CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2018-5661

    Last Modified: 21 Nov 2024

    An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php logo_width parameter.

    Published: 13 Jan 2018
    4.8
    Medium

    CVE-2018-5662

    Last Modified: 21 Nov 2024

    An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php counter_title parameter.

    Published: 13 Jan 2018
    4.8
    Medium

    CVE-2018-5663

    Last Modified: 21 Nov 2024

    An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php button_text_link parameter.

    Published: 13 Jan 2018
    4.8
    Medium

    CVE-2018-5664

    Last Modified: 21 Nov 2024

    An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php social_icon_1 parameter.

    Published: 13 Jan 2018
    4.8
    Medium

    CVE-2018-5666

    Last Modified: 21 Nov 2024

    An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php bg_color parameter.

    Published: 13 Jan 2018
    4.8
    Medium

    CVE-2018-5667

    Last Modified: 21 Nov 2024

    An issue was discovered in the read-and-understood plugin 2.1 for WordPress. XSS exists via the wp-admin/options-general.php rnu_username_validation_pattern parameter.

    Published: 13 Jan 2018
    4.8
    Medium

    CVE-2018-5668

    Last Modified: 21 Nov 2024

    An issue was discovered in the read-and-understood plugin 2.1 for WordPress. XSS exists via the wp-admin/options-general.php rnu_username_validation_title parameter.

    Published: 13 Jan 2018
    8.8
    High

    CVE-2018-5669

    Last Modified: 21 Nov 2024

    An issue was discovered in the read-and-understood plugin 2.1 for WordPress. CSRF exists via wp-admin/options-general.php.

    Published: 13 Jan 2018
    4.8
    Medium

    CVE-2018-5670

    Last Modified: 21 Nov 2024

    An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php sale_conditions[count][] parameter.

    Published: 13 Jan 2018
    4.8
    Medium

    CVE-2018-5671

    Last Modified: 21 Nov 2024

    An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extra_field1[items][field_item1][price_percent] parameter.

    Published: 13 Jan 2018
    4.8
    Medium

    CVE-2018-5672

    Last Modified: 21 Nov 2024

    An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_field5[label] parameter.

    Published: 13 Jan 2018
    8.8
    High

    CVE-2018-5673

    Last Modified: 21 Nov 2024

    An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php.

    Published: 13 Jan 2018
    6.5
    Medium

    CVE-2018-5727

    Last Modified: 21 Nov 2024

    In OpenJPEG 2.3.0, there is an integer overflow vulnerability in the opj_t1_encode_cblks function (openjp2/t1.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.

    Published: 13 Jan 2018
    4.8
    Medium

    CVE-2018-5657

    Last Modified: 21 Nov 2024

    An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php counter_title_icon parameter.

    Published: 13 Jan 2018
    7.5
    High

    CVE-2018-7334

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the UMTS MAC dissector could crash. This was addressed in epan/dissectors/packet-umts_mac.c by rejecting a certain reserved value.

    Published: 13 Jan 2018
    6.1
    Medium

    CVE-2018-5653

    Last Modified: 21 Nov 2024

    An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php weblizar_pffree_settings_save_get-users parameter.

    Published: 13 Jan 2018
    8.8
    High

    CVE-2018-5658

    Last Modified: 21 Nov 2024

    An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. CSRF exists via wp-admin/admin.php.

    Published: 13 Jan 2018
    4.8
    Medium

    CVE-2018-5665

    Last Modified: 21 Nov 2024

    An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php logo_height parameter.

    Published: 13 Jan 2018
    8.8
    High

    CVE-2017-13176

    Last Modified: 21 Nov 2024

    In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a remote elevation of privilege that could enable bypassing user interaction requirements with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68341964.

    Published: 12 Jan 2018
    9.8
    Critical

    CVE-2017-13178

    Last Modified: 21 Nov 2024

    In the initDecoder function of SoftAVCDec, there is a possible out-of-bounds write to mCodecCtx due to a use after free when buffer allocation fails. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-66969281.

    Published: 12 Jan 2018
    7.8
    High

    CVE-2017-13181

    Last Modified: 21 Nov 2024

    In the doGetThumb and getThumbnail functions of MtpServer, there is a possible double free due to not NULLing out a freed pointer. This could lead to an local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-67864232.

    Published: 12 Jan 2018
    9.1
    Critical

    CVE-2017-13188

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Android media framework (aac). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65280786.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13195

    Last Modified: 21 Nov 2024

    In the ihevcd_parse_sps function of ihevcd_parse_headers.c, several parameter values could be negative which could lead to negative indexes which could lead to an infinite loop. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65398821.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13201

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Android media framework (mediadrm). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-63982768.

    Published: 12 Jan 2018
    9.8
    Critical

    CVE-2017-13208

    Last Modified: 21 Nov 2024

    In receive_packet of libnetutils/packet.c, there is a possible out-of-bounds write due to a missing bounds check on the DHCP response. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-67474440.

    Published: 12 Jan 2018
    7.8
    High

    CVE-2017-13209

    Last Modified: 21 Nov 2024

    In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller which could allow an application or service to replace a HAL service with its own service. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-68217907.

    Published: 12 Jan 2018
    7.8
    High

    CVE-2017-13180

    Last Modified: 21 Nov 2024

    In the onQueueFilled function of SoftAVCDec, there is a possible out-of-bounds write due to a use after free if a bad header causes the decoder to get caught in a loop while another thread frees the memory it's accessing. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-66969349.

    Published: 12 Jan 2018
    9.1
    Critical

    CVE-2017-13187

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65034175.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13191

    Last Modified: 21 Nov 2024

    In the ihevcd_decode function of ihevcd_decode.c, there is an infinite loop due to an incomplete frame error. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64380403.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13193

    Last Modified: 21 Nov 2024

    In ihevcd_decode.c there is a possible infinite loop due to bytes for an sps of unsupported resolution resulting in the same sps being fed in over and over. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65718319.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13200

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Android media framework (av) related to id3 unsynchronization. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-63100526.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13214

    Last Modified: 21 Nov 2024

    In the hardware HEVC decoder, some media files could cause a page fault. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-38495900.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-0846

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Android framework (clipboardservice). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64934810.

    Published: 12 Jan 2018
    9.8
    Critical

    CVE-2017-13177

    Last Modified: 21 Nov 2024

    In several functions of libhevc, NEON registers are not preserved. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68320413.

    Published: 12 Jan 2018
    9.8
    Critical

    CVE-2017-13179

    Last Modified: 21 Nov 2024

    In the ihevcd_allocate_static_bufs and ihevcd_create functions of SoftHEVC, there is a possible out-of-bounds write due to a use after free. Both ps_codec_obj and ps_create_op->s_ivd_create_op_t.pv_handle point to the same memory and ps_codec_obj could be freed without clearing ps_create_op->s_ivd_create_op_t.pv_handle. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-66969193.

    Published: 12 Jan 2018
    7.8
    High

    CVE-2017-13182

    Last Modified: 21 Nov 2024

    In the sendFormatChange function of ACodec, there is a possible integer overflow which could lead to an out-of-bounds write. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-67737022.

    Published: 12 Jan 2018
    7
    High

    CVE-2017-13183

    Last Modified: 21 Nov 2024

    In the OMXNodeInstance::useBuffer and IOMX::freeBuffer functions, there is a possible use after free due to a race condition if the user frees the buffer while it's being used in another thread. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 8.1. Android ID: A-38118127.

    Published: 12 Jan 2018
    7.8
    High

    CVE-2017-13184

    Last Modified: 21 Nov 2024

    In the enableVSyncInjections function of SurfaceFlinger, there is a possible use after free of mVSyncInjector. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-65483324.

    Published: 12 Jan 2018
    9.1
    Critical

    CVE-2017-13185

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-65123471.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13186

    Last Modified: 21 Nov 2024

    A vulnerability in the Android media framework (libavc) related to incorrect use of mmco parameters. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65735716.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13189

    Last Modified: 21 Nov 2024

    A vulnerability in the Android media framework (libavc) related to handling dec_hdl memory allocation failures. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68300072.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13190

    Last Modified: 21 Nov 2024

    A vulnerability in the Android media framework (libhevc) related to handling ps_codec_obj memory allocation failures. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68299873.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13192

    Last Modified: 21 Nov 2024

    In the ihevcd_parse_slice_header function of ihevcd_parse_slice_header.c a slice address of zero after the first slice could result in an infinite loop. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64380202.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13196

    Last Modified: 21 Nov 2024

    In several places in ihevcd_decode.c, a dead loop could occur due to incomplete frames which could lead to memory leaks. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-63522067.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13197

    Last Modified: 21 Nov 2024

    In the ihevcd_parse_slice.c function, slave threads are not joined if there is an error. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64784973.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13198

    Last Modified: 21 Nov 2024

    A vulnerability in the Android media framework (ex) related to composition of frames lacking a color map. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68399117.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13199

    Last Modified: 21 Nov 2024

    In Bitmap.ccp if Bitmap.nativeCreate fails an out of memory exception is not thrown leading to a java.io.IOException later on. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-33846679.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13202

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-67647856.

    Published: 12 Jan 2018
    9.1
    Critical

    CVE-2017-13203

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Android media framework (libavc). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-63122634.

    Published: 12 Jan 2018
    9.1
    Critical

    CVE-2017-13204

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Android media framework (libavc). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64380237.

    Published: 12 Jan 2018