CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-5279

    Last Modified: 21 Nov 2024

    In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e02c. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).

    Published: 8 Jan 2018
    9.8
    Critical

    CVE-2017-5971

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in NewsBee CMS allow remote attackers to execute arbitrary SQL commands.

    Published: 8 Jan 2018
    7.8
    High

    CVE-2018-5275

    Last Modified: 21 Nov 2024

    In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40E020. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).

    Published: 8 Jan 2018
    7.8
    High

    CVE-2018-5276

    Last Modified: 21 Nov 2024

    In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e018. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).

    Published: 8 Jan 2018
    5.4
    Medium

    CVE-2018-5071

    Last Modified: 21 Nov 2024

    Persistent XSS exists in the web server on Cobham Sea Tel 116 build 222429 satellite communication system devices: remote attackers can inject malicious JavaScript code using the device's TELNET shell built-in commands, as demonstrated by the "set ship name" command. This is similar to a Cross Protocol Injection with SNMP.

    Published: 8 Jan 2018
    7.5
    High

    CVE-2018-5266

    Last Modified: 21 Nov 2024

    Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information about valid usernames by reading the loginName lines at the js/userLogin.js URI. NOTE: default passwords for the standard usernames are listed in the product's documentation: Dealer with password seatel3, SysAdmin with password seatel2, and User with password seatel1.

    Published: 8 Jan 2018
    9.8
    Critical

    CVE-2018-5267

    Last Modified: 21 Nov 2024

    Cobham Sea Tel 121 build 222701 devices allow remote attackers to bypass authentication via a direct request to MenuDealerGx.html, MenuDealer.html, MenuEuNCGx.html, MenuEuNC.html, MenuSysGx.html, or MenuSys.html.

    Published: 8 Jan 2018
    7.8
    High

    CVE-2017-15913

    Last Modified: 21 Nov 2024

    The Installer in Whale allows DLL hijacking.

    Published: 8 Jan 2018
    7.5
    High

    CVE-2018-0786

    Last Modified: 21 Nov 2024

    Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."

    Published: 8 Jan 2018
    7.5
    High

    CVE-2014-10069

    Last Modified: 21 Nov 2024

    Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which makes it easier for attackers to obtain sensitive information by decrypting a backup configuration file, as demonstrated by a password hash in the um_auth_account_password field.

    Published: 7 Jan 2018
    5.5
    Medium

    CVE-2018-5268

    Last Modified: 21 Nov 2024

    In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file.

    Published: 7 Jan 2018
    5.5
    Medium

    CVE-2018-5269

    Last Modified: 21 Nov 2024

    In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast.

    Published: 7 Jan 2018
    9.8
    Critical

    CVE-2018-5206

    Last Modified: 21 Nov 2024

    When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer.

    Published: 6 Jan 2018
    7.5
    High

    CVE-2018-5207

    Last Modified: 21 Nov 2024

    When using an incomplete variable argument, Irssi before 1.0.6 may access data beyond the end of the string.

    Published: 6 Jan 2018
    9.8
    Critical

    CVE-2018-5208

    Last Modified: 21 Nov 2024

    In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings.

    Published: 6 Jan 2018
    5
    Medium

    CVE-2018-1000021

    Last Modified: 21 Nov 2024

    GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious git server, (or have their traffic modified in a MITM attack).

    Published: 6 Jan 2018
    7.8
    High

    CVE-2018-5344

    Last Modified: 21 Nov 2024

    In the Linux kernel through 4.14.13, drivers/block/loop.c mishandles lo_release serialization, which allows attackers to cause a denial of service (__lock_acquire use-after-free) or possibly have unspecified other impact.

    Published: 6 Jan 2018
    7.5
    High

    CVE-2018-5205

    Last Modified: 21 Nov 2024

    When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string.

    Published: 6 Jan 2018
    5.3
    Medium

    CVE-2018-5252

    Last Modified: 21 Nov 2024

    libimageworsener.a in ImageWorsener 1.3.2, when libjpeg 8d is used, has a large loop in the get_raw_sample_int function in imagew-main.c.

    Published: 5 Jan 2018
    7.8
    High

    CVE-2018-5253

    Last Modified: 21 Nov 2024

    The AP4_FtypAtom class in Core/Ap4FtypAtom.cpp in Bento4 1.5.1.0 has an Infinite loop via a crafted MP4 file that triggers size mishandling.

    Published: 5 Jan 2018
    6.1
    Medium

    CVE-2018-5249

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php).

    Published: 5 Jan 2018
    6.5
    Medium

    CVE-2018-5251

    Last Modified: 21 Nov 2024

    In libming 0.4.8, there is an integer signedness error vulnerability (left shift of a negative value) in the readSBits function (util/read.c). Remote attackers can leverage this vulnerability to cause a denial of service via a crafted swf file.

    Published: 5 Jan 2018
    9.8
    Critical

    CVE-2017-18021

    Last Modified: 21 Nov 2024

    It was discovered that QtPass before 1.2.1, when using the built-in password generator, generates possibly predictable and enumerable passwords. This only applies to the QtPass GUI.

    Published: 5 Jan 2018
    9.8
    Critical

    CVE-2017-15548

    Last Modified: 21 Nov 2024

    An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote unauthenticated malicious user can potentially bypass application authentication and gain unauthorized root access to the affected systems.

    Published: 5 Jan 2018
    8.8
    High

    CVE-2017-15550

    Last Modified: 21 Nov 2024

    An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could access arbitrary files on the server file system in the context of the running vulnerable application via Path traversal.

    Published: 5 Jan 2018
    8.8
    High

    CVE-2017-15549

    Last Modified: 21 Nov 2024

    An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privileges could potentially upload arbitrary maliciously crafted files in any location on the server file system.

    Published: 5 Jan 2018
    7.8
    High

    CVE-2014-8335

    Last Modified: 21 Nov 2024

    (1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress place credentials on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.

    Published: 5 Jan 2018
    6.5
    Medium

    CVE-2014-8336

    Last Modified: 21 Nov 2024

    The "Sql Run Query" panel in WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote attackers to read arbitrary files by leveraging failure to sufficiently limit queries, as demonstrated by use of LOAD_FILE in an INSERT statement.

    Published: 5 Jan 2018
    6.5
    Medium

    CVE-2014-8540

    Last Modified: 21 Nov 2024

    The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.

    Published: 5 Jan 2018
    9.8
    Critical

    CVE-2014-8579

    Last Modified: 21 Nov 2024

    TRENDnet TEW-823DRU devices with firmware before 1.00b36 have a hardcoded password of kcodeskcodes for the root account, which makes it easier for remote attackers to obtain access via an FTP session.

    Published: 5 Jan 2018
    8.8
    High

    CVE-2017-16666

    Last Modified: 21 Nov 2024

    Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name of an uploaded PCAP file. NOTE: this issue can be exploited without authentication by leveraging the user registration feature.

    Published: 5 Jan 2018
    Unknown

    CVE-2017-1922

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-1924

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-1928

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-1931

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-2005

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-2008

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-2074

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-2012

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-2076

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-2081

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-2084

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-2087

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-2064

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-2065

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-2068

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-2070

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-2071

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    7.8
    High

    CVE-2017-4946

    Last Modified: 21 Nov 2024

    The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issue could result in a low privileged windows user escalating their privileges to SYSTEM.

    Published: 5 Jan 2018
    Unknown

    CVE-2017-1977

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018