Medium · CVSS 5.4
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.
Published Mar 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
yidashi yii2cmf 2.0 has XSS via the /search q parameter.
Published Mar 12, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Contao before 4.5.7 has XSS in the system log.
Published Mar 16, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow XSS.
Published Mar 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerabilities in version 7.5.7 of Gespage software allow remote attackers to inject arbitrary web script or HTML via the email, passwd, and repasswd parameters to webapp/users/user_reg.jsp.
Published Mar 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A NULL pointer dereference bug in the function ObReferenceObjectByHandle in the Kingsoft Internet Security 9+ kernel driver KWatch3.sys allows local non-privileged users to crash the system via IOCTL 0x80030030.
Published Mar 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
On Samsung mobile devices with N(7.x) software, a buffer overflow in the vision service allows code execution in a privileged process via a large frame size, aka SVE-2017-11165.
Published Mar 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An XXE vulnerability within WireMock before 2.16.0 allows a remote unauthenticated attacker to access local files and internal resources and potentially cause a Denial of Service.
Published Mar 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename action, as demonstrated by renaming an arbitrary file under uploads/userup to a .php file under the web root to achieve PHP code execution. This uses the oldfilename and newfilename parameters.
Published Mar 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
On Samsung mobile devices with N(7.x) software, attackers can install an arbitrary APK in the Secure Folder SD Card area because of faulty validation of a package signature and package name, aka SVE-2017-10932.
Published Mar 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Exiv2 0.26, there is an out-of-bounds read in Exiv2::Internal::binaryToString in image.cpp. It could result in denial of service or information disclosure.
Published Mar 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
Published Mar 31, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribute, aka SVE-2017-10747.
Published Mar 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
WireMock before 2.16.0 contains a vulnerability that allows a remote unauthenticated attacker to access local files beyond the application directory via a specially crafted XML request, aka Directory Traversal.
Published Mar 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
On Samsung mobile devices with M(6.0) and N(7.x) software, a heap overflow in the sensorhub binder service leads to code execution in a privileged process, aka SVE-2017-10991.
Published Mar 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer size. A large size value may lead to a SIGABRT during an attempt at memory allocation. NOTE: some third parties have been unable to reproduce the SIGABRT when using the 4-DataBuf-abort-1 PoC file.
Published Mar 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a crafted .exe file, a different vulnerability than CVE-2018-8821.
Published Mar 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In ImageMagick 7.0.7-24 Q16, there is a heap-based buffer over-read in IsWEBPImageLossless in coders/webp.c.
Published Mar 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.29 and 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_nested_args, demangle_args, do_arg, and do_type.
Published Mar 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web server process and delete files owned by the account running the web server process.
Published Mar 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. NOTE: this product is unrelated to Ignite Realtime Spark.
Published Mar 31, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.
Published Mar 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
On Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software, Gallery allows remote attackers to execute arbitrary code via a BMP file with a crafted resolution, aka SVE-2017-11105.
Published Mar 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandled in a CSV export.
Published Mar 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage and EncodeLabImage functions (coders/tiff.c), which results in a hang (tens of minutes) with a tiny PoC file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tiff file.
Published Mar 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web server process and delete files owned by the account running the web server process. NOTE: this issue exists because of an incomplete fix for CVE-2018-9109.
Published Mar 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory. NOTE: this can be exploited in conjunction with CVE-2018-7171 for remote authentication bypass within a product that uses My Cloud.
Published Mar 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
IBOS 4.4.3 has XSS via a company full name.
Published Mar 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via a value that is mishandled in a CSV export.
Published Mar 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100202d.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on the directional branch predictor, as demonstrated by a pattern history table (PHT), aka BranchScope.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_x86.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402000.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100283c.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402000.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002009.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
aws/resource_aws_iam_user_login_profile.go in the HashiCorp Terraform Amazon Web Services (AWS) provider through v1.12.0 has an inappropriate PRNG algorithm and seeding, which makes it easier for remote attackers to obtain access by leveraging an IAM account that was provisioned with a weak password.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Octopus Deploy 2.0 and later before 2018.3.7, an authenticated user, with variable edit permissions, can scope some variables to targets greater than their permissions should allow. In other words, they can see machines beyond their team's scoped environments.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf10026cc.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_x86.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060cc.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_x86.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060d0.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win7_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060c4.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100284c.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002841.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg or oldflv parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.
Published Mar 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version : 1.02-2.06) devices potentially allows attackers to bypass SharePort Web Access Portal by directly visiting /category_view.php or /folder_view.php.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002003.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100282d.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100282c.
Published Mar 27, 2018 · Updated Aug 5, 2024