LiveActive security incident?Get immediate response
CVE archive

March 2018

Browse CVE records published in March 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1325 matching CVEs · Page 21 of 27.

Unknown · CVSS Not scored

CVE-2018-8076: ZenMate 1.5.4 for macOS suffers from a type confusion vulnerability within the com.zenmate.chron-xpc Launch...

ZenMate 1.5.4 for macOS suffers from a type confusion vulnerability within the com.zenmate.chron-xpc LaunchDaemon component. The LaunchDaemon implements an XPC service that uses an insecure XPC API for accessing data from an inbound XPC message. This could potentially result in an XPC object of the wrong type being passed as the first argument to the xpc_connection_create_from_endpoint function if controlled by an attacker. In recent versions of macOS and OS X, Apple has implemented an internal check to prevent such XPC API abuse from occurring, thus making this vulnerability only result in a denial of service if exploited by an attacker.

Published Mar 15, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8045: In Joomla!

In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.

Published Mar 14, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-7995: Race condition in the store_int_with_restart() function in arch/x86/kernel/cpu/mcheck/mce.c in the Linux ke...

Race condition in the store_int_with_restart() function in arch/x86/kernel/cpu/mcheck/mce.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (panic) by leveraging root access to write to the check_interval file in a /sys/devices/system/machinecheck/machinecheck<cpu number> directory. NOTE: a third party has indicated that this report is not security relevant

Published Mar 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8000: In PoDoFo 0.9.5, there exists a heap-based buffer overflow vulnerability in PoDoFo::PdfTokenizer::GetNextTo...

In PoDoFo 0.9.5, there exists a heap-based buffer overflow vulnerability in PoDoFo::PdfTokenizer::GetNextToken() in PdfTokenizer.cpp, a related issue to CVE-2017-5886. Remote attackers could leverage this vulnerability to cause a denial-of-service or potentially execute arbitrary code via a crafted pdf file.

Published Mar 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-7998: In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_gen...

In libvips before 8.6.3, a NULL function pointer dereference vulnerability was found in the vips_region_generate function in region.c, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted image file. This occurs because of a race condition involving a failed delayed load and other worker threads.

Published Mar 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-7890: A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 1...

A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredential.do endpoint takes multiple user inputs and validates supplied credentials by accessing a specified system. This endpoint calls several internal classes, and then executes a PowerShell script. If the specified system is OfficeSharePointServer, then the username and password parameters to this script are not validated, leading to Command Injection.

Published Mar 8, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-7886: An issue was discovered in CloudMe 1.11.0.

An issue was discovered in CloudMe 1.11.0. An unauthenticated local attacker that can connect to the "CloudMe Sync" client application listening on 127.0.0.1 port 8888 can send a malicious payload causing a buffer overflow condition. This will result in code execution, as demonstrated by a TCP reverse shell, or a crash. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-6892.

Published Mar 15, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-7750: transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before...

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

Published Mar 13, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-7739: antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the...

antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and password parameters, as demonstrated by a username=>&password=%0a string to the /login URI. This allows obtaining root permissions within the web management console, because the login process uses Java's ProcessBuilder class and a bash script called antsle-auth with insufficient input validation.

Published Mar 6, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-7746: An issue was discovered in Western Bridge Cobub Razor 0.7.2.

An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/channel/modifychannel. For example, with a crafted channel name, stored XSS is triggered during a later /index.php?/manage/channel request by an admin.

Published Mar 7, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-7755: An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kernel throu...

An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kernel through 4.15.7. The floppy driver will copy a kernel pointer to user memory in response to the FDGETPRM ioctl. An attacker can send the FDGETPRM ioctl and use the obtained kernel pointer to discover the location of kernel code and data and bypass kernel security protections such as KASLR.

Published Mar 8, 2018 · Updated Aug 5, 2024