LiveActive security incident?Get immediate response
CVE archive

May 2018

Browse CVE records published in May 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1309 matching CVEs · Page 16 of 27.

Unknown · CVSS Not scored

CVE-2018-11094: An issue was discovered on Intelbras NCLOUD 300 1.0 devices.

An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authentication. For example, when an HTTP POST request is made to /cgi-bin/ExportSettings.sh, the username, password, and other details are retrieved.

Published May 15, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11105: There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the...

There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "email" (aka wplc_email) input fields to wp-json/wp_live_chat_support/v1/start_chat whenever a malicious attacker would initiate a new chat with an administrator. NOTE: this issue exists because of an incomplete fix for CVE-2018-9864.

Published May 15, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11090: An XSS issue was discovered in MyBiz MyProcureNet 5.0.0.

An XSS issue was discovered in MyBiz MyProcureNet 5.0.0. This vulnerability within "ProxyPage.aspx" allows an attacker to inject malicious client side scripting which will be executed in the browser of users if they visit the manipulated site.

Published May 14, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11098: An issue was discovered in Frog CMS 0.9.5.

An issue was discovered in Frog CMS 0.9.5. There is a file upload vulnerability via the admin/?/plugin/file_manager/upload URI, a similar issue to CVE-2014-4912.

Published May 15, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11101: Open Whisper Signal (aka Signal-Desktop) through 1.10.1 allows XSS via a resource location specified in an...

Open Whisper Signal (aka Signal-Desktop) through 1.10.1 allows XSS via a resource location specified in an attribute of a SCRIPT, IFRAME, or IMG element, leading to JavaScript execution after a reply, a different vulnerability than CVE-2018-10994. The attacker needs to send HTML code directly as a message, and then reply to that message to trigger this vulnerability. The Signal-Desktop software fails to sanitize specific HTML elements that can be used to inject HTML code into remote chat windows when replying to an HTML message. Specifically the IMG and IFRAME elements can be used to include remote or local resources. For example, the use of an IFRAME element enables full code execution, allowing an attacker to download/upload files, information, etc. The SCRIPT element was also found to be injectable. On the Windows operating system, the CSP fails to prevent remote inclusion of resources via the SMB protocol. In this case, remote execution of JavaScript can be achieved by referencing the script on an SMB share within an IFRAME element, for example: <IFRAME src=\\DESKTOP-XXXXX\Temp\test.html> and then replying to it. The included JavaScript code is then executed automatically, without any interaction needed from the user. The vulnerability can be triggered in the Signal-Desktop client by sending a specially crafted message and then replying to it with any text or content in the reply (it doesn't matter).

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11102: An issue was discovered in Libav 12.3.

An issue was discovered in Libav 12.3. A read access violation in the mov_probe function in libavformat/mov.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv.

Published May 15, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11018: An issue was discovered in PbootCMS v1.0.7.

An issue was discovered in PbootCMS v1.0.7. Cross-site request forgery (CSRF) vulnerability in apps/admin/controller/system/RoleController.php allows remote attackers to add administrator accounts via admin.php/role/add.html.

Published May 13, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10998: An issue was discovered in Exiv2 0.26.

An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.

Published May 12, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10992: lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified...

lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by a --proxy-pac-file argument, because the GNU Guile code uses the system Scheme procedure instead of the system* Scheme procedure. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-17523.

Published May 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11004: An issue was discovered in SDcms v1.5.

An issue was discovered in SDcms v1.5. Cross-site request forgery (CSRF) vulnerability in /WWW//app/admin/controller/admincontroller.php allows remote attackers to add administrator accounts via m=admin&c=admin&a=add.

Published May 12, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11003: An issue was discovered in YXcms 1.4.7.

An issue was discovered in YXcms 1.4.7. Cross-site request forgery (CSRF) vulnerability in protected/apps/admin/controller/adminController.php allows remote attackers to delete administrator accounts via index.php?r=admin/admin/admindel.

Published May 12, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10972: An issue was discovered in Free Lossless Image Format (FLIF) 0.3.

An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The TransformPaletteC::process function in transform/palette_C.hpp allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted file.

Published May 10, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10982: An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service...

An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (unexpectedly high interrupt number, array overrun, and hypervisor crash) or possibly gain hypervisor privileges by setting up an HPET timer to deliver interrupts in IO-APIC mode, aka vHPET interrupt injection.

Published May 10, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10989: Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices are distributed by some ISPs with a default pa...

Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices are distributed by some ISPs with a default password of "password" for the admin account that is used over an unencrypted http://192.168.0.1 connection, which might allow remote attackers to bypass intended access restrictions by leveraging access to the local network. NOTE: one or more user's guides distributed by ISPs state "At a minimum, you should set a login password."

Published May 14, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10962: An issue was discovered in Shanghai 2345 Security Guard 3.7.0.

An issue was discovered in Shanghai 2345 Security Guard 3.7.0. 2345MPCSafe.exe, 2345SafeTray.exe, and 2345Speedup.exe allow local users to bypass intended process protections, and consequently terminate processes, because mouse_event is not properly considered.

Published May 10, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10990: On Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices, a logout action does not immediately destr...

On Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices, a logout action does not immediately destroy all state on the device related to the validity of the "credential" cookie, which might make it easier for attackers to obtain access at a later time (e.g., "at least for a few minutes"). NOTE: there is no documentation stating that the web UI's logout feature was supposed to do anything beyond removing the cookie from one instance of a web browser; a client-side logout action is often not intended to address cases where a person has made a copy of a cookie outside of a browser.

Published May 14, 2018 · Updated Aug 5, 2024