LiveActive security incident?Get immediate response
CVE archive

April 2018

Browse CVE records published in April 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1687 matching CVEs · Page 21 of 34.

Unknown · CVSS Not scored

CVE-2018-10361: An issue was discovered in KTextEditor 5.34.0 through 5.45.0.

An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper service (as utilized in the Kate text editor) can allow other unprivileged users on the local system to gain root privileges. The attack occurs when one user (who has an unprivileged account but is also able to authenticate as root) writes a text file using Kate into a directory owned by a another unprivileged user. The latter unprivileged user conducts a symlink attack to achieve privilege escalation.

Published Apr 25, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10311: A vulnerability was discovered in WUZHI CMS 4.1.0.

A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f=index&v=add URI.

Published Apr 24, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10299: An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem C...

An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), the Ethereum ERC20 token used in the Beauty Chain economic system, allows attackers to accomplish an unauthorized increase of digital assets by providing two _receivers arguments in conjunction with a large _value argument, as exploited in the wild in April 2018, aka the "batchOverflow" issue.

Published Apr 23, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10237: Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to cond...

Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.

Published Apr 26, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10238: bvlc.c in skarg BACnet Protocol Stack bacserv 0.9.1 and 0.8.5 is affected by a Buffer Overflow because of a...

bvlc.c in skarg BACnet Protocol Stack bacserv 0.9.1 and 0.8.5 is affected by a Buffer Overflow because of a lack of packet-size validation. The affected component is bacserv BACnet/IP BVLC forwarded NPDU. The function bvlc_bdt_forward_npdu() calls bvlc_encode_forwarded_npdu() which copies the content from the request into a local in the bvlc_bdt_forward_npdu() stack frame and clobbers the canary. The attack vector is: A BACnet/IP device with BBMD enabled based on this library connected to IP network. The fixed version is: 0.8.6.

Published Apr 20, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10286: The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin crede...

The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the responses to certain HTTP POST requests. In order to be able to see the credentials in cleartext, an attacker needs to be authenticated.

Published Apr 22, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10235: POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diy\module\member\controllers\a...

POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diy\module\member\controllers\admin\Setting.php 'index' function because an attacker can control the value of $cache['setting']['ucssocfg'] in diy\module\member\models\Member_model.php and write this code into the api/ucsso/config.php file.

Published Apr 19, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10201: An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11.

An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible to read arbitrary files outside the root directory of the web server. This vulnerability could be exploited remotely by a crafted URL without credentials, with .../ or ...\ or ..../ or ....\ as a directory-traversal pattern to TCP port 8667.

Published Apr 20, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10194: The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscrip...

The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.

Published Apr 18, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10172: 7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRight...

7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to add the SeLockMemoryPrivilege privilege to the user's account, which makes it easier for attackers to bypass intended access restrictions by using this privilege in the context of a sandboxed process. Note: This has been disputed by 3rd parties who argue this is a valid feature of Windows.

Published Apr 16, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10221: An issue was discovered in WUZHI CMS V4.1.0.

An issue was discovered in WUZHI CMS V4.1.0. There is a persistent XSS vulnerability that can steal the administrator cookies via the tag[tag] parameter to the index.php?m=tags&f=index&v=add&&_su=wuzhicms URI. After a website editor (whose privilege is lower than the administrator) logs in, he can add a new TAGS with the XSS payload.

Published Apr 19, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10183: An issue was discovered in BigTree 4.2.22.

An issue was discovered in BigTree 4.2.22. There is cross-site scripting (XSS) in /core/inc/lib/less.php/test/index.php because of a $_SERVER['REQUEST_URI'] echo, as demonstrated by the dir parameter in a file=charsets action.

Published Apr 17, 2018 · Updated Aug 5, 2024