LiveActive security incident?Get immediate response
CVE archive

March 2018

Browse CVE records published in March 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1325 matching CVEs · Page 18 of 27.

Unknown · CVSS Not scored

CVE-2018-9145: In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an i...

In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer size. A large size value may lead to a SIGABRT during an attempt at memory allocation. NOTE: some third parties have been unable to reproduce the SIGABRT when using the 4-DataBuf-abort-1 PoC file.

Published Mar 30, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-9110: Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zip...

Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web server process and delete files owned by the account running the web server process. NOTE: this issue exists because of an incomplete fix for CVE-2018-9109.

Published Mar 28, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-9148: Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, whi...

Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory. NOTE: this can be exploited in conjunction with CVE-2018-7171 for remote authentication bypass within a product that uses My Cloud.

Published Mar 30, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8968: An issue was discovered in zzcms 8.2.

An issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg or oldflv parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.

Published Mar 24, 2018 · Updated Aug 5, 2024