CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2018-6042

    Last Modified: 21 Nov 2024

    Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 24 Jan 2018
    6.5
    Medium

    CVE-2018-6050

    Last Modified: 21 Nov 2024

    Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 24 Jan 2018
    7.8
    High

    CVE-2018-7208

    Last Modified: 21 Nov 2024

    In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, an index is not validated, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted file, as demonstrated by objcopy of a COFF object.

    Published: 24 Jan 2018
    8.8
    High

    CVE-2017-1000502

    Last Modified: 21 Nov 2024

    Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the master node whenever the agent was supposed to be launched. Configuration of these agents now requires the 'Run Scripts' permission typically only granted to administrators.

    Published: 24 Jan 2018
    8.8
    High

    CVE-2018-6033

    Last Modified: 21 Nov 2024

    Insufficient data validation in Downloads in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially run arbitrary code outside sandbox via a crafted Chrome Extension.

    Published: 24 Jan 2018
    6.1
    Medium

    CVE-2018-6039

    Last Modified: 21 Nov 2024

    Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted Chrome Extension.

    Published: 24 Jan 2018
    6.5
    Medium

    CVE-2018-6040

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially bypass content security policy via a crafted HTML page.

    Published: 24 Jan 2018
    8.8
    High

    CVE-2018-6043

    Last Modified: 21 Nov 2024

    Insufficient data validation in External Protocol Handler in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially execute arbitrary programs on user machine via a crafted HTML page.

    Published: 24 Jan 2018
    6.5
    Medium

    CVE-2018-6045

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user local file data via a crafted Chrome Extension.

    Published: 24 Jan 2018
    4.3
    Medium

    CVE-2018-6047

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user redirect URL via a crafted HTML page.

    Published: 24 Jan 2018
    6.5
    Medium

    CVE-2018-6049

    Last Modified: 21 Nov 2024

    Incorrect security UI in permissions prompt in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the origin to which permission is granted via a crafted HTML page.

    Published: 24 Jan 2018
    4.3
    Medium

    CVE-2018-6051

    Last Modified: 21 Nov 2024

    XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote attacker to obtain referrer details via a crafted HTML page.

    Published: 24 Jan 2018
    4.3
    Medium

    CVE-2018-6052

    Last Modified: 21 Nov 2024

    Lack of support for a non standard no-referrer policy value in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain referrer details from a web page that had thought it had opted out of sending referrer data.

    Published: 24 Jan 2018
    8.8
    High

    CVE-2018-6054

    Last Modified: 21 Nov 2024

    Use after free in WebUI in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension.

    Published: 24 Jan 2018
    9.8
    Critical

    CVE-2017-15697

    Last Modified: 21 Nov 2024

    A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fix to properly handle these headers was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

    Published: 23 Jan 2018
    7.5
    High

    CVE-2017-12632

    Last Modified: 21 Nov 2024

    A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and compare to a controlled whitelist was applied on the Apache NiFi 1.5.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

    Published: 23 Jan 2018
    9.8
    Critical

    CVE-2017-15531

    Last Modified: 21 Nov 2024

    Symantec Reporter 9.5 prior to 9.5.4.1 and 10.1 prior to 10.1.5.5 does not restrict excessive authentication attempts for management interface users. A remote attacker can use brute force search to guess a user password and gain access to Reporter.

    Published: 23 Jan 2018
    9.8
    Critical

    CVE-2018-5749

    Last Modified: 21 Nov 2024

    install.php in Minecraft Servers List Lite before commit c1cd164 and Premium Minecraft Servers List before 2.0.4 does not sanitize input before saving database connection information in connect.php, which might allow remote attackers to execute arbitrary PHP code via the (1) database_server, (2) database_user, (3) database_password, or (4) database_name parameter.

    Published: 23 Jan 2018
    8.1
    High

    CVE-2018-5359

    Last Modified: 21 Nov 2024

    The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system-level access because of a Buffer Overflow.

    Published: 23 Jan 2018
    9.8
    Critical

    CVE-2017-17999

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter to index.php/knowledge_base/get_article_suggestion/.

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15473

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15474

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15475

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15476

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15477

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15478

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15487

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15488

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15489

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15439

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15470

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15471

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15472

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15492

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15493

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15494

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15495

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15496

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15497

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15498

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15499

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15437

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15438

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15432

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15433

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15434

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15435

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15436

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15441

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018
    Unknown

    CVE-2017-15442

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 23 Jan 2018