Unknown · CVSS Not scored
ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input.
Published Apr 10, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to cause a denial of service (stack exhaustion), related to the QPDFObjectHandle and QPDF_Dictionary classes, because nesting in direct objects is not restricted.
Published Apr 10, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a user account via index.php?m=member&f=index&v=add.
Published Apr 10, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Gxlcms QY v1.0.0713, the upload function in Lib\Lib\Action\Admin\UploadAction.class.php allows remote attackers to execute arbitrary PHP code by first using an Admin-Admin-Configsave request to change the config[upload_class] value from jpg,gif,png,jpeg to jpg,gif,png,jpeg,php and then making an Admin-Upload-Upload request.
Published Apr 7, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote attackers to inject arbitrary web script through a crafted IMG element.
Published Apr 19, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in idreamsoft iCMS through 7.0.7. SQL injection exists via the pid array parameter in an admincp.php?app=tag&do=save&frame=iPHP request.
Published Apr 10, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
util.c in runV 1.0.0 for Docker mishandles a numeric username, which allows attackers to obtain root access by leveraging the presence of an initial numeric value on an /etc/passwd line, and then issuing a "docker exec" command with that value in the -u argument, a similar issue to CVE-2016-3697.
Published Apr 9, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in idreamsoft iCMS through 7.0.7. CSRF exists in admincp.php, as demonstrated by adding an article via an app=article&do=save&frame=iPHP request.
Published Apr 10, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serialized .NET object in an Authorization HTTP header.
Published Apr 12, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in idreamsoft iCMS through 7.0.7. XSS exists via the nickname field in an admincp.php?app=user&do=save&frame=iPHP request.
Published Apr 10, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor.
Published Apr 18, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=core&f=power&v=add.
Published Apr 10, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Etherpad Lite before 1.6.4 is exploitable for admin access.
Published Apr 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.
Published Apr 9, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" screen).
Published Apr 9, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Botan 1.11.32 through 2.x before 2.6.0. An off-by-one error when processing malformed TLS-CBC ciphertext could cause the receiving side to include in the HMAC computation exactly 64K bytes of data following the record buffer, aka an over-read. The MAC comparison will subsequently fail and the connection will be closed. This could be used for denial of service. No information leak occurs.
Published Apr 12, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The caml_ba_deserialize function in byterun/bigarray.c in the standard library in OCaml 4.06.0 has an integer overflow which, in situations where marshalled data is accepted from an untrusted source, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted object.
Published Apr 6, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
Published Apr 7, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and directories outside the web-site installation directory, and determine whether a file has contents matching a specified checksum. The attack uses an admin/checksum.php?__c= request.
Published Apr 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plugin.move2archive request) to perform an MX (IMAP) injection attack by placing an IMAP command after a %0d%0a sequence. NOTE: this is less easily exploitable in 1.3.4 and later because of a Same Origin Policy protection mechanism.
Published Apr 7, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execute arbitrary PHP code by placing this code into a template.
Published Apr 7, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in save.php in MetInfo 6.0 allows remote attackers to inject arbitrary web script or HTML via the webname or weburl parameter.
Published Apr 10, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feature via certain rapid sequences of actions that include app opening, clicking on cancel, and using the home button.
Published Apr 10, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field that reveals a core/library/weixin.class.php pathname.
Published Apr 10, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The export function in libavfilter/vf_signature.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via a long filename.
Published Apr 7, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message.
Published Apr 12, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execute arbitrary SQL statements via the sql parameter. Consequently, an attacker can execute arbitrary PHP code by placing it after a <?php substring, and then using INTO OUTFILE with a .php filename.
Published Apr 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in MagniComp SysInfo before 10-H82 if setuid root (the default). This vulnerability allows any local user on a Linux/UNIX system to run SysInfo and obtain a root shell, which can be used to compromise the local system.
Published Apr 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code.
Published Apr 7, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
register.jsp in Coremail XT3.0 allows stored XSS, as demonstrated by the third form field to a URI under register/, a different vulnerability than CVE-2015-6942.
Published Apr 7, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in zzcms 8.2. user/adv.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter. This can be leveraged for database access by deleting install.lock.
Published Apr 7, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the Kerberos dissector could crash. This was addressed in epan/dissectors/packet-kerberos.c by ensuring a nonzero key length.
Published Apr 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/oids.c has a memory leak.
Published Apr 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.4.0 to 2.4.5, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by preserving valid data sources.
Published Apr 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-tn3270.c has a memory leak.
Published Apr 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Exiv2 0.26, an assertion failure in BigTiffImage::readData in bigtiffimage.cpp results in an abort.
Published Apr 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-smb2.c has a memory leak.
Published Apr 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Main_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.384_10007; RT-N18U devices before 3.0.0.4.382.39935; RT-AC87U and RT-AC3200 devices before 3.0.0.4.382.50010; and RT-AC5300 devices before 3.0.0.4.384.20287 allows OS command injection via the pingCNT and destIP fields of the SystemCmd variable.
Published Apr 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the login page and execute remote code on the operating system.
Published Apr 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.
Published Apr 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
Published Apr 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Exiv2 0.26, an out-of-bounds read in IptcData::printStructure in iptc.c could result in a crash or information leak, related to the "== 0x1c" case.
Published Apr 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.
Published Apr 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.
Published Apr 5, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the MP4 dissector could crash. This was addressed in epan/dissectors/file-mp4.c by restricting the box recursion depth.
Published Apr 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.
Published Apr 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the ADB dissector could crash with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-adb.c by checking for a length inconsistency.
Published Apr 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to an unauthenticated request.
Published Apr 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-lapd.c has a memory leak.
Published Apr 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-nbap.c by prohibiting the self-linking of DCH-IDs.
Published Apr 4, 2018 · Updated Aug 5, 2024