Unknown · CVSS Not scored
In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. This could lead to a remote temporary denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-62851602.
Published Feb 12, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4
Published Feb 9, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attackers that have write access to an indexed repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in via a specially crafted repository branch name when trying to display deleted files of the branch.
Published Feb 2, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An Authentication Bypass vulnerability in HPE MSA 1040 and MSA 2040 SAN Storage IN version GL220P008 and earlier was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 shipped with an MCollective configuration that allowed the package plugin to install or remove arbitrary packages on all managed agents. This release adds default configuration to not allow these actions. Customers who rely on this functionality can change this policy.
Published Feb 1, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.
Published Feb 23, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE UCMDB version v10.10, v10.11, v10.20, v10.21, v10.22, v10.30, v10.31 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not have authorization to access via an improper authorization vulnerability.
Published Feb 19, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Local Disclosure of Sensitive Information vulnerability in HPE NonStop Software Essentials version T0894 T0894H02 through T0894H02^AAI was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A directory traversal vulnerability in HPE Intelligent Management Center (IMC) PLAT 7.3 E0504P02 could allow remote code execution.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A privilege escalation vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Low · CVSS 3.7
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host. IBM X-Force ID: 123675.
Published Feb 5, 2019 · Updated Sep 16, 2024
Unknown · CVSS Not scored
IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 135859.
Published Feb 21, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review.
Published Feb 16, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Low · CVSS 3.7
IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 123673.
Published Feb 5, 2019 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In all Qualcomm products with Android releases from CAF using the Linux kernel, the num_failure_info value from firmware is not properly validated in wma_rx_aggr_failure_event_handler() so that an integer overflow vulnerability in a buffer size calculation may potentially lead to a buffer overflow.
Published Feb 23, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A elevation of privilege vulnerability in the Upstream kernel audio driver. Product: Android. Versions: Android kernel. ID: A-64315347.
Published Feb 12, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A remote code execution vulnerability in HPE intelligent Management Center (iMC) PLAT iMC Plat 7.3 E0504P2 and earlier was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.
Published Feb 15, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code.
Published Feb 9, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Croogo version 2.3.1-17-g6f82e6c contains a Cross Site Scripting (XSS) vulnerability in Page name that can result in execution of javascript code.
Published Feb 9, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.
Published Feb 9, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Canvs Canvas version 3.4.2 contains a Cross Site Scripting (XSS) vulnerability in User's details that can result in denial of service and execution of javascript code.
Published Feb 9, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and later.
Published Feb 9, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.
Published Feb 1, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.
Published Feb 1, 2018 · Updated Aug 5, 2024
Low · CVSS 3.1
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by this issue is the function saveJSON of the file components/install/process.php. The manipulation of the argument data leads to information disclosure. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 2.8.1 is able to address this issue. The patch is identified as 517119de673e62547ee472a730be0604f44342b5. It is recommended to upgrade the affected component. VDB-221498 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Published Feb 21, 2023 · Updated Aug 5, 2024
Medium · CVSS 6.5
A vulnerability was found in InSTEDD Pollit 2.3.1. It has been rated as critical. This issue affects the function TourController of the file app/controllers/tour_controller.rb. The manipulation leads to an unknown weakness. The attack may be initiated remotely. Upgrading to version 2.3.2 is able to address this issue. The patch is named 6ef04f8b5972d5f16f8b86f8b53f62fac68d5498. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-221507.
Published Feb 21, 2023 · Updated Aug 5, 2024