CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-0487

    Last Modified: 21 Nov 2024

    ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted certificate chain that is mishandled during RSASSA-PSS signature verification within a TLS or DTLS session.

    Published: 13 Feb 2018
    9.8
    Critical

    CVE-2018-6911

    Last Modified: 21 Nov 2024

    The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argument (aka the command parameter).

    Published: 13 Feb 2018
    9.8
    Critical

    CVE-2018-6292

    Last Modified: 21 Nov 2024

    Remote Code Execution in Saperion Web Client version 7.5.2 83166.

    Published: 13 Feb 2018
    7.5
    High

    CVE-2018-6293

    Last Modified: 21 Nov 2024

    Arbitrary File Read in Saperion Web Client version 7.5.2 83166.

    Published: 13 Feb 2018
    9.8
    Critical

    CVE-2018-1297

    Last Modified: 21 Nov 2024

    When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

    Published: 13 Feb 2018
    7.5
    High

    CVE-2018-7050

    Last Modified: 21 Nov 2024

    An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. A NULL pointer dereference occurs for an "empty" nick.

    Published: 13 Feb 2018
    9.8
    Critical

    CVE-2018-7053

    Last Modified: 21 Nov 2024

    An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected order.

    Published: 13 Feb 2018
    7.5
    High

    CVE-2018-7262

    Last Modified: 21 Nov 2024

    In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service.

    Published: 13 Feb 2018
    5.5
    Medium

    CVE-2016-10713

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU patch before 2.7.6. Out-of-bounds access within pch_write_line() in pch.c can possibly lead to DoS via a crafted input file.

    Published: 13 Feb 2018
    3.7
    Low

    CVE-2017-15709

    Last Modified: 21 Nov 2024

    When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.

    Published: 13 Feb 2018
    7.8
    High

    CVE-2017-16670

    Last Modified: 21 Nov 2024

    The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.

    Published: 13 Feb 2018
    6.5
    Medium

    CVE-2017-15699

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vulnerability, a remote user must be able to establish an AMQP connection to the Qpid Dispatch Router and send a specifically crafted AMQP frame which will cause it to segfault and shut down.

    Published: 13 Feb 2018
    8.8
    High

    CVE-2018-6056

    Last Modified: 21 Nov 2024

    Type confusion could lead to a heap out-of-bounds write in V8 in Google Chrome prior to 64.0.3282.168 allowing a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

    Published: 13 Feb 2018
    8.1
    High

    CVE-2017-9963

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social engineering in order to get a legitimate user to click on or access a malicious link/site containing the CSRF attack.

    Published: 12 Feb 2018
    5.9
    Medium

    CVE-2017-9968

    Last Modified: 21 Nov 2024

    A security misconfiguration vulnerability exists in Schneider Electric's IGSS Mobile application versions 3.01 and prior in which a lack of certificate pinning during the TLS/SSL connection establishing process can result in a man-in-the-middle attack.

    Published: 12 Feb 2018
    6.7
    Medium

    CVE-2017-9969

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear text in the configuration which can result in exposure of sensitive information.

    Published: 12 Feb 2018
    7.2
    High

    CVE-2017-9970

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1.3 and prior. Uploading a zip which contains carefully crafted metadata allows for the file to be uploaded to any directory on the host machine information which could lead to remote code execution.

    Published: 12 Feb 2018
    7.8
    High

    CVE-2017-9967

    Last Modified: 21 Nov 2024

    A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) and Data Execution prevention (DEP) were not properly configured resulting in weak security.

    Published: 12 Feb 2018
    7
    High

    CVE-2018-1214

    Last Modified: 21 Nov 2024

    Dell EMC SupportAssist Enterprise version 1.1 creates a local Windows user account named "OMEAdapterUser" with a default password as part of the installation process. This unnecessary user account also remains even after an upgrade from v1.1 to v1.2. Access to the management console can be achieved by someone with knowledge of the default password. If SupportAssist Enterprise is installed on a server running OpenManage Essentials (OME), the OmeAdapterUser user account is added as a member of the OmeAdministrators group for the OME. An unauthorized person with knowledge of the default password and access to the OME web console could potentially use this account to gain access to the affected installation of OME with OmeAdministrators privileges. This is fixed in version 1.2.1.

    Published: 12 Feb 2018
    7.8
    High

    CVE-2017-13231

    Last Modified: 21 Nov 2024

    In libmediadrm, there is an out-of-bounds write due to improper input validation. This could lead to local elevation of privileges with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-67962232.

    Published: 12 Feb 2018
    7.5
    High

    CVE-2017-13239

    Last Modified: 21 Nov 2024

    A information disclosure vulnerability in the Android framework (ui framework). Product: Android. Versions: 8.0. ID: A-66244132.

    Published: 12 Feb 2018
    7.5
    High

    CVE-2017-13246

    Last Modified: 21 Nov 2024

    A information disclosure vulnerability in the Upstream kernel network driver. Product: Android. Versions: Android kernel. ID: A-36279469.

    Published: 12 Feb 2018
    7.8
    High

    CVE-2017-13247

    Last Modified: 21 Nov 2024

    In the Pixel 2 bootloader, there is a missing permission check which bypasses carrier bootloader lock. This could lead to local elevation of privileges with user execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-71486645.

    Published: 12 Feb 2018
    8.8
    High

    CVE-2017-13230

    Last Modified: 21 Nov 2024

    In hevc codec, there is an out-of-bounds write due to an incorrect bounds check with the i2_pic_width_in_luma_samples value. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65483665.

    Published: 12 Feb 2018
    7.8
    High

    CVE-2017-13236

    Last Modified: 21 Nov 2024

    In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-68217699.

    Published: 12 Feb 2018
    4.2
    Medium

    CVE-2017-13238

    Last Modified: 21 Nov 2024

    In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical access to the device. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-64610940.

    Published: 12 Feb 2018
    7.8
    High

    CVE-2017-13244

    Last Modified: 21 Nov 2024

    A elevation of privilege vulnerability in the Upstream kernel easel. Product: Android. Versions: Android kernel. ID: A-62678986.

    Published: 12 Feb 2018
    8.8
    High

    CVE-2017-13228

    Last Modified: 21 Nov 2024

    In function ih264d_ref_idx_reordering of libavc, there is an out-of-bounds write due to modCount being defined as an unsigned character. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69478425.

    Published: 12 Feb 2018
    9.8
    Critical

    CVE-2017-13229

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-68160703.

    Published: 12 Feb 2018
    7.5
    High

    CVE-2017-13232

    Last Modified: 21 Nov 2024

    In audioserver, there is an out-of-bounds write due to a log statement using %s with an array that may not be NULL terminated. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68953950.

    Published: 12 Feb 2018
    6.5
    Medium

    CVE-2017-13233

    Last Modified: 21 Nov 2024

    In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. This could lead to a remote temporary denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-62851602.

    Published: 12 Feb 2018
    6.5
    Medium

    CVE-2017-13234

    Last Modified: 21 Nov 2024

    In DLSParser of the sonivox library, there is possible resource exhaustion due to a memory leak. This could lead to remote temporary denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68159767.

    Published: 12 Feb 2018
    6.5
    Medium

    CVE-2017-13235

    Last Modified: 21 Nov 2024

    A other vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-68342866.

    Published: 12 Feb 2018
    7.5
    High

    CVE-2017-13240

    Last Modified: 21 Nov 2024

    A information disclosure vulnerability in the Android framework (crypto framework). Product: Android. Versions: 8.0, 8.1. ID: A-68694819.

    Published: 12 Feb 2018
    7.5
    High

    CVE-2017-13241

    Last Modified: 21 Nov 2024

    A information disclosure vulnerability in the Android media framework (libstagefright_soft_avcenc). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-69065651.

    Published: 12 Feb 2018
    7.5
    High

    CVE-2017-13242

    Last Modified: 21 Nov 2024

    A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-62672248.

    Published: 12 Feb 2018
    7.5
    High

    CVE-2017-13243

    Last Modified: 21 Nov 2024

    A information disclosure vulnerability in the Android system (ui). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. ID: A-38258991.

    Published: 12 Feb 2018
    7.8
    High

    CVE-2017-13245

    Last Modified: 21 Nov 2024

    A elevation of privilege vulnerability in the Upstream kernel audio driver. Product: Android. Versions: Android kernel. ID: A-64315347.

    Published: 12 Feb 2018
    4.4
    Medium

    CVE-2016-9569

    Last Modified: 21 Nov 2024

    The cbstream.sys driver in Carbon Black 5.1.1.60603 allows local users with admin privileges to cause a denial of service (out-of-bounds read and system crash) via a large counter value in an 0x62430028 IOCTL call.

    Published: 12 Feb 2018
    7.5
    High

    CVE-2016-9570

    Last Modified: 21 Nov 2024

    cb.exe in Carbon Black 5.1.1.60603 allows attackers to cause a denial of service (out-of-bounds read, invalid pointer dereference, and application crash) by leveraging access to the NetMon named pipe.

    Published: 12 Feb 2018
    7.8
    High

    CVE-2016-8742

    Last Modified: 21 Nov 2024

    The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service launcher, or CouchDB batch or binary files. A subsequent service or server restart will then run that binary with administrator privilege. This issue affected CouchDB 2.0.0 (Windows platform only) and was addressed in CouchDB 2.0.0.1.

    Published: 12 Feb 2018
    7.2
    High

    CVE-2018-6926

    Last Modified: 21 Nov 2024

    In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The impact is limited by the setting being only accessible to the site administrator.

    Published: 12 Feb 2018
    8.8
    High

    CVE-2017-15089

    Last Modified: 21 Nov 2024

    It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.

    Published: 12 Feb 2018
    9.8
    Critical

    CVE-2018-6893

    Last Modified: 21 Nov 2024

    controllers/member/Api.php in dayrui FineCms 5.2.0 has SQL Injection: a request with s=member,c=api,m=checktitle, and the parameter 'module' with a SQL statement, lacks effective filtering.

    Published: 12 Feb 2018
    6.1
    Medium

    CVE-2017-18178

    Last Modified: 21 Nov 2024

    Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1.

    Published: 12 Feb 2018
    5.4
    Medium

    CVE-2017-18177

    Last Modified: 21 Nov 2024

    Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is fixed in 10.1.

    Published: 12 Feb 2018
    5.4
    Medium

    CVE-2017-18176

    Last Modified: 21 Nov 2024

    Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.

    Published: 12 Feb 2018
    5.4
    Medium

    CVE-2017-18175

    Last Modified: 21 Nov 2024

    Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1.

    Published: 12 Feb 2018
    8.8
    High

    CVE-2017-18179

    Last Modified: 21 Nov 2024

    Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termination. Also, it is transmitted as a GET parameter. This is fixed in 10.1.

    Published: 12 Feb 2018
    4.8
    Medium

    CVE-2018-6506

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) exists in the Add Forum feature in the Administrative Panel in miniBB 3.2.2 via crafted use of an onload attribute of an SVG element in the supertitle field.

    Published: 12 Feb 2018