CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2018-6484

    Last Modified: 10 Jul 2025

    In ZZIPlib 0.13.67, there is a memory alignment error and bus error in the __zzip_fetch_disk_trailer function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.

    Published: 1 Feb 2018
    9.8
    Critical

    CVE-2017-16861

    Last Modified: 21 Nov 2024

    It was possible for double OGNL evaluation in certain redirect action and in WebWork URL and Anchor tags in JSP files to occur. An attacker who can access the web interface of Fisheye or Crucible or who hosts a website that a user who can access the web interface of Fisheye or Crucible visits, is able to exploit this vulnerability to execute Java code of their choice on systems that run a vulnerable version of Fisheye or Crucible. All versions of Fisheye and Crucible before 4.4.5 (the fixed version for 4.4.x) and from 4.5.0 before 4.5.2 (the fixed version for 4.5.x) are affected by this vulnerability.

    Published: 1 Feb 2018
    9.8
    Critical

    CVE-2018-4877

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player's quality of service functionality. A successful attack can lead to arbitrary code execution.

    Published: 1 Feb 2018
    6.5
    Medium

    CVE-2018-6541

    Last Modified: 10 Jul 2025

    In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address (when handling disk64_trailer local entries) in __zzip_fetch_disk_trailer (zzip/zip.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.

    Published: 1 Feb 2018
    7.8
    High

    CVE-2018-6543

    Last Modified: 21 Nov 2024

    In GNU Binutils 2.30, there's an integer overflow in the function load_specific_debug_section() in objdump.c, which results in `malloc()` with 0 size. A crafted ELF file allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 1 Feb 2018
    7.8
    High

    CVE-2018-4878

    Last Modified: 18 Nov 2025

    A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.

    Published: 1 Feb 2018
    6.5
    Medium

    CVE-2018-6374

    Last Modified: 21 Nov 2024

    The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 does not perform strict SSL Certificate Validation. This can lead to the manipulation of the Pulse Connection set.

    Published: 31 Jan 2018
    8.6
    High

    CVE-2018-0136

    Last Modified: 2 Dec 2024

    A vulnerability in the IPv6 subsystem of Cisco IOS XR Software Release 5.3.4 for the Cisco Aggregation Services Router (ASR) 9000 Series could allow an unauthenticated, remote attacker to trigger a reload of one or more Trident-based line cards, resulting in a denial of service (DoS) condition. The vulnerability is due to incorrect handling of IPv6 packets with a fragment header extension. An attacker could exploit this vulnerability by sending IPv6 packets designed to trigger the issue either to or through the Trident-based line card. A successful exploit could allow the attacker to trigger a reload of Trident-based line cards, resulting in a DoS during the period of time the line card takes to restart. This vulnerability affects Cisco Aggregation Services Router (ASR) 9000 Series when the following conditions are met: The router is running Cisco IOS XR Software Release 5.3.4, and the router has installed Trident-based line cards that have IPv6 configured. A software maintenance upgrade (SMU) has been made available that addresses this vulnerability. The fix has also been incorporated into service pack 7 for Cisco IOS XR Software Release 5.3.4. Cisco Bug IDs: CSCvg46800.

    Published: 31 Jan 2018
    7.5
    High

    CVE-2018-6479

    Last Modified: 21 Nov 2024

    An issue was discovered on Netwave IP Camera devices. An unauthenticated attacker can crash a device by sending a POST request with a huge body size to the / URI.

    Published: 31 Jan 2018
    8.8
    High

    CVE-2017-15656

    Last Modified: 21 Nov 2024

    Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt.

    Published: 31 Jan 2018
    8.8
    High

    CVE-2017-15653

    Last Modified: 21 Nov 2024

    Improper administrator IP validation after his login in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allows an unauthorized user to execute any action knowing administrator session token by using a specific User-Agent string.

    Published: 31 Jan 2018
    8.3
    High

    CVE-2017-15654

    Last Modified: 21 Nov 2024

    Highly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allow gaining administrative router access.

    Published: 31 Jan 2018
    9.6
    Critical

    CVE-2017-15655

    Last Modified: 21 Nov 2024

    Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have been fixed in version 3.0.0.4.378, but this vulnerability was not previously disclosed. Some end-of-life routers have this version as the newest and thus are vulnerable at this time. This vulnerability allows for RCE with administrator rights when the administrator visits several pages.

    Published: 31 Jan 2018
    7.8
    High

    CVE-2017-16928

    Last Modified: 21 Nov 2024

    The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a crafted update URL, as demonstrated by file:///tmp/blah/Arq.zip.

    Published: 31 Jan 2018
    7.8
    High

    CVE-2017-16945

    Last Modified: 21 Nov 2024

    The standardrestorer binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a crafted restore path.

    Published: 31 Jan 2018
    8.8
    High

    CVE-2018-6480

    Last Modified: 21 Nov 2024

    A type confusion issue was discovered in CCN-lite 2, leading to a memory access violation and a failure of the nonce feature (which, for example, helped with loop prevention). ccnl_fwd_handleInterest assumes that the union member s is of type ccnl_pktdetail_ndntlv_s. However, if the type is in fact struct ccnl_pktdetail_ccntlv_s or struct ccnl_pktdetail_iottlv_s, the memory at that point is either uninitialised or points to data that is not a nonce, which renders the code using the local variable nonce pointless. A later nonce check is insufficient.

    Published: 31 Jan 2018
    7.8
    High

    CVE-2018-6471

    Last Modified: 21 Nov 2024

    In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C402078.

    Published: 31 Jan 2018
    7.8
    High

    CVE-2018-6472

    Last Modified: 21 Nov 2024

    In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40204c.

    Published: 31 Jan 2018
    7.8
    High

    CVE-2018-6473

    Last Modified: 21 Nov 2024

    In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C402080.

    Published: 31 Jan 2018
    7.8
    High

    CVE-2018-6474

    Last Modified: 21 Nov 2024

    In SUPERAntiSpyware Professional Trial 6.0.1254, the driver file (SASKUTIL.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C402148.

    Published: 31 Jan 2018
    7.8
    High

    CVE-2018-6475

    Last Modified: 21 Nov 2024

    In SUPERAntiSpyware Professional Trial 6.0.1254, SUPERAntiSpyware.exe allows DLL hijacking, leading to Escalation of Privileges.

    Published: 31 Jan 2018
    9.8
    Critical

    CVE-2018-6476

    Last Modified: 21 Nov 2024

    In SUPERAntiSpyware Professional Trial 6.0.1254, the SASKUTIL.SYS driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating input values from IOCtl 0x9C402114 or 0x9C402124 or 0x9C40207c.

    Published: 31 Jan 2018
    9.8
    Critical

    CVE-2018-5701

    Last Modified: 21 Nov 2024

    In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerability due to not validating input values from IOCtl 0x00226003.

    Published: 31 Jan 2018
    6.1
    Medium

    CVE-2018-6464

    Last Modified: 21 Nov 2024

    Simditor v2.3.11 allows XSS via crafted use of svg/onload=alert in a TEXTAREA element, as demonstrated by Firefox 54.0.1.

    Published: 31 Jan 2018
    6.1
    Medium

    CVE-2018-6465

    Last Modified: 21 Nov 2024

    The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-applicant-matches-email.php.

    Published: 31 Jan 2018
    7.5
    High

    CVE-2014-1631

    Last Modified: 21 Nov 2024

    Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.

    Published: 31 Jan 2018
    8.1
    High

    CVE-2014-1632

    Last Modified: 21 Nov 2024

    htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the hostname parameter.

    Published: 31 Jan 2018
    7.8
    High

    CVE-2018-6462

    Last Modified: 21 Nov 2024

    Tracker PDF-XChange Viewer and Viewer AX SDK before 2.5.322.8 mishandle conversion from YCC to RGB colour spaces by calculating on the basis of 1 bpc instead of 8 bpc, which might allow remote attackers to execute arbitrary code via a crafted PDF document.

    Published: 31 Jan 2018
    7.5
    High

    CVE-2018-6460

    Last Modified: 21 Nov 2024

    Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sensitive information including configuration. User controlled input is not sufficiently filtered: an unauthenticated attacker can send a POST request to /status.js with the parameter func=$_APPLOG.Rfunc and extract sensitive information about the machine, including whether the user is connected to a VPN, to which VPN he/she is connected, and what is their real IP address.

    Published: 31 Jan 2018
    7.8
    High

    CVE-2018-6384

    Last Modified: 21 Nov 2024

    Unquoted Windows search path vulnerability in NSClient++ before 0.4.1.73 allows non-privileged local users to execute arbitrary code with elevated privileges on the system via a malicious program.exe executable in the %SYSTEMDRIVE% folder.

    Published: 31 Jan 2018
    7.8
    High

    CVE-2017-8916

    Last Modified: 21 Nov 2024

    In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access.

    Published: 31 Jan 2018
    6.7
    Medium

    CVE-2017-1233

    Last Modified: 21 Nov 2024

    IBM Remote Control v9 could allow a local user to use the component to replace files to which he does not have write access and which he can cause to be executed with Local System or root privileges. IBM X-Force ID: 123912.

    Published: 31 Jan 2018
    4
    Medium

    CVE-2017-1773

    Last Modified: 21 Nov 2024

    IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle techniques to spoof DNS responses to perform DNS cache poisoning and redirect Internet traffic. IBM X-Force ID: 136817.

    Published: 31 Jan 2018
    6.8
    Medium

    CVE-2017-16858

    Last Modified: 21 Nov 2024

    The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an attacker to impersonate a Crowd user in REST requests by being able to authenticate to a directory bound to an application using the feature. Given the following situation: the Crowd application is bound to directory 1 and has a user called admin and the Google Apps application is bound to directory 2, which also has a user called admin, it was possible to authenticate REST requests using the credentials of the user coming from directory 2 and impersonate the user from directory 1.

    Published: 31 Jan 2018
    6.5
    Medium

    CVE-2018-6930

    Last Modified: 21 Nov 2024

    A stack-based buffer over-read in the ComputeResizeImage function in the MagickCore/accelerate.c file of ImageMagick 7.0.7-22 allows a remote attacker to cause a denial of service (application crash) via a maliciously crafted pict file.

    Published: 31 Jan 2018
    4.7
    Medium

    CVE-2017-16911

    Last Modified: 21 Nov 2024

    The vhci_hcd driver in the Linux Kernel before version 4.14.8 and 4.4.114 allows allows local attackers to disclose kernel memory addresses. Successful exploitation requires that a USB device is attached over IP.

    Published: 31 Jan 2018
    5.9
    Medium

    CVE-2017-15698

    Last Modified: 21 Nov 2024

    When parsing the AIA-Extension field of a client certificate, Apache Tomcat Native Connector 1.2.0 to 1.2.14 and 1.1.23 to 1.1.34 did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the OCSP check. It was therefore possible for client certificates that should have been rejected (if the OCSP check had been made) to be accepted. Users not using OCSP checks are not affected by this vulnerability.

    Published: 31 Jan 2018
    5.3
    Medium

    CVE-2017-15706

    Last Modified: 21 Nov 2024

    As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify which script to execute. The update was not correct. As a result, some scripts may have failed to execute as expected and other scripts may have been executed unexpectedly. Note that the behaviour of the CGI servlet has remained unchanged in this regard. It is only the documentation of the behaviour that was wrong and has been corrected.

    Published: 31 Jan 2018
    5.9
    Medium

    CVE-2018-1304

    Last Modified: 21 Nov 2024

    The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.

    Published: 31 Jan 2018
    7.5
    High

    CVE-2018-6412

    Last Modified: 21 Nov 2024

    In the function sbusfb_ioctl_helper() in drivers/video/fbdev/sbuslib.c in the Linux kernel through 4.15, an integer signedness error allows arbitrary information leakage for the FBIOPUTCMAP_SPARC and FBIOGETCMAP_SPARC commands.

    Published: 31 Jan 2018
    7.5
    High

    CVE-2018-6407

    Last Modified: 21 Nov 2024

    An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. An unauthenticated attacker can crash a device by sending a POST request with a huge body size to /hy-cgi/devices.cgi?cmd=searchlandevice. The crash completely freezes the device.

    Published: 30 Jan 2018
    8.8
    High

    CVE-2018-6408

    Last Modified: 21 Nov 2024

    An issue was discovered on Conceptronic CIPCAMPTIWL V3 0.61.30.21 devices. CSRF exists in hy-cgi/user.cgi, as demonstrated by changing an administrator password or adding a new administrator account.

    Published: 30 Jan 2018
    Unknown

    CVE-2012-3878

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 30 Jan 2018
    6.5
    Medium

    CVE-2018-6405

    Last Modified: 21 Nov 2024

    In the ReadDCMImage function in coders/dcm.c in ImageMagick before 7.0.7-23, each redmap, greenmap, and bluemap variable can be overwritten by a new pointer. The previous pointer is lost, which leads to a memory leak. This allows remote attackers to cause a denial of service.

    Published: 30 Jan 2018
    4.8
    Medium

    CVE-2018-6194

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in admin/partials/wp-splashing-admin-sidebar.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the search parameter to wp-admin/upload.php.

    Published: 30 Jan 2018
    5.3
    Medium

    CVE-2011-2902

    Last Modified: 21 Nov 2024

    zxpdf in xpdf before 3.02-19 as packaged in Debian unstable and 3.02-12+squeeze1 as packaged in Debian squeeze deletes temporary files insecurely, which allows remote attackers to delete arbitrary files via a crafted .pdf.gz file name.

    Published: 30 Jan 2018
    9.8
    Critical

    CVE-2016-6599

    Last Modified: 21 Nov 2024

    BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service contains a method that can be used to retrieve a configuration file that contains the application database name, username and password as well as the domain administrator username and password. These are encrypted with a fixed key and IV ("NumaraIT") using the DES algorithm. The domain administrator username and password can only be obtained if the Self-Service component is enabled, which is the most common scenario in enterprise deployments.

    Published: 30 Jan 2018
    9.8
    Critical

    CVE-2016-6598

    Last Modified: 21 Nov 2024

    BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service contains a method that allows uploading a file to an arbitrary path on the machine that is running Track-It!. This can be used to upload a file to the web root and achieve code execution as NETWORK SERVICE or SYSTEM.

    Published: 30 Jan 2018
    7.8
    High

    CVE-2018-5441

    Last Modified: 21 Nov 2024

    An Improper Validation of Integrity Check Value issue was discovered in PHOENIX CONTACT mGuard firmware versions 7.2 to 8.6.0. mGuard devices rely on internal checksums for verification of the internal integrity of the update packages. Verification may not always be performed correctly, allowing an attacker to modify firmware update packages.

    Published: 30 Jan 2018
    7.2
    High

    CVE-2018-6195

    Last Modified: 21 Nov 2024

    admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows authenticated (administrator, editor, or author) remote attackers to conduct PHP Object Injection attacks via crafted serialized data in the 'session' HTTP GET parameter to wp-admin/upload.php.

    Published: 30 Jan 2018