CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2017-16609

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within download.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to download a file. An attacker can leverage this vulnerability to expose sensitive information. Was ZDI-CAN-4750.

    Published: 23 Jan 2018
    9.8
    Critical

    CVE-2017-17406

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within an exposed RMI registry, which listens on TCP ports 1800 and 1850 by default. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute arbitrary code under the context of the current process. Was ZDI-CAN-4753.

    Published: 23 Jan 2018
    5.3
    Medium

    CVE-2018-5117

    Last Modified: 25 Nov 2025

    If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.

    Published: 23 Jan 2018
    9.8
    Critical

    CVE-2018-5098

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.

    Published: 23 Jan 2018
    9.8
    Critical

    CVE-2018-5097

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content during the transformation. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.

    Published: 23 Jan 2018
    9.8
    Critical

    CVE-2018-5096

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Thunderbird < 52.6.

    Published: 23 Jan 2018
    9.8
    Critical

    CVE-2018-5091

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Firefox < 58.

    Published: 23 Jan 2018
    9.8
    Critical

    CVE-2018-5104

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.

    Published: 23 Jan 2018
    9.8
    Critical

    CVE-2018-5103

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.

    Published: 23 Jan 2018
    9.8
    Critical

    CVE-2018-5102

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.

    Published: 23 Jan 2018
    9.8
    Critical

    CVE-2018-5099

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, resulting in a potentially exploitable crash when these references are used. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.

    Published: 23 Jan 2018
    9.8
    Critical

    CVE-2018-5089

    Last Modified: 25 Nov 2025

    Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.

    Published: 23 Jan 2018
    7.8
    High

    CVE-2018-5996

    Last Modified: 10 Jan 2025

    Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruptions within the PPMd code, allows remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.

    Published: 23 Jan 2018
    5.4
    Medium

    CVE-2018-6013

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) in BigTree 4.2.19 allows any remote users to inject arbitrary web script or HTML via the directory parameter. This issue exists in core/admin/ajax/developer/extensions/file-browser.php.

    Published: 23 Jan 2018
    7.5
    High

    CVE-2018-6196

    Last Modified: 21 Nov 2024

    w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a negative indent value.

    Published: 23 Jan 2018
    4.7
    Medium

    CVE-2018-6198

    Last Modified: 21 Nov 2024

    w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

    Published: 23 Jan 2018
    6.5
    Medium

    CVE-2018-6014

    Last Modified: 21 Nov 2024

    Subsonic v6.1.3 has an insecure allow-access-from domain="*" Flash cross-domain policy that allows an attacker to retrieve sensitive user information via a read request. To exploit this issue, an attacker must convince the user to visit a web site loaded with a SWF file created specifically to steal user data.

    Published: 23 Jan 2018
    5.5
    Medium

    CVE-2018-11232

    Last Modified: 21 Nov 2024

    The etm_setup_aux function in drivers/hwtracing/coresight/coresight-etm-perf.c in the Linux kernel before 4.10.2 allows attackers to cause a denial of service (panic) because a parameter is incorrectly used as a local variable.

    Published: 23 Jan 2018
    6.5
    Medium

    CVE-2018-11251

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.7-23 Q16 x86_64 2018-01-24, there is a heap-based buffer over-read in ReadSUNImage in coders/sun.c, which allows attackers to cause a denial of service (application crash in SetGrayscaleImage in MagickCore/quantize.c) via a crafted SUN image file.

    Published: 23 Jan 2018
    9.8
    Critical

    CVE-2018-5095

    Last Modified: 25 Nov 2025

    An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.

    Published: 23 Jan 2018
    8.8
    High

    CVE-2018-0848

    Last Modified: 21 Nov 2024

    Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807.

    Published: 22 Jan 2018
    8.8
    High

    CVE-2018-0862

    Last Modified: 21 Nov 2024

    Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807.

    Published: 22 Jan 2018
    8.8
    High

    CVE-2018-0849

    Last Modified: 21 Nov 2024

    Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807.

    Published: 22 Jan 2018
    5.3
    Medium

    CVE-2017-1000417

    Last Modified: 21 Nov 2024

    MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509 certificates.

    Published: 22 Jan 2018
    5.3
    Medium

    CVE-2017-1000416

    Last Modified: 21 Nov 2024

    axTLS version 1.5.3 has a coding error in the ASN.1 parser resulting in the year (19)50 of UTCTime being misinterpreted as 2050.

    Published: 22 Jan 2018
    7.8
    High

    CVE-2018-0845

    Last Modified: 21 Nov 2024

    Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0805, CVE-2018-0806, and CVE-2018-0807.

    Published: 22 Jan 2018
    8.8
    High

    CVE-2018-6009

    Last Modified: 21 Nov 2024

    In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a change of identity.

    Published: 22 Jan 2018
    7.5
    High

    CVE-2018-6010

    Last Modified: 21 Nov 2024

    In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, or exploit reflected XSS on the error handler page in non-debug mode. Related to base/ErrorHandler.php, log/Dispatcher.php, and views/errorHandler/exception.php.

    Published: 22 Jan 2018
    9.8
    Critical

    CVE-2018-5999

    Last Modified: 21 Nov 2024

    An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests continues even if authentication fails.

    Published: 22 Jan 2018
    6.1
    Medium

    CVE-2018-6002

    Last Modified: 21 Nov 2024

    The Soundy Background Music plugin 3.9 and below for WordPress has Cross-Site Scripting via soundy-background-music\templates\front-end.php (war_soundy_preview parameter).

    Published: 22 Jan 2018
    6.1
    Medium

    CVE-2018-6001

    Last Modified: 21 Nov 2024

    The Soundy Audio Playlist plugin 4.6 and below for WordPress has Cross-Site Scripting via soundy-audio-playlist\templates\front-end.php (war_sdy_pl_preview parameter).

    Published: 22 Jan 2018
    9.8
    Critical

    CVE-2018-6000

    Last Modified: 21 Nov 2024

    An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and launch an SSH daemon (or enable infosvr command mode), and consequently obtain remote administrative access, via a crafted request. This is available to unauthenticated attackers in conjunction with CVE-2018-5999.

    Published: 22 Jan 2018
    3.7
    Low

    CVE-2018-1000002

    Last Modified: 21 Nov 2024

    Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay.

    Published: 22 Jan 2018
    3.7
    Low

    CVE-2018-1000003

    Last Modified: 21 Nov 2024

    Improper input validation bugs in DNSSEC validators components in PowerDNS version 4.1.0 allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay.

    Published: 22 Jan 2018
    8.1
    High

    CVE-2018-5761

    Last Modified: 21 Nov 2024

    A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vulnerability might expose Rubrik user credentials configured to access vCenter as Rubrik clusters did not verify TLS certificates presented by vCenter.

    Published: 22 Jan 2018
    7.8
    High

    CVE-2017-17858

    Last Modified: 21 Nov 2024

    Heap-based buffer overflow in the ensure_solid_xref function in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 allows a remote attacker to potentially execute arbitrary code via a crafted PDF file, because xref subsection object numbers are unrestricted.

    Published: 22 Jan 2018
    6.5
    Medium

    CVE-2018-1042

    Last Modified: 21 Nov 2024

    Moodle 3.x has Server Side Request Forgery in the filepicker.

    Published: 22 Jan 2018
    4.3
    Medium

    CVE-2018-1044

    Last Modified: 21 Nov 2024

    In Moodle 3.x, quiz web services allow students to see quiz results when it is prohibited in the settings.

    Published: 22 Jan 2018
    5.4
    Medium

    CVE-2018-1045

    Last Modified: 21 Nov 2024

    In Moodle 3.x, there is XSS via a calendar event name.

    Published: 22 Jan 2018
    6.5
    Medium

    CVE-2018-1043

    Last Modified: 21 Nov 2024

    In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames.

    Published: 22 Jan 2018
    8.8
    High

    CVE-2016-10709

    Last Modified: 21 Nov 2024

    pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph parameter, related to _rrd_graph_img.php.

    Published: 22 Jan 2018
    9.8
    Critical

    CVE-2017-18047

    Last Modified: 21 Nov 2024

    Buffer Overflow in the FTP client in LabF nfsAxe 3.7 allows remote FTP servers to execute arbitrary code via a long reply.

    Published: 22 Jan 2018
    8.8
    High

    CVE-2018-5960

    Last Modified: 21 Nov 2024

    Zenario v7.1 - v7.6 has SQL injection via the `Name` input field of organizer.php or admin_boxes.ajax.php in the `Categories - Edit` module.

    Published: 22 Jan 2018
    6.1
    Medium

    CVE-2018-5961

    Last Modified: 21 Nov 2024

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 has XSS via the `module` value of the `index.php` file.

    Published: 22 Jan 2018
    6.1
    Medium

    CVE-2018-5962

    Last Modified: 21 Nov 2024

    index.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 has XSS via the id parameter to the phpini_editor module or the email_address parameter to the mail_add-new module.

    Published: 22 Jan 2018
    7.4
    High

    CVE-2018-1000028

    Last Modified: 21 Nov 2024

    Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS server (nfsd) that can result in remote users reading or writing files they should not be able to via NFS. This attack appear to be exploitable via NFS server must export a filesystem with the "rootsquash" options enabled. This vulnerability appears to have been fixed in after commit 1995266727fa.

    Published: 22 Jan 2018
    8.1
    High

    CVE-2017-15135

    Last Modified: 21 Nov 2024

    It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific circumstances.

    Published: 22 Jan 2018
    4.8
    Medium

    CVE-2018-1000015

    Last Modified: 21 Nov 2024

    On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Build permission on some agents. This did not prevent the execution of Pipeline `node` blocks on those agents due to incorrect permissions checks in Pipeline: Nodes and Processes plugin 2.17 and earlier.

    Published: 22 Jan 2018
    7.5
    High

    CVE-2017-15134

    Last Modified: 21 Nov 2024

    A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.

    Published: 22 Jan 2018
    7.5
    High

    CVE-2016-10708

    Last Modified: 28 Apr 2026

    sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.

    Published: 21 Jan 2018