Unknown · CVSS Not scored
TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices allow authenticated remote code execution via crafted JSON data because /usr/lib/lua/luci/torchlight/validator.lua does not block various punctuation characters.
Published May 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.php is exploitable using SQL injection.
Published May 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field.
Published May 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI.
Published May 31, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by people registered in the system rather than masking that information.
Published May 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact because sense buffers have different sizes at the CDROM layer and the SCSI layer, as demonstrated by a CDROMREADMODE2 ioctl call.
Published May 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUser/list" that can add an admin account.
Published May 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html.
Published May 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is not checked. This will lead to a denial of service or possibly unspecified other impact.
Published May 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
tificc in Little CMS 2.9 has an out-of-bounds write in the PrecalculatedXFORM function in cmsxform.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerability because the issue is based on an sample program using LIBTIFF and do not apply to the lcms2 library, lcms2 does not depends on LIBTIFF other than to build sample programs, and the issue cannot be reproduced on the lcms2 library.”
Published May 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Naukri Clone Script through 3.0.3 allows Unrestricted Upload of a File with a Dangerous Type in edit_resume_det.php, as demonstrated by changing .docx to .php.
Published May 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Monstra CMS 3.0.4 has a Session Management Issue in the Users tab. A password change at users/1/edit does not invalidate a session that is open in a different browser.
Published May 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
OpenCart through 3.0.2.0 allows directory traversal in the editDownload function in admin\model\catalog\download.php via admin/index.php?route=catalog/download/edit, related to the download_id. For example, an attacker can download ../../config.php.
Published May 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.
Published May 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ngiflib.c in MiniUPnP ngiflib 0.4 has a stack-based buffer overflow in DecodeGifImg.
Published May 31, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The data packets that are sent between the iOS or Android application and the OBD dongle are not encrypted. The combination of this vulnerability with the lack of wireless network protection exposes all transferred car data to the public.
Published May 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A vulnerability allows a phreaking attack on HCL legacy IVR systems that do not use VoIP. These IVR systems rely on various frequencies of audio signals; based on the frequency, certain commands and functions are processed. Since these frequencies are accepted within a phone call, an attacker can record these frequencies and use them for service activations. This is a request-forgery issue when the required series of DTMF signals for a service activation is predictable (e.g., the IVR system does not speak a nonce to the caller). In this case, the IVR system accepts an activation request from a less-secure channel (any loudspeaker in the caller's physical environment) without verifying that the request was intended (it matches a nonce sent over a more-secure channel to the caller's earpiece).
Published May 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html.
Published May 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Liblouis 3.5.0 has a Segmentation fault in lou_logPrint in logging.c.
Published May 31, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ngiflib.c in MiniUPnP ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor.
Published May 31, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A stack exhaustion vulnerability in the search function of dtSearch 7.90.8538.1 and prior allows remote attackers to cause a denial of service condition by sending a specially crafted HTTP request.
Published May 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The vlc_demux_chained_Delete function in input/demux_chained.c in VideoLAN VLC media player 3.0.1 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted .swf file.
Published May 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS.
Published May 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move, xml, remove) that allows attackers to execute arbitrary code if the remove step is skipped, because the attacker can discover a secret temporary directory name (containing 10 random digits) via a directory traversal attack involving language_info['code'].
Published May 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
GifIndexToTrueColor in ngiflib.c in MiniUPnP ngiflib 0.4 has a Segmentation fault.
Published May 31, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
/usr/lib/lua/luci/websys.lua on TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices has a hardcoded zMiVw8Kw0oxKXL0 password.
Published May 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.
Published May 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cockpit 0.5.5 has XSS via a collection, form, or region.
Published May 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.
Published May 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing 1.0. A User can be added with the Admin role.
Published May 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain CrntCode array index is not checked. This will lead to a denial of service or possibly unspecified other impact.
Published May 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.
Published May 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea.
Published May 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Lizard v1.0 and LZ5 v2.0 (the prior release, before the product was renamed), there is an unchecked buffer size during a memcpy in the Lizard_decompress_LIZv1 function (lib/lizard_decompress_liz.h). Remote attackers can leverage this vulnerability to cause a denial of service via a crafted input file, as well as achieve remote code execution.
Published May 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c.
Published May 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The mobi_parse_mobiheader function in read.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.
Published May 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, related to the proto_http.c check_request_for_cacheability function.
Published May 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.
Published May 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The buffer_fill64 function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.
Published May 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that establishes a \\.\pipe\WindscribeService named pipe endpoint that allows the Windscribe VPN process to connect and execute an OpenVPN process or other processes (like taskkill, etc.). There is no validation of the program name before constructing the lpCommandLine argument for a CreateProcess call. An attacker can run any malicious process with SYSTEM privileges through this named pipe.
Published May 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The OBD port is used to receive measurement data and debug information from the car. This on-board diagnostics feature can also be used to send commands to the car (different for every vendor / car product line / car). No authentication is needed, which allows attacks from the local Wi-Fi network.
Published May 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0.
Published May 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= URI, as demonstrated by adding a new quotation.
Published May 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab. A password change at admin/index.php?id=users&action=edit&user_id=1 does not invalidate a session that is open in a different browser.
Published May 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Vgate iCar 2 Wi-Fi OBD2 Dongle devices. The dongle opens an unprotected wireless LAN that cannot be configured with encryption or a password. This enables anyone within the range of the WLAN to connect to the network without authentication.
Published May 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Monstra CMS 3.0.4 has Reflected XSS during Login (i.e., the login parameter to admin/index.php).
Published May 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product.
Published May 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The mobi_get_kf8boundary_seqnumber function in util.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.
Published May 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html.
Published May 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).
Published May 25, 2018 · Updated Aug 5, 2024