LiveActive security incident?Get immediate response
CVE archive

May 2018

Browse CVE records published in May 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1309 matching CVEs · Page 15 of 27.

Unknown · CVSS Not scored

CVE-2018-11326: An issue was discovered in Joomla!

An issue was discovered in Joomla! Core before 3.8.8. Inadequate input filtering leads to a multiple XSS vulnerabilities. Additionally, the default filtering settings could potentially allow users of the default Administrator user group to perform a XSS attack.

Published May 22, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11315: The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84 and below products allows unauthorized access...

The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84 and below products allows unauthorized access via a DNS rebinding attack. This can result in remote device temperature control, as demonstrated by a tstat t_heat request that accesses a device purchased in the Spring of 2018, and sets a home's target temperature to 95 degrees Fahrenheit. This vulnerability might be described as an addendum to CVE-2013-4860.

Published May 20, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11322: An issue was discovered in Joomla!

An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by the webserver.

Published May 22, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11345: An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers...

An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data via the POST parameter filename. This can be used to place attacker controlled code on the file system that can then be executed. Further, the filename parameter is vulnerable to path traversal and allows the attacker to place the file anywhere on the system.

Published May 22, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11319: Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it s...

Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrary code execution via a malicious gcc plugin, if an attacker has write access to a directory that is a parent of the base directory of the project being checked. NOTE: exploitation is more difficult after 3.8.0 because filename prediction may be needed.

Published May 20, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11324: An issue was discovered in Joomla!

An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could create a race condition where a session that was expected to be destroyed would be recreated.

Published May 22, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11328: An issue was discovered in Joomla!

An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could result in an XSS vulnerability.

Published May 22, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11321: An issue was discovered in com_fields in Joomla!

An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option.

Published May 22, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11323: An issue was discovered in Joomla!

An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of user groups with higher permissions.

Published May 22, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11327: An issue was discovered in Joomla!

An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to see the names of tags that were either unpublished or published with restricted view permission.

Published May 22, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11239: An integer overflow in the _transfer function of a smart contract implementation for Hexagon (HXG), an Ethe...

An integer overflow in the _transfer function of a smart contract implementation for Hexagon (HXG), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets by providing a _to argument in conjunction with a large _value argument, as exploited in the wild in May 2018, aka the "burnOverflow" issue.

Published May 19, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11271: Improper authentication can happen on Remote command handling due to inappropriate handling of events in Sn...

Improper authentication can happen on Remote command handling due to inappropriate handling of events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables in MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SM7150, Snapdragon_High_Med_2016, SXR1130

Published May 24, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11212: An issue was discovered in libjpeg 9a and 9d.

An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.

Published May 16, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11242: An issue was discovered in the MakeMyTrip application 7.2.4 for Android.

An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as demonstrated by data/com.makemytrip/databases and data/com.makemytrip/Cache SQLite database files.

Published May 20, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11235: In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2...

In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs "git clone --recurse-submodules" because submodule "names" are obtained from this file, and then appended to $GIT_DIR/modules, leading to directory traversal with "../" in a name. Finally, post-checkout hooks from a submodule are executed, bypassing the intended design in which hooks are not obtained from a remote server.

Published May 30, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11209: An issue was discovered in Z-BlogPHP 2.0.0.

An issue was discovered in Z-BlogPHP 2.0.0. zb_system/cmd.php?act=verify relies on MD5 for the password parameter, which might make it easier for attackers to bypass intended access restrictions via a dictionary or rainbow-table attack. NOTE: the vendor declined to accept this as a valid issue

Published May 16, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11214: An issue was discovered in libjpeg 9a.

An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.

Published May 16, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11213: An issue was discovered in libjpeg 9a.

An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.

Published May 16, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11208: An issue was discovered in Z-BlogPHP 2.0.0.

An issue was discovered in Z-BlogPHP 2.0.0. There is a persistent XSS that allows remote attackers to inject arbitrary web script or HTML into background web site settings via the "copyright information office" field. NOTE: the vendor indicates that the product was not intended to block this type of XSS by a user with the admin privilege

Published May 16, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11132: In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0....

In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs daemonized with root privileges and only allows a set of commands to be executed. A command injection vulnerability exists within this message queue which allows low-privilege users to append arbitrary commands that will be run as root.

Published May 31, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11139: The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 i...

The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbitrary commands on the system. This script is vulnerable to command injection via the unsanitized user input 'TEST_SERVER' sent to the script via the POST method.

Published May 31, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11142: The 'systemui/settings_network.php' and 'systemui/settings_patching.php' scripts in the Quest KACE System M...

The 'systemui/settings_network.php' and 'systemui/settings_patching.php' scripts in the Quest KACE System Management Appliance 8.0.318 are accessible only from localhost. This restriction can be bypassed by modifying the 'Host' and 'X_Forwarded_For' HTTP headers in a POST request. An anonymous user can abuse this vulnerability to execute critical functions without authorization.

Published May 31, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11141: The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Que...

The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Appliance 8.0.318 can be abused to write and delete files respectively via Directory Traversal. Files can be at any location where the 'www' user has write permissions.

Published May 31, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11134: In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0...

In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed that runs with root privileges and only allows a set of commands. One of the available commands allows changing any user's password (including root). A low-privilege user could abuse this feature by changing the password of the 'kace_support' account, which comes disabled by default but has full sudo privileges.

Published May 31, 2018 · Updated Aug 5, 2024