CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-6781

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A008264.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6787

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x221808.

    Published: 6 Feb 2018
    7
    High

    CVE-2018-5457

    Last Modified: 21 Nov 2024

    A uncontrolled search path element issue was discovered in Vyaire Medical CareFusion Upgrade Utility used with Windows XP systems, Versions 2.0.2.2 and prior versions. A successful exploit of this vulnerability requires the local user to install a crafted DLL on the target machine. The application loads the DLL and gives the attacker access at the same privilege level as the application.

    Published: 6 Feb 2018
    7.5
    High

    CVE-2018-1299

    Last Modified: 21 Nov 2024

    In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application. Some webservers used with Allura, such as Nginx, Apache/mod_wsgi or paster may prevent the attack from succeeding. Others, such as gunicorn do not prevent it and leave Allura vulnerable.

    Published: 6 Feb 2018
    5.5
    Medium

    CVE-2016-3954

    Last Modified: 21 Nov 2024

    web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status. NOTE: this issue can be leveraged by remote attackers to execute arbitrary code using CVE-2016-3957.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2016-3952

    Last Modified: 21 Nov 2024

    web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values via a direct request to examples/template_examples/beautify. NOTE: this issue can be leveraged by remote attackers to gain administrative access.

    Published: 6 Feb 2018
    9.8
    Critical

    CVE-2016-3953

    Last Modified: 21 Nov 2024

    The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a hardcoded encryption key when calling the session.connect function.

    Published: 6 Feb 2018
    9.8
    Critical

    CVE-2016-3957

    Last Modified: 21 Nov 2024

    The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, which might allow remote attackers to execute arbitrary code by leveraging knowledge of encryption_key.

    Published: 6 Feb 2018
    9.8
    Critical

    CVE-2018-6758

    Last Modified: 21 Nov 2024

    The uwsgi_expand_path function in core/utils.c in Unbit uWSGI through 2.0.15 has a stack-based buffer overflow via a large directory length.

    Published: 6 Feb 2018
    7.5
    High

    CVE-2018-6389

    Last Modified: 21 Nov 2024

    In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.

    Published: 6 Feb 2018
    9.8
    Critical

    CVE-2017-17663

    Last Modified: 21 Nov 2024

    The htpasswd implementation of mini_httpd before v1.28 and of thttpd before v2.28 is affected by a buffer overflow that can be exploited remotely to perform code execution.

    Published: 6 Feb 2018
    5.4
    Medium

    CVE-2015-3619

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component before 3.0.8 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors involving a "double encode combination of first_name, last_name and company."

    Published: 6 Feb 2018
    8.8
    High

    CVE-2014-5279

    Last Modified: 21 Nov 2024

    The Docker daemon managed by boot2docker 1.2 and earlier improperly enables unauthenticated TCP connections by default, which makes it easier for remote attackers to gain privileges or execute arbitrary code from children containers.

    Published: 6 Feb 2018
    8.8
    High

    CVE-2014-5280

    Last Modified: 21 Nov 2024

    boot2docker 1.2 and earlier allows attackers to conduct cross-site request forgery (CSRF) attacks by leveraging Docker daemons enabling TCP connections without TLS authentication.

    Published: 6 Feb 2018
    6.1
    Medium

    CVE-2015-3618

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via vectors involving index.php.

    Published: 6 Feb 2018
    4.6
    Medium

    CVE-2015-4400

    Last Modified: 21 Nov 2024

    Ring (formerly DoorBot) video doorbells allow remote attackers to obtain sensitive information about the wireless network configuration by pressing the set up button and leveraging an API in the GainSpan Wi-Fi module.

    Published: 6 Feb 2018
    6.1
    Medium

    CVE-2016-7394

    Last Modified: 21 Nov 2024

    tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.

    Published: 6 Feb 2018
    8.8
    High

    CVE-2017-17996

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in "Add command" functionality exists in Flexense SyncBreeze Enterprise <= 10.3.14. The vulnerability can be triggered by an authenticated attacker who submits more than 5000 characters as the command name. It will cause termination of the SyncBreeze Enterprise server and possibly remote command execution with SYSTEM privilege.

    Published: 6 Feb 2018
    6.5
    Medium

    CVE-2017-6198

    Last Modified: 21 Nov 2024

    The Supervisor in Sandstorm doesn't set and enforce the resource limits of a process. This allows remote attackers to cause a denial of service by launching a fork bomb in the sandbox, or by using a large amount of disk space.

    Published: 6 Feb 2018
    9.8
    Critical

    CVE-2017-6199

    Last Modified: 21 Nov 2024

    A remote attacker could bypass the Sandstorm organization restriction before build 0.203 via a comma in an email-address field.

    Published: 6 Feb 2018
    6.5
    Medium

    CVE-2017-6200

    Last Modified: 21 Nov 2024

    Sandstorm before build 0.203 allows remote attackers to read any specified file under /etc or /run via the sandbox backup function. The root cause is that the findFilesToZip function doesn't filter Line Feed (\n) characters in a directory name.

    Published: 6 Feb 2018
    8.1
    High

    CVE-2017-6201

    Last Modified: 21 Nov 2024

    A Server Side Request Forgery vulnerability exists in the install app process in Sandstorm before build 0.203. A remote attacker may exploit this issue by providing a URL. It could bypass access control such as firewalls that prevent the attackers from accessing the URLs directly.

    Published: 6 Feb 2018
    8.8
    High

    CVE-2018-6288

    Last Modified: 21 Nov 2024

    Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1.

    Published: 6 Feb 2018
    9.8
    Critical

    CVE-2018-6289

    Last Modified: 21 Nov 2024

    Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6290

    Last Modified: 21 Nov 2024

    Local Privilege Escalation in Kaspersky Secure Mail Gateway version 1.1.

    Published: 6 Feb 2018
    6.1
    Medium

    CVE-2018-6291

    Last Modified: 21 Nov 2024

    WebConsole Cross-Site Scripting in Kaspersky Secure Mail Gateway version 1.1.

    Published: 6 Feb 2018
    8.8
    High

    CVE-2018-6467

    Last Modified: 21 Nov 2024

    The flickrRSS plugin 5.3.1 for WordPress has CSRF via wp-admin/options-general.php.

    Published: 6 Feb 2018
    6.5
    Medium

    CVE-2018-6656

    Last Modified: 21 Nov 2024

    Z-BlogPHP 1.5.1 has CSRF via zb_users/plugin/AppCentre/app_del.php, as demonstrated by deleting files and directories.

    Published: 6 Feb 2018
    6.1
    Medium

    CVE-2018-6469

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_tags parameter to wp-admin/options-general.php.

    Published: 6 Feb 2018
    6.1
    Medium

    CVE-2018-6466

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_set parameter to wp-admin/options-general.php.

    Published: 6 Feb 2018
    6.1
    Medium

    CVE-2018-6468

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_id parameter to wp-admin/options-general.php.

    Published: 6 Feb 2018
    9.8
    Critical

    CVE-2016-6813

    Last Modified: 21 Nov 2024

    Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is able to determine the ID of another (non-"root") CloudStack user, the malicious user may be able to reset the API keys for the other user, in turn accessing their account and resources.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2017-6258

    Last Modified: 21 Nov 2024

    NVIDIA libnvmmlite_audio.so contains an elevation of privilege vulnerability when running in media server which may cause an out of bounds write and could lead to local code execution in a privileged process. This issue is rated as high. Product: Android. Version: N/A. Android: A-38027496. Reference: N-CVE-2017-6258.

    Published: 6 Feb 2018
    6.8
    Medium

    CVE-2017-6169

    Last Modified: 21 Nov 2024

    In versions 13.0.0, 12.0.0-12.1.3, or 11.6.0-11.6.2, an F5 BIG-IP virtual server using the URL categorization feature may cause the Traffic Management Microkernel (TMM) to produce a core file when it receives malformed URLs during categorization.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2017-6279

    Last Modified: 21 Nov 2024

    NVIDIA libnvmmlite_audio.so contains an elevation of privilege vulnerability when running in media server which may cause an out of bounds write and could lead to local code execution in a privileged process. This issue is rated as high. Product: Android. Version: N/A. Android: A-65023166. Reference: N-CVE-2017-6279.

    Published: 6 Feb 2018
    8.8
    High

    CVE-2018-6654

    Last Modified: 21 Nov 2024

    The Grammarly extension before 2018-02-02 for Chrome allows remote attackers to discover authentication tokens via an 'action: "user"' request to iframe.gr_-ifr, because the exposure of these tokens is not restricted to any specific web site.

    Published: 6 Feb 2018
    8.8
    High

    CVE-2018-14682

    Last Modified: 21 Nov 2024

    An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.

    Published: 6 Feb 2018
    8.8
    High

    CVE-2018-6569

    Last Modified: 21 Nov 2024

    West Wind Web Server 6.x does not require authentication for /ADMIN.ASP.

    Published: 6 Feb 2018
    7.5
    High

    CVE-2018-6644

    Last Modified: 21 Nov 2024

    SBLIM Small Footprint CIM Broker (SFCB) 1.4.9 has a null pointer (DoS) vulnerability via a crafted POST request to the /cimom URI.

    Published: 6 Feb 2018
    5.5
    Medium

    CVE-2018-6759

    Last Modified: 21 Nov 2024

    The bfd_get_debug_link_info_1 function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, has an unchecked strnlen operation. Remote attackers could leverage this vulnerability to cause a denial of service (segmentation fault) via a crafted ELF file.

    Published: 6 Feb 2018
    7.5
    High

    CVE-2018-7320

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the SIGCOMP protocol dissector could crash. This was addressed in epan/dissectors/packet-sigcomp.c by validating operand offsets.

    Published: 6 Feb 2018
    9.8
    Critical

    CVE-2018-6609

    Last Modified: 21 Nov 2024

    SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit action, or the id parameter in a statuslist (or prioritylist) edit action.

    Published: 5 Feb 2018
    7.5
    High

    CVE-2018-6610

    Last Modified: 21 Nov 2024

    Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request.

    Published: 5 Feb 2018
    8.8
    High

    CVE-2018-6651

    Last Modified: 21 Nov 2024

    In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin header validation (accepting an arbitrary substring match) for WebSocket API requests allows remote attackers to bypass intended access restrictions. In Parsec, this means full control over the victim's computer.

    Published: 5 Feb 2018
    9.8
    Critical

    CVE-2018-6604

    Last Modified: 21 Nov 2024

    SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetails request.

    Published: 5 Feb 2018
    9.8
    Critical

    CVE-2018-6582

    Last Modified: 21 Nov 2024

    SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.

    Published: 5 Feb 2018
    9.8
    Critical

    CVE-2018-6605

    Last Modified: 21 Nov 2024

    SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.

    Published: 5 Feb 2018
    9.8
    Critical

    CVE-2018-5442

    Last Modified: 21 Nov 2024

    A Stack-based Buffer Overflow issue was discovered in Fuji Electric V-Server VPR 4.0.1.0 and prior. The stack-based buffer overflow vulnerability has been identified, which may allow remote code execution.

    Published: 5 Feb 2018
    7.8
    High

    CVE-2018-6626

    Last Modified: 21 Nov 2024

    In Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110005.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x80000035.

    Published: 5 Feb 2018
    7.8
    High

    CVE-2018-6628

    Last Modified: 21 Nov 2024

    In Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110005.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8000010c.

    Published: 5 Feb 2018