LiveActive security incident?Get immediate response
CVE archive

April 2018

Browse CVE records published in April 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1687 matching CVEs · Page 25 of 34.

Unknown · CVSS Not scored

CVE-2018-8941: Diagnostics functionality on D-Link DSL-3782 devices with firmware EU v.

Diagnostics functionality on D-Link DSL-3782 devices with firmware EU v. 1.01 has a buffer overflow, allowing authenticated remote attackers to execute arbitrary code via a long Addr value to the 'set Diagnostics_Entry' function in an HTTP request, related to /userfs/bin/tcapi.

Published Apr 3, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8778: In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an a...

In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-read in the String#unpack method, resulting in a massive and controlled information disclosure.

Published Apr 3, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8826: ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4...

ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N600 routers with firmware before 3.0.0.4.380.10446; RT-AC55U and RT-AC55UHP routers with firmware before 3.0.0.4.382.50276; RT-AC86U and RT-AC2900 routers with firmware before 3.0.0.4.384.20648; and possibly other RT-series routers allow remote attackers to execute arbitrary code via unspecified vectors.

Published Apr 20, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8117: A security feature bypass vulnerability exists in the Microsoft Wireless Keyboard 850 which could allow an...

A security feature bypass vulnerability exists in the Microsoft Wireless Keyboard 850 which could allow an attacker to reuse an AES encryption key to send keystrokes to other keyboard devices or to read keystrokes sent by other keyboards for the affected devices, aka "Microsoft Wireless Keyboard 850 Security Feature Bypass Vulnerability." This affects Microsoft Wireless Keyboard 850.

Published Apr 12, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8116: A denial of service vulnerability exists in the way that Windows handles objects in memory, aka "Microsoft...

A denial of service vulnerability exists in the way that Windows handles objects in memory, aka "Microsoft Graphics Component Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

Published Apr 12, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8072: An issue was discovered on EDIMAX IC-3140W through 3.06, IC-5150W through 3.09, and IC-6220DC through 3.06...

An issue was discovered on EDIMAX IC-3140W through 3.06, IC-5150W through 3.09, and IC-6220DC through 3.06 devices. The ipcam_cgi binary contains a stack-based buffer overflow that is possible to trigger from a remote unauthenticated /camera-cgi/public/getsysyeminfo.cgi?action=VALUE_HERE HTTP request: if the VALUE_HERE length is more than 0x400 (1024), it is possible to overwrite other values located on the stack due to an incorrect use of the strcpy() function.

Published Apr 26, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-7930: The Near Field Communication (NFC) module in Mate 9 Huawei mobile phones with the versions before MHA-L29B...

The Near Field Communication (NFC) module in Mate 9 Huawei mobile phones with the versions before MHA-L29B 8.0.0.366(C567) has an information leak vulnerability due to insufficient validation on data transfer requests. When an affected mobile phone sends files to an attacker's mobile phone using the NFC function, the attacker can obtain arbitrary files from the mobile phone, causing information leaks.

Published Apr 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-7901: RCS module in Huawei ALP-AL00B smart phones with software versions earlier than 8.0.0.129, BLA-AL00B smart...

RCS module in Huawei ALP-AL00B smart phones with software versions earlier than 8.0.0.129, BLA-AL00B smart phones with software versions earlier than 8.0.0.129 has a remote control vulnerability. An attacker can trick a user to install a malicious application. When the application connects with RCS for the first time, it needs user to manually click to agree. In addition, the attacker needs to obtain the key that RCS uses to authenticate the application. Successful exploitation may cause the attacker to control keyboard remotely.

Published Apr 30, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-7758: A denial of service vulnerability exists in Schneider Electric's MiCOM Px4x (P540 range excluded) with lega...

A denial of service vulnerability exists in Schneider Electric's MiCOM Px4x (P540 range excluded) with legacy Ethernet board, MiCOM P540D Range with Legacy Ethernet Board, and MiCOM Px4x Rejuvenated could lose network communication in case of TCP/IP open requests on port 20000 (DNP3oE) if an older TCI/IP session is still open with identical IP address and port number.

Published Apr 18, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-7669: An issue was discovered in Sitecore Sitecore.NET 8.1 rev.

An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application is vulnerable to a directory traversal attack, allowing an attacker to access arbitrary files from the host Operating System using a sitecore/shell/default.aspx?xmlcontrol=LogViewerDetails&file= URI. Validation is performed to ensure that the text passed to the 'file' parameter correlates to the correct log file directory. This filter can be bypassed by including a valid log filename and then appending a traditional 'dot dot' style attack.

Published Apr 27, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-7539: On Appear TV XC5000 and XC5100 devices with firmware 3.26.217, it is possible to read OS files with a speci...

On Appear TV XC5000 and XC5100 devices with firmware 3.26.217, it is possible to read OS files with a specially crafted HTTP request (such as GET /../../../../../../../../../../../../etc/passwd) to the web server (fuzzd/0.1.1) running the Maintenance Center on port TCP/8088. This can lead to full compromise of the device.

Published Apr 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-7465: An XSS issue was discovered in VirtueMart before 3.2.14.

An XSS issue was discovered in VirtueMart before 3.2.14. All the textareas in the backend of the plugin can be closed by simply adding </textarea> to the value and saving the product/config. By editing back the product/config, the editor's browser will execute everything after the </textarea>, leading to a possible XSS.

Published Apr 26, 2018 · Updated Aug 5, 2024

High · CVSS 7.7

CVE-2018-7340: Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal

Duo Network Gateway 1.2.9 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.

Published Apr 17, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-7246: A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Ne...

A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. he integrated web server (Port 80/443/TCP) of the affected devices could allow remote attackers to discover an administrative account. If default on device, it is not using a SSL in settings and if multiple request of the page "Access Control" (IP-address device/ups/pas_cont.htm) account data will be sent in cleartext

Published Apr 18, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-7243: An authorization bypass vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Tran...

An authorization bypass vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to get a full access to device, bypassing the authorization system.

Published Apr 18, 2018 · Updated Aug 5, 2024