson/decimal128.js. The flaw is triggered when the Decimal128.fromString() function is called to parse a long untrusted string.

    Published: 27 Feb 2018
    7.5
    High

    CVE-2018-7182

    Last Modified: 21 Nov 2024

    The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd instance from 4.2.8p6 through 4.2.8p10.

    Published: 27 Feb 2018
    9.8
    Critical

    CVE-2018-7183

    Last Modified: 21 Nov 2024

    Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array.

    Published: 27 Feb 2018
    7.5
    High

    CVE-2018-7185

    Last Modified: 14 Jan 2025

    The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association.

    Published: 27 Feb 2018
    6.5
    Medium

    CVE-2018-7540

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (host OS CPU hang) via non-preemptable L3/L4 pagetable freeing.

    Published: 27 Feb 2018
    6.5
    Medium

    CVE-2018-7542

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen 4.8.x through 4.10.x allowing x86 PVH guest OS users to cause a denial of service (NULL pointer dereference and hypervisor crash) by leveraging the mishandling of configurations that lack a Local APIC.

    Published: 27 Feb 2018
    7.4
    High

    CVE-2017-12191

    Last Modified: 21 Nov 2024

    A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (VMWare Remote Console) functions that may not be appropriate for users of CloudForms (and thus this account). An attacker could use this vulnerability to view and make changes to settings in the VMRC and virtual machines controlled by it that they should not have access to.

    Published: 27 Feb 2018
    5.3
    Medium

    CVE-2018-7170

    Last Modified: 14 Jan 2025

    ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.

    Published: 27 Feb 2018
    2.7
    Low

    CVE-2017-15136

    Last Modified: 21 Nov 2024

    When registering and activating a new system with Red Hat Satellite 6 if the new systems hostname is then reset to the hostname of a previously registered system the previously registered system will lose access to updates including security updates.

    Published: 27 Feb 2018
    7
    High

    CVE-2017-18202

    Last Modified: 21 Nov 2024

    The __oom_reap_task_mm function in mm/oom_kill.c in the Linux kernel before 4.14.4 mishandles gather operations, which allows attackers to cause a denial of service (TLB entry leak or use-after-free) or possibly have unspecified other impact by triggering a copy_to_user call within a certain time window.

    Published: 27 Feb 2018
    6.5
    Medium

    CVE-2018-0489

    Last Modified: 21 Nov 2024

    Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via crafted XML data. NOTE: this issue exists because of an incomplete fix for CVE-2018-0486.

    Published: 27 Feb 2018
    3.7
    Low

    CVE-2018-1315

    Last Modified: 21 Nov 2024

    In Apache Hive 2.1.0 to 2.3.2, when 'COPY FROM FTP' statement is run using HPL/SQL extension to Hive, a compromised/malicious FTP server can cause the file to be written to an arbitrary location on the cluster where the command is run from. This is because FTP client code in HPL/SQL does not verify the destination location of the downloaded file. This does not affect hive cli user and hiveserver2 user as hplsql is a separate command line script and needs to be invoked differently.

    Published: 27 Feb 2018
    7.5
    High

    CVE-2018-7184

    Last Modified: 14 Jan 2025

    ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix for CVE-2015-7704.

    Published: 27 Feb 2018
    8.8
    High

    CVE-2018-7541

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.10.x allowing guest OS users to cause a denial of service (hypervisor crash) or gain privileges by triggering a grant-table transition from v2 to v1.

    Published: 27 Feb 2018
    8.8
    High

    CVE-2018-7550

    Last Modified: 21 Nov 2024

    The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which triggers an out-of-bounds read or write memory access.

    Published: 27 Feb 2018
    7.5
    High

    CVE-2018-7490

    Last Modified: 21 Nov 2024

    uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.

    Published: 26 Feb 2018
    5.5
    Medium

    CVE-2017-16814

    Last Modified: 21 Nov 2024

    A Directory Traversal issue was discovered in the Foxit MobilePDF app before 6.1 for iOS. This occurs by abusing the URL + escape character during a Wi-Fi transfer, which could be exploited by attackers to bypass intended restrictions on local application files.

    Published: 26 Feb 2018
    6.1
    Medium

    CVE-2018-0908

    Last Modified: 21 Nov 2024

    Microsoft Identity Manager 2016 SP1 allows an attacker to gain elevated privileges when it does not properly sanitize a specially crafted attribute value being displayed to a user on an affected MIM 2016 server, aka "Microsoft Identity Manager XSS Elevation of Privilege Vulnerability."

    Published: 26 Feb 2018
    9.8
    Critical

    CVE-2017-11632

    Last Modified: 21 Nov 2024

    An issue was discovered on Wireless IP Camera 360 devices. A root account with a known SHA-512 password hash exists, which makes it easier for remote attackers to obtain administrative access via a TELNET session.

    Published: 26 Feb 2018
    7.5
    High

    CVE-2017-11633

    Last Modified: 21 Nov 2024

    An issue was discovered on Wireless IP Camera 360 devices. Remote attackers can discover RTSP credentials by connecting to TCP port 9527 and reading the InsertConnect field.

    Published: 26 Feb 2018
    9.8
    Critical

    CVE-2017-11634

    Last Modified: 21 Nov 2024

    An issue was discovered on Wireless IP Camera 360 devices. Remote attackers can discover a weakly encoded admin password by connecting to TCP port 9527 and reading the password field of the debugging information, e.g., nTBCS19C corresponds to a password of 123456.

    Published: 26 Feb 2018
    7.5
    High

    CVE-2017-11635

    Last Modified: 21 Nov 2024

    An issue was discovered on Wireless IP Camera 360 devices. Attackers can read recordings by navigating to /mnt/idea0 or /mnt/idea1 on the SD memory card.

    Published: 26 Feb 2018
    5.5
    Medium

    CVE-2017-16229

    Last Modified: 21 Nov 2024

    In the Ox gem 2.8.1 for Ruby, the process crashes with a stack-based buffer over-read in the read_from_str function in sax_buf.c when a crafted input is supplied to sax_parse.

    Published: 26 Feb 2018
    5.5
    Medium

    CVE-2017-16813

    Last Modified: 21 Nov 2024

    A denial-of-service issue was discovered in the Foxit MobilePDF app before 6.1 for iOS. This occurs when a user uploads a file that includes a hexadecimal Unicode character in the "filename" parameter via Wi-Fi, since the app could fail to parse this.

    Published: 26 Feb 2018
    7
    High

    CVE-2018-7249

    Last Modified: 21 Nov 2024

    An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. Two carefully timed calls to IOCTL 0xCA002813 can cause a race condition that leads to a use-after-free. When exploited, an unprivileged attacker can run arbitrary code in the kernel.

    Published: 26 Feb 2018
    5.5
    Medium

    CVE-2018-7250

    Last Modified: 21 Nov 2024

    An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. An uninitialized kernel pool allocation in IOCTL 0xCA002813 allows a local unprivileged attacker to leak 16 bits of uninitialized kernel PagedPool data.

    Published: 26 Feb 2018
    7.5
    High

    CVE-2018-7448

    Last Modified: 21 Nov 2024

    Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.

    Published: 26 Feb 2018
    5.3
    Medium

    CVE-2017-18195

    Last Modified: 21 Nov 2024

    An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog posts by POSTing requests to /index.php/tools/required/conversations/view_ajax with incremental 'cnvID' integers.

    Published: 26 Feb 2018
    7.5
    High

    CVE-2018-7491

    Last Modified: 21 Nov 2024

    In PrestaShop through 1.7.2.5, a UI-Redressing/Clickjacking vulnerability was found that might lead to state-changing impact in the context of a user or an admin, because the generateHtaccess function in classes/Tools.php sets neither X-Frame-Options nor 'Content-Security-Policy "frame-ancestors' values.

    Published: 26 Feb 2018
    5.9
    Medium

    CVE-2018-5762

    Last Modified: 21 Nov 2024

    The TLS implementation in the TCP/IP networking module in Unisys ClearPath MCP systems with TCP-IP-SW 58.1 before 58.160, 59.1 before 059.1a.17 (IC #17), and 60.0 before 60.044 might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.

    Published: 26 Feb 2018
    7.8
    High

    CVE-2018-7487

    Last Modified: 21 Nov 2024

    There is a heap-based buffer overflow in the LoadPCX function of in_pcx.cpp in sam2p 0.49.4. A Crafted input will lead to a denial of service or possibly unspecified other impact.

    Published: 26 Feb 2018
    7.8
    High

    CVE-2018-1377

    Last Modified: 21 Nov 2024

    IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 137778.

    Published: 26 Feb 2018
    7.2
    High

    CVE-2018-7486

    Last Modified: 21 Nov 2024

    Blue River Mura CMS before v7.0.7029 supports inline function calls with an [m] tag and [/m] end tag, without proper restrictions on file types or pathnames, which allows remote attackers to execute arbitrary code via an [m]$.dspinclude("../pathname/executable.jpeg")[/m] approach, where executable.jpeg contains ColdFusion Markup Language code. This can be exploited in conjunction with a CKFinder feature that allows file upload.

    Published: 26 Feb 2018
    5.3
    Medium

    CVE-2017-1774

    Last Modified: 21 Nov 2024

    IBM Security Guardium Big Data Intelligence (SonarG) 3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 136818.

    Published: 26 Feb 2018
    9.8
    Critical

    CVE-2017-18201

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.

    Published: 26 Feb 2018
    9.8
    Critical

    CVE-2018-7485

    Last Modified: 21 Nov 2024

    The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to cause a denial of service or possibly have unspecified other impact.

    Published: 26 Feb 2018
    9.8
    Critical

    CVE-2018-7463

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in files.php in the "files" component in ASANHAMAYESH CMS 3.4.6 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter.

    Published: 26 Feb 2018
    9.8
    Critical

    CVE-2017-9426

    Last Modified: 21 Nov 2024

    ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action.

    Published: 26 Feb 2018
    6.1
    Medium

    CVE-2017-9425

    Last Modified: 21 Nov 2024

    The Facetag extension 0.0.3 for Piwigo allows XSS via the name parameter to ws.php in a facetag.changeTag action.

    Published: 26 Feb 2018
    5.3
    Medium

    CVE-2018-7479

    Last Modified: 21 Nov 2024

    YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.php.

    Published: 26 Feb 2018
    7.5
    High

    CVE-2017-15696

    Last Modified: 21 Nov 2024

    When an Apache Geode cluster before v1.4.0 is operating in secure mode, the Geode configuration service does not properly authorize configuration requests. This allows an unprivileged user who gains access to the Geode locator to extract configuration data and previously deployed application code.

    Published: 26 Feb 2018
    7.8
    High

    CVE-2018-7484

    Last Modified: 21 Nov 2024

    An issue was discovered in PureVPN through 5.19.4.0 on Windows. The client installation grants the Everyone group Full Control permission to the installation directory. In addition, the PureVPNService.exe service, which runs under NT Authority\SYSTEM privileges, tries to load several dynamic-link libraries using relative paths instead of the absolute path. When not using a fully qualified path, the application will first try to load the library from the directory from which the application is started. As the residing directory of PureVPNService.exe is writable to all users, this makes the application susceptible to privilege escalation through DLL hijacking.

    Published: 26 Feb 2018
    4.3
    Medium

    CVE-2018-1000114

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.

    Published: 26 Feb 2018
    5.5
    Medium

    CVE-2018-7569

    Last Modified: 21 Nov 2024

    dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (integer underflow or overflow, and application crash) via an ELF file with a corrupt DWARF FORM block, as demonstrated by nm.

    Published: 26 Feb 2018
    5.5
    Medium

    CVE-2018-7570

    Last Modified: 21 Nov 2024

    The assign_file_positions_for_non_load_sections function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an ELF file with a RELRO segment that lacks a matching LOAD segment, as demonstrated by objcopy.

    Published: 26 Feb 2018