CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2018-3673

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3674

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3675

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3676

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3677

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3678

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3681

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3685

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3692

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3694

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3695

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3706

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3707

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3708

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3709

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    9.1
    Critical

    CVE-2018-3739

    Last Modified: 21 Nov 2024

    https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON).

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3623

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    8.8
    High

    CVE-2017-17942

    Last Modified: 20 Apr 2025

    In LibTIFF 4.0.9, there is a heap-based buffer over-read in the function PackBitsEncode in tif_packbits.c.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3631

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3625

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3651

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3680

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    9.8
    Critical

    CVE-2015-6237

    Last Modified: 20 Apr 2025

    The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerate users, (2) reset passwords, or (3) manipulate IP filter restrictions via crafted "privileged commands."

    Published: 27 Dec 2017
    6.1
    Medium

    CVE-2015-7324

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) img or (2) url tag of a new comment.

    Published: 27 Dec 2017
    6.1
    Medium

    CVE-2015-7666

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functions in cp_ppp_admin_int_message_list.inc.php in the Payment Form for PayPal Pro plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the cal parameter.

    Published: 27 Dec 2017
    9.8
    Critical

    CVE-2015-7669

    Last Modified: 20 Apr 2025

    Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the Easy2Map plugin before 1.3.0 for WordPress allow remote attackers to include and execute arbitrary files via the csvfile parameter related to "upload file functionality."

    Published: 27 Dec 2017
    6.1
    Medium

    CVE-2015-7668

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.3.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id parameter.

    Published: 27 Dec 2017
    6.1
    Medium

    CVE-2015-7667

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in (1) templates/admanagement/admanagement.php and (2) templates/adspot/adspot.php in the ResAds plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 27 Dec 2017
    6.5
    Medium

    CVE-2017-9608

    Last Modified: 20 Apr 2025

    The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted mov file.

    Published: 27 Dec 2017
    9.8
    Critical

    CVE-2014-8389

    Last Modified: 20 Apr 2025

    cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with firmware 1.81 21.08.2014, AirLive WL-2000CAM with firmware LM.1.6.18 14.10.2011, and AirLive POE-200CAM v2 with firmware LM.1.6.17.01 uses hard-coded credentials in the embedded Boa web server, which allows remote attackers to obtain user credentials via crafted HTTP requests.

    Published: 27 Dec 2017
    5.5
    Medium

    CVE-2015-7889

    Last Modified: 20 Apr 2025

    The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the com.samsung.android.email.intent.action.QUICK_REPLY_BACKGROUND service action, which might allow remote attackers with knowledge of the local email address to obtain sensitive information via a crafted application that sends a crafted intent.

    Published: 27 Dec 2017
    8.1
    High

    CVE-2015-3637

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in phpMyBackupPro when run in multi-user mode before 2.5 allows remote attackers to execute arbitrary SQL commands via the username and password parameters.

    Published: 27 Dec 2017
    6.5
    Medium

    CVE-2017-10910

    Last Modified: 20 Apr 2025

    MQTT.js 2.x.x prior to 2.15.0 issue in handling PUBLISH tickets may lead to an attacker causing a denial-of-service condition.

    Published: 27 Dec 2017
    7.8
    High

    CVE-2017-13056

    Last Modified: 20 Apr 2025

    The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file.

    Published: 27 Dec 2017
    4.8
    Medium

    CVE-2017-16768

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the name parameter.

    Published: 27 Dec 2017
    7.8
    High

    CVE-2016-6914

    Last Modified: 20 Apr 2025

    Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privileges via a Trojan horse taskkill.exe file.

    Published: 27 Dec 2017
    5.3
    Medium

    CVE-2017-1698

    Last Modified: 20 Apr 2025

    IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message that could lead to further attacks against the system. IBM X-Force ID: 124390.

    Published: 27 Dec 2017
    4.3
    Medium

    CVE-2017-1191

    Last Modified: 20 Apr 2025

    An undisclosed vulnerability in CLM applications (including IBM Rational Collaborative Lifecycle Management 4.0, 5.0, and 6.0) with potential for failure to restrict URL Access. IBM X-Force ID: 123661.

    Published: 27 Dec 2017
    5.4
    Medium

    CVE-2017-1365

    Last Modified: 20 Apr 2025

    IBM Team Concert (RTC including IBM Rational Collaborative Lifecycle Management 4.0, 5.0., and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 126858.

    Published: 27 Dec 2017
    6.5
    Medium

    CVE-2017-18008

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.7-17 Q16, there is a Memory Leak in ReadPWPImage in coders/pwp.c.

    Published: 27 Dec 2017
    7.5
    High

    CVE-2017-17935

    Last Modified: 20 Apr 2025

    The File_read_line function in epan/wslua/wslua_file.c in Wireshark through 2.2.11 does not properly strip '\n' characters, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet that triggers the attempted processing of an empty line.

    Published: 27 Dec 2017
    5.3
    Medium

    CVE-2017-17924

    Last Modified: 20 Apr 2025

    PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via the id parameter to admin/review_userwise.php.

    Published: 26 Dec 2017
    5.3
    Medium

    CVE-2017-17927

    Last Modified: 20 Apr 2025

    PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via a crafted PATH_INFO to service-list/category/.

    Published: 26 Dec 2017
    9.8
    Critical

    CVE-2017-17928

    Last Modified: 20 Apr 2025

    PHP Scripts Mall Professional Service Script has SQL injection via the admin/review.php id parameter.

    Published: 26 Dec 2017
    4.8
    Medium

    CVE-2017-17929

    Last Modified: 20 Apr 2025

    PHP Scripts Mall Professional Service Script has XSS via the admin/bannerview.php view parameter.

    Published: 26 Dec 2017
    8.8
    High

    CVE-2017-17930

    Last Modified: 20 Apr 2025

    PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user panel.

    Published: 26 Dec 2017
    9.8
    Critical

    CVE-2017-17931

    Last Modified: 20 Apr 2025

    PHP Scripts Mall Resume Clone Script has SQL Injection via the forget.php username parameter.

    Published: 26 Dec 2017
    4.8
    Medium

    CVE-2017-17925

    Last Modified: 20 Apr 2025

    PHP Scripts Mall Professional Service Script has XSS via the admin/general_settingupd.php website_title parameter.

    Published: 26 Dec 2017
    5.3
    Medium

    CVE-2017-17926

    Last Modified: 20 Apr 2025

    PHP Scripts Mall Professional Service Script has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address.

    Published: 26 Dec 2017
    8.8
    High

    CVE-2017-17913

    Last Modified: 20 Apr 2025

    In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to an incompatibility with libwebp versions, 0.5.0 and later, that use a different structure type.

    Published: 26 Dec 2017