CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2018-0148

    Last Modified: 2 Dec 2024

    A vulnerability in the web-based management interface of Cisco UCS Director Software and Cisco Integrated Management Controller (IMC) Supervisor Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protection by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the affected interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions, via the user's web browser and with the user's privileges, on an affected system. Cisco Bug IDs: CSCvf71929.

    Published: 22 Feb 2018
    5.4
    Medium

    CVE-2018-0201

    Last Modified: 2 Dec 2024

    A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to improper neutralization of input during web page generation. An attacker could exploit this vulnerability by embedding media in instant messages. An exploit could allow the attacker to cause the recipient chat client to make outbound requests. Cisco Bug IDs: CSCve54001.

    Published: 22 Feb 2018
    6.1
    Medium

    CVE-2018-0205

    Last Modified: 2 Dec 2024

    A vulnerability in the User Provisioning tab in the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. The vulnerability is due to improper input validation. An attacker could exploit this vulnerability by placing a malicious string in the Prime Collaboration Provisioning database. A successful exploit could allow the attacker to access Cisco Prime Collaboration Provisioning by injecting crafted data into the database. Cisco Bug IDs: CSCvd86609.

    Published: 22 Feb 2018
    5.9
    Medium

    CVE-2018-7287

    Last Modified: 21 Nov 2024

    An issue was discovered in res_http_websocket.c in Asterisk 15.x through 15.2.1. If the HTTP server is enabled (default is disabled), WebSocket payloads of size 0 are mishandled (with a busy loop).

    Published: 22 Feb 2018
    8.8
    High

    CVE-2018-7436

    Last Modified: 21 Nov 2024

    An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the parse_SST function.

    Published: 22 Feb 2018
    8.8
    High

    CVE-2018-7438

    Last Modified: 21 Nov 2024

    An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the parse_unicode_string function.

    Published: 22 Feb 2018
    5.5
    Medium

    CVE-2018-7728

    Last Modified: 21 Nov 2024

    An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp mishandles a case of a zero length, leading to a heap-based buffer over-read in the MD5Update() function in third-party/zuid/interfaces/MD5.cpp.

    Published: 22 Feb 2018
    5.5
    Medium

    CVE-2018-7731

    Last Modified: 21 Nov 2024

    An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FormatSupport/WEBP_Support.cpp does not check whether a bitstream has a NULL value, leading to a NULL pointer dereference in the WEBP::VP8XChunk class.

    Published: 22 Feb 2018
    8.6
    High

    CVE-2018-0139

    Last Modified: 2 Dec 2024

    A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause the IVR connection to disconnect, creating a system-wide denial of service (DoS) condition. The vulnerability is due to improper handling of a TCP connection request when the IVR connection is already established. An attacker could exploit this vulnerability by initiating a crafted connection to the IP address of the targeted CVP device. An exploit could allow the attacker to disconnect the IVR to CVP connection, creating a DoS condition that prevents the CVP from accepting new, incoming calls while the IVR automatically attempts to re-establish the connection to the CVP. This vulnerability affects Cisco Unified Customer Voice Portal (CVP) Software Release 11.5(1). Cisco Bug IDs: CSCve70560.

    Published: 22 Feb 2018
    6.1
    Medium

    CVE-2018-0145

    Last Modified: 2 Dec 2024

    A vulnerability in the web-based management interface of the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information on the affected system. Cisco Bug IDs: CSCvg45105.

    Published: 22 Feb 2018
    6.1
    Medium

    CVE-2018-0199

    Last Modified: 2 Dec 2024

    A vulnerability in Cisco Jabber Client Framework (JCF) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to improper neutralization of script in attributes in a web page. An attacker could exploit this vulnerability by executing arbitrary JavaScript in the Jabber client of the recipient. An exploit could allow the attacker to perform remote code execution. Cisco Bug IDs: CSCve53989.

    Published: 22 Feb 2018
    5.3
    Medium

    CVE-2018-0203

    Last Modified: 2 Dec 2024

    A vulnerability in the SMTP relay of Cisco Unity Connection could allow an unauthenticated, remote attacker to send unsolicited email messages, aka a Mail Relay Vulnerability. The vulnerability is due to improper handling of domain information in the affected software. An unauthenticated, remote attacker could exploit this vulnerability by sending crafted requests to the targeted application. A successful exploit could allow the attacker to send email messages to arbitrary addresses. Cisco Bug IDs: CSCvg62215.

    Published: 22 Feb 2018
    6.1
    Medium

    CVE-2018-0206

    Last Modified: 2 Dec 2024

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the web-based management interface to click a link that submits malicious input to the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvg74815.

    Published: 22 Feb 2018
    5.5
    Medium

    CVE-2017-18193

    Last Modified: 21 Nov 2024

    fs/f2fs/extent_cache.c in the Linux kernel before 4.13 mishandles extent trees, which allows local users to cause a denial of service (BUG) via an application with multiple threads.

    Published: 22 Feb 2018
    6.5
    Medium

    CVE-2018-7286

    Last Modified: 21 Nov 2024

    An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation fault) by sending a number of SIP INVITE messages on a TCP or TLS connection and then suddenly closing the connection.

    Published: 22 Feb 2018
    5.5
    Medium

    CVE-2018-7729

    Last Modified: 21 Nov 2024

    An issue was discovered in Exempi through 2.4.4. There is a stack-based buffer over-read in the PostScript_MetaHandler::ParsePSFile() function in XMPFiles/source/FileHandlers/PostScript_Handler.cpp.

    Published: 22 Feb 2018
    9.8
    Critical

    CVE-2018-8088

    Last Modified: 21 Nov 2024

    org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.

    Published: 22 Feb 2018
    5.4
    Medium

    CVE-2018-0146

    Last Modified: 2 Dec 2024

    A vulnerability in the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to improper CSRF protection by the affected application. An attacker could exploit this vulnerability by persuading a user of the affected application to click a malicious link. A successful exploit could allow the attacker to submit arbitrary requests and take unauthorized actions on behalf of the user. Cisco Bug IDs: CSCvg45114.

    Published: 22 Feb 2018
    6.1
    Medium

    CVE-2018-0200

    Last Modified: 2 Dec 2024

    A vulnerability in the web-based interface of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based interface of an affected product. The vulnerability is due to insufficient validation of user-supplied input by the web-based interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvh65713.

    Published: 22 Feb 2018
    7.5
    High

    CVE-2018-0204

    Last Modified: 2 Dec 2024

    A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for individual users. The vulnerability is due to weak login controls. An attacker could exploit this vulnerability by using a brute-force attack (Repeated Bad Login Attempts). A successful exploit could allow the attacker to restrict user access. Manual administrative intervention is required to restore access. Cisco Bug IDs: CSCvd07264.

    Published: 22 Feb 2018
    7.5
    High

    CVE-2018-7284

    Last Modified: 21 Nov 2024

    A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. When processing a SUBSCRIBE request, the res_pjsip_pubsub module stores the accepted formats present in the Accept headers of the request. This code did not limit the number of headers it processed, despite having a fixed limit of 32. If more than 32 Accept headers were present, the code would write outside of its memory and cause a crash.

    Published: 22 Feb 2018
    7.5
    High

    CVE-2018-7285

    Last Modified: 21 Nov 2024

    A NULL pointer access issue was discovered in Asterisk 15.x through 15.2.1. The RTP support in Asterisk maintains its own registry of dynamic codecs and desired payload numbers. While an SDP negotiation may result in a codec using a different payload number, these desired ones are still stored internally. When an RTP packet was received, this registry would be consulted if the payload number was not found in the negotiated SDP. This registry was incorrectly consulted for all packets, even those which are dynamic. If the payload number resulted in a codec of a different type than the RTP stream (for example, the payload number resulted in a video codec but the stream carried audio), a crash could occur if no stream of that type had been negotiated. This was due to the code incorrectly assuming that a stream of that type would always exist.

    Published: 22 Feb 2018
    8.8
    High

    CVE-2018-7435

    Last Modified: 21 Nov 2024

    An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the freexl::destroy_cell function.

    Published: 22 Feb 2018
    8.8
    High

    CVE-2018-7437

    Last Modified: 21 Nov 2024

    An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a memcpy call of the parse_SST function.

    Published: 22 Feb 2018
    8.8
    High

    CVE-2018-7439

    Last Modified: 21 Nov 2024

    An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the function read_mini_biff_next_record.

    Published: 22 Feb 2018
    5.5
    Medium

    CVE-2018-7730

    Last Modified: 21 Nov 2024

    An issue was discovered in Exempi through 2.4.4. A certain case of a 0xffffffff length is mishandled in XMPFiles/source/FormatSupport/PSIR_FileWriter.cpp, leading to a heap-based buffer over-read in the PSD_MetaHandler::CacheFileData() function.

    Published: 22 Feb 2018
    5.4
    Medium

    CVE-2018-6936

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists on the D-Link DIR-600M C1 3.01 via the SSID or the name of a user account.

    Published: 21 Feb 2018
    8.8
    High

    CVE-2018-7281

    Last Modified: 21 Nov 2024

    CactusVPN 5.3.6 for macOS contains a root privilege escalation vulnerability through a setuid root binary called runme. The binary takes a single command line argument and passes this argument to a system() call, thus allowing low privileged users to execute commands as root.

    Published: 21 Feb 2018
    8.8
    High

    CVE-2018-7311

    Last Modified: 21 Nov 2024

    PrivateVPN 2.0.31 for macOS suffers from a root privilege escalation vulnerability. The software installs a privileged helper tool that runs as the root user. This privileged helper tool is installed as a LaunchDaemon and implements an XPC service. The XPC service is responsible for handling new VPN connection operations via the main PrivateVPN application. The privileged helper tool creates new VPN connections by executing the openvpn binary located in the /Applications/PrivateVPN.app/Contents/Resources directory. The openvpn binary can be overwritten by the default user, which allows an attacker that has already installed malicious software as the default user to replace the binary. When a new VPN connection is established, the privileged helper tool will launch this malicious binary, thus allowing an attacker to execute code as the root user. NOTE: the vendor has reportedly indicated that this behavior is "an acceptable part of their software.

    Published: 21 Feb 2018
    8.8
    High

    CVE-2018-7308

    Last Modified: 21 Nov 2024

    A CSRF issue was found in var/www/html/files.php in DanWin hosting through 2018-02-11 that allows arbitrary remote users to add/delete/modify any files in any hosting account.

    Published: 21 Feb 2018
    5.4
    Medium

    CVE-2017-1462

    Last Modified: 21 Nov 2024

    IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128461.

    Published: 21 Feb 2018
    7.1
    High

    CVE-2017-1758

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 135859.

    Published: 21 Feb 2018
    5.4
    Medium

    CVE-2017-1604

    Last Modified: 21 Nov 2024

    IBM Maximo Anywhere 7.5 and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132851.

    Published: 21 Feb 2018
    5.4
    Medium

    CVE-2018-7302

    Last Modified: 21 Nov 2024

    Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.

    Published: 21 Feb 2018
    5.4
    Medium

    CVE-2018-7303

    Last Modified: 21 Nov 2024

    The Calendar component in Tiki 17.1 allows HTML injection.

    Published: 21 Feb 2018
    8.8
    High

    CVE-2018-7304

    Last Modified: 21 Nov 2024

    Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.

    Published: 21 Feb 2018
    4.9
    Medium

    CVE-2018-7305

    Last Modified: 21 Nov 2024

    MyBB 1.8.14 is not checking for a valid CSRF token, leading to arbitrary deletion of user accounts.

    Published: 21 Feb 2018
    3.3
    Low

    CVE-2018-7289

    Last Modified: 21 Nov 2024

    An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames containing pure UTF-16 characters can bypass detection. The user-mode service will fail to open the file for scanning after the conversion is done from Unicode to ANSI. This happens because characters that cannot be converted from Unicode are replaced with '?' characters.

    Published: 21 Feb 2018
    5.4
    Medium

    CVE-2018-7261

    Last Modified: 21 Nov 2024

    There are multiple Persistent XSS vulnerabilities in Radiant CMS 1.1.4. They affect Personal Preferences (Name and Username) and Configuration (Site Title, Dev Site Domain, Page Parts, and Page Fields).

    Published: 21 Feb 2018
    6.1
    Medium

    CVE-2018-7280

    Last Modified: 21 Nov 2024

    The Ninja Forms plugin before 3.2.14 for WordPress has XSS.

    Published: 21 Feb 2018
    8
    High

    CVE-2016-0348

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3, 3.3.1, 3.3.2, and 3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. IBM X-Force ID: 111813.

    Published: 21 Feb 2018
    6.1
    Medium

    CVE-2013-4891

    Last Modified: 21 Nov 2024

    The xss_clean function in CodeIgniter before 2.1.4 might allow remote attackers to bypass an intended protection mechanism and conduct cross-site scripting (XSS) attacks via an unclosed HTML tag.

    Published: 21 Feb 2018
    5.9
    Medium

    CVE-2015-5314

    Last Modified: 21 Nov 2024

    The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when used with (1) an internal EAP server or (2) a RADIUS server and EAP-pwd is enabled in a runtime configuration, which allows remote attackers to cause a denial of service (process termination) via a large final fragment in an EAP-pwd message.

    Published: 21 Feb 2018
    5.4
    Medium

    CVE-2016-0344

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the My Reports component in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111785.

    Published: 21 Feb 2018
    9.8
    Critical

    CVE-2015-5725

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter before 2.2.4 allows remote attackers to execute arbitrary SQL commands via vectors involving the offset variable.

    Published: 21 Feb 2018
    4.3
    Medium

    CVE-2016-0343

    Last Modified: 21 Nov 2024

    IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 111784.

    Published: 21 Feb 2018
    4.3
    Medium

    CVE-2016-0345

    Last Modified: 21 Nov 2024

    IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain the installation path via vectors involving Birt report rendering. IBM X-Force ID: 111786.

    Published: 21 Feb 2018
    3.7
    Low

    CVE-2016-0351

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session. IBM X-Force ID: 111890.

    Published: 21 Feb 2018
    3.7
    Low

    CVE-2016-0366

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 might allow remote attackers to obtain sensitive information by leveraging weak encryption. IBM X-Force ID: 112071.

    Published: 21 Feb 2018
    4.3
    Medium

    CVE-2016-0367

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 112072.

    Published: 21 Feb 2018