6.5
    Medium

    CVE-2018-7286

    Last Modified: 27 Feb 2018

    An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation fault) by sending a number of SIP INVITE messages on a TCP or TLS connection and then suddenly closing the connection.

    Source:EnableSecurity
    Published:22 Feb 2018
    7.5
    High

    CVE-2018-7284

    Last Modified: 27 Feb 2018

    A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. When processing a SUBSCRIBE request, the res_pjsip_pubsub module stores the accepted formats present in the Accept headers of the request. This code did not limit the number of headers it processed, despite having a fixed limit of 32. If more than 32 Accept headers were present, the code would write outside of its memory and cause a crash.

    Source:EnableSecurity
    Published:22 Feb 2018
    5.5
    Medium

    CVE-2018-7273

    Last Modified: 22 Mar 2018

    In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables using printk calls within the function show_floppy in drivers/block/floppy.c. An attacker can read this information from dmesg and use the addresses to find the locations of kernel code and data and bypass kernel security protections such as KASLR.

    Source:Gregory Draperi
    Published:20 Feb 2018
    9.8
    Critical

    CVE-2018-7264

    Last Modified: 5 Mar 2018

    The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out of bounds write and sign errors, allowing a remote attacker to execute arbitrary code on vulnerable applications using the ActivePDF Toolkit to process untrusted images.

    Source:François Goichon
    Published:28 Feb 2018
    7.8
    High

    CVE-2018-7254

    Last Modified: 21 Feb 2018

    The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-read), or possibly trigger a buffer overflow or incorrect memory allocation, via a maliciously crafted CAF file.

    Source:r4xis
    Published:19 Feb 2018
    9.8
    Critical

    CVE-2018-7251

    Last Modified: 3 Oct 2019

    An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.

    Source:Tijme Gommers
    Published:19 Feb 2018
    5.5
    Medium

    CVE-2018-7250

    Last Modified: 21 Nov 2024

    An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. An uninitialized kernel pool allocation in IOCTL 0xCA002813 allows a local unprivileged attacker to leak 16 bits of uninitialized kernel PagedPool data.

    Published:26 Feb 2018
    7
    High

    CVE-2018-7249

    Last Modified: 21 Nov 2024

    An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. Two carefully timed calls to IOCTL 0xCA002813 can cause a race condition that leads to a use-after-free. When exploited, an unprivileged attacker can run arbitrary code in the kernel.

    Published:26 Feb 2018
    8
    High

    CVE-2018-7216

    Last Modified: 6 Mar 2018

    Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal allows remote authenticated users to hijack the authentication of application users for requests that modify their personal data by leveraging lack of anti-CSRF tokens.

    Source:Arvind V
    Published:18 Feb 2018
    8.1
    High

    CVE-2018-7211

    Last Modified: 21 Nov 2024

    An issue was discovered in iDashboards 9.6b. The SSO implementation is affected by a weak obfuscation library, allowing man-in-the-middle attackers to discover credentials.

    Published:18 Feb 2018
    6.1
    Medium

    CVE-2018-7203

    Last Modified: 28 Mar 2018

    Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the friendlyname parameter to rpc/set_all.

    Source:Sven Fassbender
    Published:30 Mar 2018
    6.1
    Medium

    CVE-2018-7198

    Last Modified: 19 Feb 2018

    October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.

    Source:Samrat Das
    Published:18 Feb 2018
    6.1
    Medium

    CVE-2018-7197

    Last Modified: 21 Nov 2024

    An issue was discovered in Pluck through 4.7.4. A stored cross-site scripting (XSS) vulnerability allows remote unauthenticated users to inject arbitrary web script or HTML into admin/blog Reaction Comments via a crafted URL.

    Published:18 Feb 2018
    7.5
    High

    CVE-2018-7182

    Last Modified: 14 Nov 2018

    The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd instance from 4.2.8p6 through 4.2.8p10.

    Source:Magnus Klaaborg Stubman
    Published:27 Feb 2018
    9.8
    Critical

    CVE-2018-7180

    Last Modified: 16 Feb 2018

    SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-7179

    Last Modified: 16 Feb 2018

    SQL Injection exists in the SquadManagement 1.0.3 component for Joomla! via the id parameter.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-7178

    Last Modified: 16 Feb 2018

    SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-7177

    Last Modified: 16 Feb 2018

    SQL Injection exists in the Saxum Numerology 3.0.4 component for Joomla! via the publicid parameter.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    8.8
    High

    CVE-2018-7176

    Last Modified: 16 Feb 2018

    FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page).

    Source:Samrat Das
    Published:16 Feb 2018
    7.5
    High

    CVE-2018-7171

    Last Modified: 28 Mar 2018

    Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a .. (dot dot) in the contentbase parameter to rpc/set_all.

    Source:Sven Fassbender
    Published:30 Mar 2018
    8.8
    High

    CVE-2018-6981

    Last Modified: 21 Nov 2024

    VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without ESXi600-201811401-BG, VMware Workstation 15, VMware Workstation 14.1.3 or below, VMware Fusion 11, VMware Fusion 10.1.3 or below contain uninitialized stack memory usage in the vmxnet3 virtual network adapter which may allow a guest to execute code on the host.

    Published:4 Dec 2018
    8.1
    High

    CVE-2018-6961

    Last Modified: 2 Jul 2018

    VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful exploitation of this issue could result in remote code execution.

    Source:ParagonSec
    Published:11 Jun 2018
    7.8
    High

    CVE-2018-6947

    Last Modified: 23 Feb 2018

    An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2 and earlier allows a local low privileged user to gain elevation of privileges on Windows 7 (32 and 64bit), and denial of service for Windows 8 and 10.

    Source:Fidus InfoSecurity
    Published:28 Feb 2018
    8.8
    High

    CVE-2018-6941

    Last Modified: 14 Feb 2018

    A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with XSS.

    Source:hyp3rlinx
    Published:20 Feb 2018
    6.1
    Medium

    CVE-2018-6940

    Last Modified: 14 Feb 2018

    A /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with CSRF.

    Source:hyp3rlinx
    Published:20 Feb 2018
    5.4
    Medium

    CVE-2018-6936

    Last Modified: 2 Mar 2018

    Cross Site Scripting (XSS) exists on the D-Link DIR-600M C1 3.01 via the SSID or the name of a user account.

    Source:Prasenjit Kanti Paul
    Published:21 Feb 2018
    9.8
    Critical

    CVE-2018-6911

    Last Modified: 13 Feb 2018

    The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argument (aka the command parameter).

    Source:Nassim Asrir
    Published:13 Feb 2018
    4.8
    Medium

    CVE-2018-6905

    Last Modified: 21 Nov 2024

    The page module in TYPO3 before 8.7.11, and 9.1.0, has XSS via $GLOBALS['TYPO3_CONF_VARS']['SYS']['sitename'], as demonstrated by an admin entering a crafted site name during the installation process.

    Published:8 Apr 2018
    9.8
    Critical

    CVE-2018-6892

    Last Modified: 26 Feb 2018

    An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client application listening on port 8888 can send a malicious payload causing a buffer overflow condition. This will result in an attacker controlling the program's execution flow and allowing arbitrary code execution.

    Source:Metasploit
    Published:11 Feb 2018
    4.8
    Medium

    CVE-2018-6890

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Wolf CMS 0.8.3.1 via the page editing feature, as demonstrated by /?/admin/page/edit/3.

    Published:22 Feb 2018
    8.8
    High

    CVE-2018-6889

    Last Modified: 13 Feb 2018

    An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the web cache or perform advanced password reset attacks or even trigger arbitrary user re-direction.

    Source:Navina Asrani
    Published:12 Feb 2018
    8
    High

    CVE-2018-6888

    Last Modified: 13 Feb 2018

    An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack of an anti-CSRF token.

    Source:Navina Asrani
    Published:12 Feb 2018
    9.8
    Critical

    CVE-2018-6871

    Last Modified: 12 Feb 2018

    LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.

    Source:Mikhail Klementev
    Published:9 Feb 2018
    4.3
    Medium

    CVE-2018-6849

    Last Modified: 5 Apr 2018

    In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP address in a STUN request.

    Source:Dhiraj Mishra
    Published:1 Apr 2018
    6.1
    Medium

    CVE-2018-6845

    Last Modified: 10 Feb 2018

    PHP Scripts Mall Multi Language Olx Clone Script 2.0.6 has XSS via the Leave Comment field.

    Source:Varun Bagaria
    Published:12 Feb 2018
    5.3
    Medium

    CVE-2018-6794

    Last Modified: 5 Mar 2018

    Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious server breaks a normal TCP flow and sends data before the 3-way handshake is complete, then the data sent by the malicious server will be accepted by web clients such as a web browser or Linux CLI utilities, but ignored by Suricata IDS signatures. This mostly affects IDS signatures for the HTTP protocol and TCP stream content; signatures for TCP packets will inspect such network traffic as usual.

    Source:Positive Technologies
    Published:7 Feb 2018
    6.8
    Medium

    CVE-2018-6791

    Last Modified: 21 Nov 2024

    An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is "$(touch b)" -- this will create a file called b in the home folder.

    Published:7 Feb 2018
    9.8
    Critical

    CVE-2018-6789

    Last Modified: 25 Oct 2018

    An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.

    Source:hackk.gr
    Published:7 Feb 2018
    7.5
    High

    CVE-2018-6757

    Last Modified: 11 Dec 2018

    Privilege Escalation vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbitrary code via specially crafted malware.

    Source:Google Security Research
    Published:6 Dec 2018
    7.8
    High

    CVE-2018-6756

    Last Modified: 11 Dec 2018

    Authentication Abuse vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute unauthorized commands via specially crafted malware.

    Source:Google Security Research
    Published:6 Dec 2018
    7.2
    High

    CVE-2018-6755

    Last Modified: 11 Dec 2018

    Weak Directory Permission Vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbitrary code via specially crafted malware.

    Source:Google Security Research
    Published:6 Dec 2018
    4.7
    Medium

    CVE-2018-6671

    Last Modified: 8 Mar 2019

    Application Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows remote authenticated users to bypass localhost only access security protection for some ePO features via a specially crafted HTTP request.

    Source:leonjza
    Published:15 Jun 2018
    6.1
    Medium

    CVE-2018-6643

    Last Modified: 21 Nov 2024

    Infoblox NetMRI 7.1.1 has Reflected Cross-Site Scripting via the /api/docs/index.php query parameter.

    Published:28 Aug 2018
    7.1
    High

    CVE-2018-6622

    Last Modified: 21 Nov 2024

    An issue was discovered that affects all producers of BIOS firmware who make a certain realistic interpretation of an obscure portion of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2.0 specification. An abnormal case is not handled properly by this firmware while S3 sleep and can clear TPM 2.0. It allows local users to overwrite static PCRs of TPM and neutralize the security features of it, such as seal/unseal and remote attestation.

    Published:17 Aug 2018
    7.5
    High

    CVE-2018-6610

    Last Modified: 5 Feb 2018

    Information Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request.

    Source:Ihsan Sencan
    Published:5 Feb 2018
    9.8
    Critical

    CVE-2018-6609

    Last Modified: 5 Feb 2018

    SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit action, or the id parameter in a statuslist (or prioritylist) edit action.

    Source:Ihsan Sencan
    Published:5 Feb 2018
    7.8
    High

    CVE-2018-6606

    Last Modified: 7 Feb 2018

    An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows a non-privileged process to register itself with the driver by sending IOCTL 0x80002010 and then using IOCTL 0x8000204C to \\.\ZemanaAntiMalware to elevate privileges.

    Source:Souhail Hammou
    Published:4 Feb 2018
    9.8
    Critical

    CVE-2018-6605

    Last Modified: 5 Feb 2018

    SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.

    Source:Ihsan Sencan
    Published:5 Feb 2018
    9.8
    Critical

    CVE-2018-6604

    Last Modified: 5 Feb 2018

    SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetails request.

    Source:Ihsan Sencan
    Published:5 Feb 2018
    7.8
    High

    CVE-2018-6593

    Last Modified: 6 Feb 2018

    An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows a non-privileged process to register itself with the driver by connecting to the filter communication port and then using IOCTL 0x8000204C to \\.\ZemanaAntiMalware to elevate privileges.

    Source:Souhail Hammou
    Published:3 Feb 2018