CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2017-6230

    Last Modified: 21 Nov 2024

    Ruckus Networks Solo APs firmware releases R110.x or before and Ruckus Networks SZ managed APs firmware releases R5.x or before contain authenticated Root Command Injection in the web-GUI that could allow authenticated valid users to execute privileged commands on the respective systems.

    Published: 14 Feb 2018
    8.8
    High

    CVE-2017-6229

    Last Modified: 21 Nov 2024

    Ruckus Networks Unleashed AP firmware releases before 200.6.10.1.x and Ruckus Networks Zone Director firmware releases 10.1.0.0.x, 9.10.2.0.x, 9.12.3.0.x, 9.13.3.0.x, 10.0.1.0.x or before contain authenticated Root Command Injection in the CLI that could allow authenticated valid users to execute privileged commands on the respective systems.

    Published: 14 Feb 2018
    9.8
    Critical

    CVE-2017-18187

    Last Modified: 21 Nov 2024

    In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.

    Published: 14 Feb 2018
    7.5
    High

    CVE-2018-7034

    Last Modified: 21 Nov 2024

    TRENDnet TEW-751DR v1.03B03, TEW-752DRU v1.03B01, and TEW733GR v1.03B01 devices allow authentication bypass via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.

    Published: 14 Feb 2018
    8.8
    High

    CVE-2017-1499

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable Web server. IBM X-Force ID: 129106.

    Published: 14 Feb 2018
    5.4
    Medium

    CVE-2017-1682

    Last Modified: 21 Nov 2024

    IBM Connections 4.0, 4.5, 5.0, 5.5, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134004.

    Published: 14 Feb 2018
    7.5
    High

    CVE-2018-7032

    Last Modified: 21 Nov 2024

    webcheckout in myrepos through 1.20171231 does not sanitize URLs that are passed to git clone, allowing a malicious website operator or a MitM attacker to take advantage of it for arbitrary code execution, as demonstrated by an "ext::sh -c" attack or an option injection attack.

    Published: 14 Feb 2018
    9.8
    Critical

    CVE-2018-1287

    Last Modified: 21 Nov 2024

    In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

    Published: 14 Feb 2018
    6.1
    Medium

    CVE-2018-2364

    Last Modified: 21 Nov 2024

    SAP CRM WebClient UI 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01, S4FND 1.02, does not sufficiently validate and/or encode hidden fields, resulting in Cross-Site Scripting (XSS) vulnerability.

    Published: 14 Feb 2018
    6.1
    Medium

    CVE-2018-2371

    Last Modified: 21 Nov 2024

    The SAML 2.0 service provider of SAP Netweaver AS Java Web Application, 7.50, does not sufficiently encode user controlled inputs, which results in Cross-Site Scripting (XSS) vulnerability.

    Published: 14 Feb 2018
    6.5
    Medium

    CVE-2018-2372

    Last Modified: 21 Nov 2024

    A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication.

    Published: 14 Feb 2018
    7.5
    High

    CVE-2018-2373

    Last Modified: 21 Nov 2024

    Under certain circumstances, a specific endpoint of the Controller's API could be misused by unauthenticated users to execute SQL statements that deliver information about system configuration in SAP HANA Extended Application Services, 1.0.

    Published: 14 Feb 2018
    6.5
    Medium

    CVE-2018-2374

    Last Modified: 21 Nov 2024

    In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve sensitive application data like service bindings within that space.

    Published: 14 Feb 2018
    8.1
    High

    CVE-2018-2375

    Last Modified: 21 Nov 2024

    In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space.

    Published: 14 Feb 2018
    8.1
    High

    CVE-2018-2376

    Last Modified: 21 Nov 2024

    In SAP HANA Extended Application Services, 1.0, a controller user who has SpaceAuditor authorization in a specific space could retrieve application environments within that space.

    Published: 14 Feb 2018
    8.8
    High

    CVE-2018-2381

    Last Modified: 21 Nov 2024

    SAP ERP Financials Information System (SAP_APPL 6.00, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16; SAP_FIN 6.17, 6.18, 7.00, 7.20, 7.30 S4CORE 1.00, 1.01, 1.02) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

    Published: 14 Feb 2018
    6.1
    Medium

    CVE-2018-2383

    Last Modified: 21 Nov 2024

    Reflected cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.

    Published: 14 Feb 2018
    6.5
    Medium

    CVE-2018-2386

    Last Modified: 21 Nov 2024

    Under certain conditions a malicious user provoking an out of bounds buffer overflow can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53.

    Published: 14 Feb 2018
    6.5
    Medium

    CVE-2018-2387

    Last Modified: 21 Nov 2024

    A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to obtain information on ports, which is not available to the user otherwise.

    Published: 14 Feb 2018
    6.1
    Medium

    CVE-2018-2388

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.

    Published: 14 Feb 2018
    5.7
    Medium

    CVE-2018-2389

    Last Modified: 21 Nov 2024

    Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding important information in the log file.

    Published: 14 Feb 2018
    6.5
    Medium

    CVE-2018-2390

    Last Modified: 21 Nov 2024

    Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, via IGS Chart service.

    Published: 14 Feb 2018
    6.5
    Medium

    CVE-2018-2391

    Last Modified: 21 Nov 2024

    Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, via IGS portwatcher service.

    Published: 14 Feb 2018
    6.5
    Medium

    CVE-2018-2394

    Last Modified: 21 Nov 2024

    Under certain conditions an unauthenticated malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, services and/or system files.

    Published: 14 Feb 2018
    8.8
    High

    CVE-2018-2395

    Last Modified: 21 Nov 2024

    Under certain conditions a malicious user may retrieve information on SAP Internet Graphic Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, overwrite existing image or corrupt other type of files.

    Published: 14 Feb 2018
    6.5
    Medium

    CVE-2018-2396

    Last Modified: 21 Nov 2024

    Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, using IGS Interpreter service.

    Published: 14 Feb 2018
    5.3
    Medium

    CVE-2018-2369

    Last Modified: 21 Nov 2024

    Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would otherwise be restricted. An attacker can misuse the authentication function of the SAP HANA server on its SQL interface and disclose 8 bytes of the server process memory. The attacker cannot influence or predict the location of the leaked memory.

    Published: 14 Feb 2018
    5.3
    Medium

    CVE-2018-2370

    Last Modified: 21 Nov 2024

    Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad, 4.10, from 4.20, from 4.30, could allow a malicious user to use common techniques to determine which ports are in use on the backend server.

    Published: 14 Feb 2018
    6.5
    Medium

    CVE-2018-2378

    Last Modified: 21 Nov 2024

    In SAP HANA Extended Application Services, 1.0, unauthorized users can read statistical data about deployed applications including resource consumption.

    Published: 14 Feb 2018
    6.5
    Medium

    CVE-2018-2379

    Last Modified: 21 Nov 2024

    In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint.

    Published: 14 Feb 2018
    6.5
    Medium

    CVE-2018-2385

    Last Modified: 21 Nov 2024

    Under certain conditions a malicious user provoking a divide by zero crash can prevent legitimate users from accessing the SAP Internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, and its services.

    Published: 14 Feb 2018
    7.5
    High

    CVE-2018-2393

    Last Modified: 21 Nov 2024

    Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.

    Published: 14 Feb 2018
    6.5
    Medium

    CVE-2018-2377

    Last Modified: 21 Nov 2024

    In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved by unauthorized users.

    Published: 14 Feb 2018
    6.5
    Medium

    CVE-2018-2382

    Last Modified: 21 Nov 2024

    A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to store graphics in a controlled area and as such gain information from system area, which is not available to the user otherwise.

    Published: 14 Feb 2018
    6.5
    Medium

    CVE-2018-2384

    Last Modified: 21 Nov 2024

    Under certain conditions a malicious user provoking a Null Pointer dereference can prevent legitimate users from accessing the SAP Internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, and its services.

    Published: 14 Feb 2018
    7.5
    High

    CVE-2018-2392

    Last Modified: 21 Nov 2024

    Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.

    Published: 14 Feb 2018
    5.3
    Medium

    CVE-2018-1000067

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.

    Published: 14 Feb 2018
    5.3
    Medium

    CVE-2018-1000068

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessible, if the Jenkins home directory is on a case-insensitive file system.

    Published: 14 Feb 2018
    6.5
    Medium

    CVE-2018-6356

    Last Modified: 21 Nov 2024

    Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should not have access to. On Windows, any file accessible to the Jenkins master process could be downloaded. On other operating systems, any file within the Jenkins home directory accessible to the Jenkins master process could be downloaded.

    Published: 14 Feb 2018
    7.8
    High

    CVE-2018-7566

    Last Modified: 21 Nov 2024

    The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.

    Published: 14 Feb 2018
    7.5
    High

    CVE-2018-6910

    Last Modified: 21 Nov 2024

    DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.

    Published: 13 Feb 2018
    9.8
    Critical

    CVE-2018-5459

    Last Modified: 21 Nov 2024

    An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime by sending specially-crafted TCP packets to Port 2455.

    Published: 13 Feb 2018
    9.1
    Critical

    CVE-2018-1383

    Last Modified: 21 Nov 2024

    A software logic bug creates a vulnerability in an AIX 6.1, 7.1, and 7.2 daemon which could allow a user with root privileges on one system, to obtain root access on another machine. IBM X-force ID: 138117.

    Published: 13 Feb 2018
    9.8
    Critical

    CVE-2018-6953

    Last Modified: 21 Nov 2024

    In CCN-lite 2, the Parser of NDNTLV does not verify whether a certain component's length field matches the actual component length, which has a resultant buffer overflow and out-of-bounds memory accesses.

    Published: 13 Feb 2018
    7.8
    High

    CVE-2017-1711

    Last Modified: 21 Nov 2024

    IBM iNotes 8.5 and 9.0 SUService can be misguided into running malicious code from a DLL masquerading as a windows DLL in the temp directory. IBM X-Force ID: 134532.

    Published: 13 Feb 2018
    7.8
    High

    CVE-2017-1714

    Last Modified: 21 Nov 2024

    IBM Notes and Domino NSD 8.5 and 9.0 could allow an authenticated local user without administrative privileges to gain System privilege. IBM X-Force ID: 134633.

    Published: 13 Feb 2018
    5.3
    Medium

    CVE-2017-1720

    Last Modified: 21 Nov 2024

    IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC. IBM X-Force ID: 134807.

    Published: 13 Feb 2018
    9.8
    Critical

    CVE-2018-6928

    Last Modified: 21 Nov 2024

    PHP Scripts Mall News Website Script 2.0.4 has SQL Injection via a search term.

    Published: 13 Feb 2018
    9.8
    Critical

    CVE-2018-6948

    Last Modified: 21 Nov 2024

    In CCN-lite 2, the function ccnl_prefix_to_str_detailed can cause a buffer overflow, when writing a prefix to the buffer buf. The maximal size of the prefix is CCNL_MAX_PREFIX_SIZE; the buffer has the size CCNL_MAX_PREFIX_SIZE. However, when NFN is enabled, additional characters are written to the buffer (e.g., the "NFN" and "R2C" tags). Therefore, sending an NFN-R2C packet with a prefix of size CCNL_MAX_PREFIX_SIZE can cause an overflow of buf inside ccnl_prefix_to_str_detailed.

    Published: 13 Feb 2018
    9.8
    Critical

    CVE-2018-0488

    Last Modified: 21 Nov 2024

    ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted application packet within a TLS or DTLS session.

    Published: 13 Feb 2018