LiveActive security incident?Get immediate response
CVE archive

March 2018

Browse CVE records published in March 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1325 matching CVEs · Page 15 of 27.

Unknown · CVSS Not scored

CVE-2018-20032: A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of Flex...

A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.

Published Mar 21, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-20034: A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components...

A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.

Published Mar 21, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-20031: A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components...

A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.

Published Mar 21, 2019 · Updated Aug 5, 2024

High · CVSS 7.1

CVE-2018-19879: An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R_31.04.89 before R_00.05.00.5...

An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R_31.04.89 before R_00.05.00.5 devices. The authentication functionality is not protected from automated tools used to make login attempts to the application. An anonymous attacker has the ability to make unlimited login attempts with an automated tool. This ability could lead to cracking a targeted user's password.

Published Mar 28, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-19798: Fleetco Fleet Maintenance Management (FMM) 1.2 and earlier allows uploading an arbitrary ".php" file with t...

Fleetco Fleet Maintenance Management (FMM) 1.2 and earlier allows uploading an arbitrary ".php" file with the application/x-php Content-Type to the accidents_add.php?submit=1 URI, as demonstrated by the value_Images_1 field, which leads to remote command execution on the remote server. Any authenticated user can exploit this.

Published Mar 2, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-19524: An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, D...

An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTBGN1, and DT741-cb SDOTBGN1 devices. A long password to the Web_passwd function allows remote attackers to cause a denial of service (segmentation fault) or achieve unauthenticated remote code execution because of control of registers S0 through S4 and T4 through T7.

Published Mar 17, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-19514: In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without aut...

In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication. Exploitation requires authentication bypass to access administrative functions of the site to upload a crafted CSV file with a malicious payload that becomes part of a PHP eval() expression in the subscriber.php file.

Published Mar 17, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-19392: Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerabil...

Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability. This could allow modification of any user account's password (including the default "admin" account), without prior knowledge of their password. All that is required is knowledge of the username and attack vector (/index.lua?pageID=Administration usernameAdmChange, passwordAdmChange1, and passwordAdmChange2 fields).

Published Mar 15, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-19394: Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to...

Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file.

Published Mar 15, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-19393: Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of co...

Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configuration file. This was exploitable via multiple attack vectors depending on the device's configuration. Further analysis also indicated this vulnerability could be leveraged to achieve a Denial of Service (DoS) condition, where the device would require a factory reset to return to normal operation.

Published Mar 15, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-19016: Rockwell Automation EtherNet/IP Web Server Modules 1756-EWEB (includes 1756-EWEBK) Version 5.001 and earlie...

Rockwell Automation EtherNet/IP Web Server Modules 1756-EWEB (includes 1756-EWEBK) Version 5.001 and earlier, and CompactLogix 1768-EWEB Version 2.005 and earlier. A remote attacker could send a crafted UDP packet to the SNMP service causing a denial-of-service condition to occur until the affected product is restarted.

Published Mar 27, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-18913: Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send...

Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a malicious DLL to the target. Once the document is opened, it may allow the attacker to take full control of the system from any location within the system. The issue lies in the loading of the shcore.dll and dcomp.dll files: these files are being searched for by the program in the same system-wide directory where the HTML file is executed.

Published Mar 21, 2019 · Updated Aug 5, 2024