CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2014-10070

    Last Modified: 21 Nov 2024

    zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical conditions where zsh is being invoked in privilege-elevation contexts when the environment has not been properly sanitized, such as when zsh is invoked by sudo on systems where "env_reset" has been disabled.

    Published: 26 Feb 2018
    5.3
    Medium

    CVE-2018-1000111

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins Subversion Plugin version 2.10.2 and earlier in SubversionStatus.java and SubversionRepositoryStatus.java that allows an attacker with network access to obtain a list of nodes and users.

    Published: 26 Feb 2018
    6.4
    Medium

    CVE-2022-20567

    Last Modified: 21 Apr 2025

    In pppol2tp_create of l2tp_ppp.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-186777253References: Upstream kernel

    Published: 26 Feb 2018
    5.3
    Medium

    CVE-2018-1000110

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins Git Plugin version 3.7.0 and earlier in GitStatus.java that allows an attacker with network access to obtain a list of nodes and users.

    Published: 26 Feb 2018
    5.3
    Medium

    CVE-2018-1000112

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and earlier in MercurialStatus.java that allows an attacker with network access to obtain a list of nodes and users.

    Published: 26 Feb 2018
    9.8
    Critical

    CVE-2018-7489

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath.

    Published: 26 Feb 2018
    5.5
    Medium

    CVE-2018-7568

    Last Modified: 21 Nov 2024

    The parse_die function in dwarf1.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (integer overflow and application crash) via an ELF file with corrupt dwarf1 debug information, as demonstrated by nm.

    Published: 26 Feb 2018
    6.1
    Medium

    CVE-2018-7476

    Last Modified: 21 Nov 2024

    controllers/admin/Linkage.php in dayrui FineCms 5.3.0 has Cross Site Scripting (XSS) via the id or lid parameter in a c=linkage,m=import request to admin.php, because the xss_clean protection mechanism is defeated by crafted input that lacks a '<' or '>' character.

    Published: 25 Feb 2018
    7.5
    High

    CVE-2018-7466

    Last Modified: 21 Nov 2024

    install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES data during installation to provide a long, crafted value.

    Published: 25 Feb 2018
    7.8
    High

    CVE-2018-7471

    Last Modified: 21 Nov 2024

    KingView 7.5SP1 has an integer overflow during stgopenstorage API read operations.

    Published: 25 Feb 2018
    5.5
    Medium

    CVE-2018-7472

    Last Modified: 21 Nov 2024

    INVT Studio 1.2 allows remote attackers to cause a denial of service during import operations.

    Published: 25 Feb 2018
    7.8
    High

    CVE-2018-7480

    Last Modified: 21 Nov 2024

    The blkcg_init_queue function in block/blk-cgroup.c in the Linux kernel before 4.11 allows local users to cause a denial of service (double free) or possibly have unspecified other impact by triggering a creation failure.

    Published: 25 Feb 2018
    4.9
    Medium

    CVE-2018-6883

    Last Modified: 21 Nov 2024

    Piwigo before 2.9.3 has SQL injection in admin/tags.php in the administration panel, via the tags array parameter in an admin.php?page=tags request. The attacker must be an administrator.

    Published: 24 Feb 2018
    5.5
    Medium

    CVE-2018-7452

    Last Modified: 21 Nov 2024

    A NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.

    Published: 24 Feb 2018
    5.5
    Medium

    CVE-2018-7453

    Last Modified: 21 Nov 2024

    Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lack of loop checking, as demonstrated by pdftohtml.

    Published: 24 Feb 2018
    5.5
    Medium

    CVE-2018-7454

    Last Modified: 21 Nov 2024

    A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.

    Published: 24 Feb 2018
    5.5
    Medium

    CVE-2018-7455

    Last Modified: 21 Nov 2024

    An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.

    Published: 24 Feb 2018
    8.8
    High

    CVE-2017-18198

    Last Modified: 21 Nov 2024

    print_iso9660_recurse in iso-info.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted iso file.

    Published: 24 Feb 2018
    6.5
    Medium

    CVE-2017-18199

    Last Modified: 21 Nov 2024

    realloc_symlink in rock.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (NULL Pointer Dereference) via a crafted iso file.

    Published: 24 Feb 2018
    5.3
    Medium

    CVE-2018-7434

    Last Modified: 21 Nov 2024

    zzcms 8.2 allows remote attackers to discover the full path via a direct request to 3/qq_connect2.0/API/class/ErrorCase.class.php or 3/ucenter_api/code/friend.php.

    Published: 24 Feb 2018
    4.8
    Medium

    CVE-2018-7447

    Last Modified: 21 Nov 2024

    mojoPortal through 2.6.0.0 is prone to multiple persistent cross-site scripting vulnerabilities because it fails to sanitize user-supplied input. The 'Title' and 'Subtitle' fields of the 'Blog' page are vulnerable. NOTE: The software maintainer disputes this as a vulnerability because the fields claimed to be vulnerable to XSS are only available to administrators who are supposed to have access to add scripts

    Published: 24 Feb 2018
    6.5
    Medium

    CVE-2018-7456

    Last Modified: 21 Nov 2024

    A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 when using the tiffinfo tool to print crafted TIFF information, a different vulnerability than CVE-2017-18013. (This affects an earlier part of the TIFFPrintDirectory function that was not addressed by the CVE-2017-18013 patch.)

    Published: 24 Feb 2018
    5.5
    Medium

    CVE-2018-7642

    Last Modified: 21 Nov 2024

    The swap_std_reloc_in function in aoutx.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (aout_32_swap_std_reloc_out NULL pointer dereference and application crash) via a crafted ELF file, as demonstrated by objcopy.

    Published: 24 Feb 2018
    7.8
    High

    CVE-2017-15820

    Last Modified: 21 Nov 2024

    In all Qualcomm products with Android releases from CAF using the Linux kernel, in a KGSL IOCTL handler, a Use After Free Condition can potentially occur.

    Published: 23 Feb 2018
    7
    High

    CVE-2017-15829

    Last Modified: 21 Nov 2024

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a GPU Driver which can potentially lead to a Use After Free condition.

    Published: 23 Feb 2018
    7.8
    High

    CVE-2017-15518

    Last Modified: 21 Nov 2024

    All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged database user account password. All users are urged to move to a fixed version. Since the affected password is changed during every upgrade/installation no further action is required.

    Published: 23 Feb 2018
    7.8
    High

    CVE-2017-14884

    Last Modified: 21 Nov 2024

    In all Qualcomm products with Android releases from CAF using the Linux kernel, due to lack of bounds checking on the variable "data_len" from the function WLANQCMBR_McProcessMsg, a buffer overflow may potentially occur in WLANFTM_McProcessMsg.

    Published: 23 Feb 2018
    9.8
    Critical

    CVE-2017-14910

    Last Modified: 21 Nov 2024

    In Snapdragon Automobile, Snapdragon IoT and Snapdragon Mobile MDM9206 MDM9607, MDM9650, S820A, S820Am, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 820, SD 835, and SD 845, a buffer overread is possible if there are no newlines in an input file.

    Published: 23 Feb 2018
    7.8
    High

    CVE-2017-15817

    Last Modified: 21 Nov 2024

    In all Qualcomm products with Android releases from CAF using the Linux kernel, when an access point sends a challenge text greater than 128 bytes, the host driver is unable to validate this potentially leading to authentication failure.

    Published: 23 Feb 2018
    7.8
    High

    CVE-2017-15861

    Last Modified: 21 Nov 2024

    In all Qualcomm products with Android releases from CAF using the Linux kernel, in the function wma_roam_synch_event_handler, vdev_id is received from firmware and used to access an array without validation.

    Published: 23 Feb 2018
    7.8
    High

    CVE-2017-17767

    Last Modified: 21 Nov 2024

    In all Qualcomm products with Android releases from CAF using the Linux kernel, the IL client may free a buffer OMX Video Encoder Component and then subsequently access the already freed buffer.

    Published: 23 Feb 2018
    7.8
    High

    CVE-2017-15860

    Last Modified: 21 Nov 2024

    In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing an encrypted authentication management frame, a stack buffer overflow may potentially occur.

    Published: 23 Feb 2018
    7.8
    High

    CVE-2017-15862

    Last Modified: 21 Nov 2024

    In all Qualcomm products with Android releases from CAF using the Linux kernel, in wma_unified_link_radio_stats_event_handler(), the number of radio channels coming from firmware is not properly validated, potentially leading to an integer overflow vulnerability followed by a buffer overflow.

    Published: 23 Feb 2018
    7.8
    High

    CVE-2017-17764

    Last Modified: 21 Nov 2024

    In all Qualcomm products with Android releases from CAF using the Linux kernel, the num_failure_info value from firmware is not properly validated in wma_rx_aggr_failure_event_handler() so that an integer overflow vulnerability in a buffer size calculation may potentially lead to a buffer overflow.

    Published: 23 Feb 2018
    7.8
    High

    CVE-2017-17765

    Last Modified: 21 Nov 2024

    In all Qualcomm products with Android releases from CAF using the Linux kernel, multiple values received from firmware are not properly validated in wma_get_ll_stats_ext_buf() and are used to allocate the sizes of buffers and may be vulnerable to integer overflow leading to buffer overflow.

    Published: 23 Feb 2018
    7.5
    High

    CVE-2018-7321

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thrift.c had a large loop that was addressed by not proceeding with dissection after encountering an unexpected type.

    Published: 23 Feb 2018
    7.5
    High

    CVE-2018-7322

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-dcm.c had an infinite loop that was addressed by checking for integer wraparound.

    Published: 23 Feb 2018
    7.5
    High

    CVE-2018-7323

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-wccp.c had a large loop that was addressed by ensuring that a calculated length was monotonically increasing.

    Published: 23 Feb 2018
    7.5
    High

    CVE-2018-7324

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-sccp.c had an infinite loop that was addressed by using a correct integer data type.

    Published: 23 Feb 2018
    7.5
    High

    CVE-2018-7325

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-rpki-rtr.c had an infinite loop that was addressed by validating a length field.

    Published: 23 Feb 2018
    7.5
    High

    CVE-2018-7328

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-usb.c had an infinite loop that was addressed by rejecting short frame header lengths.

    Published: 23 Feb 2018
    7.5
    High

    CVE-2018-7329

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-s7comm.c had an infinite loop that was addressed by correcting off-by-one errors.

    Published: 23 Feb 2018
    7.5
    High

    CVE-2018-7330

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thread.c had an infinite loop that was addressed by using a correct integer data type.

    Published: 23 Feb 2018
    7.5
    High

    CVE-2018-7331

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-ber.c had an infinite loop that was addressed by validating a length.

    Published: 23 Feb 2018
    7.5
    High

    CVE-2018-7332

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-reload.c had an infinite loop that was addressed by validating a length.

    Published: 23 Feb 2018
    7.5
    High

    CVE-2018-7333

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-rpcrdma.c had an infinite loop that was addressed by validating a chunk size.

    Published: 23 Feb 2018
    7.5
    High

    CVE-2018-7421

    Last Modified: 21 Nov 2024

    In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the DMP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-dmp.c by correctly supporting a bounded number of Security Categories for a DMP Security Classification.

    Published: 23 Feb 2018
    5.3
    Medium

    CVE-2017-16769

    Last Modified: 21 Nov 2024

    Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer mode.

    Published: 23 Feb 2018
    7.5
    High

    CVE-2018-7326

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-lltd.c had an infinite loop that was addressed by using a correct integer data type.

    Published: 23 Feb 2018
    7.5
    High

    CVE-2018-7327

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-openflow_v6.c had an infinite loop that was addressed by validating property lengths.

    Published: 23 Feb 2018