LiveActive security incident?Get immediate response
CVE archive

May 2018

Browse CVE records published in May 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1309 matching CVEs · Page 17 of 27.

Unknown · CVSS Not scored

CVE-2018-10828: An issue was discovered in Alps Pointing-device Driver 10.1.101.207.

An issue was discovered in Alps Pointing-device Driver 10.1.101.207. ApMsgFwd.exe allows the current user to map and write to the "ApMsgFwd File Mapping Object" section. ApMsgFwd.exe uses the data written to this section as arguments to functions. This causes a denial of service condition when invalid pointers are written to the mapped section. This driver has been used with Dell, ThinkPad, and VAIO devices.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10806: An issue was discovered in Frog CMS 0.9.5.

An issue was discovered in Frog CMS 0.9.5. There is a reflected Cross Site Scripting Vulnerability via the file[current_name] parameter to the admin/?/plugin/file_manager/rename URI. This can be used in conjunction with CSRF.

Published May 8, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10831: Z-NOMP before 2018-04-05 has an incorrect Equihash solution verifier that allows attackers to spoof mining...

Z-NOMP before 2018-04-05 has an incorrect Equihash solution verifier that allows attackers to spoof mining shares, as demonstrated by providing a solution with {x1=1,x2=1,x3=1,...,x512=1} to bypass this verifier for any blockheader. This originally affected (for example) the Bitcoin Gold and Zcash cryptocurrencies, and continued to be exploited in the wild in May 2018 against smaller cryptocurrencies.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10645: Golden Frog VyprVPN 2.12.1.8015 for Windows suffers from a SYSTEM privilege escalation vulnerability throug...

Golden Frog VyprVPN 2.12.1.8015 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "VyprVPN" service. This service establishes a NetNamedPipe endpoint that allows applications to connect and call publicly exposed methods. The "SetProperty" method allows an attacker to configure the "AdditionalOpenVpnParameters" property and control the OpenVPN command line. Using the OpenVPN "plugin" parameter, an attacker may specify a dynamic library plugin that should run for every new VPN connection attempt. This plugin will execute code in the context of the SYSTEM user. This attack may be conducted using "VyprVPN Free" account credentials and the VyprVPN Desktop Client.

Published May 2, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10646: CyberGhost 6.5.0.3180 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "CG6...

CyberGhost 6.5.0.3180 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "CG6Service" service. This service establishes a NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "ConnectToVpnServer" method accepts a "connectionParams" argument that provides attacker control of the OpenVPN command line. An attacker can specify a dynamic library plugin that should run for every new VPN connection attempt. This plugin will execute code in the context of the SYSTEM user.

Published May 2, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10832: ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack.

ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files, both XML-based, which are vulnerable to XXE injection. Sending a crafted .xmpp or .xmpa file to a user, when opened/imported in ModbusPal, will return the contents of any local files to a remote attacker.

Published May 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10795: Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files...

Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment via a browser/liferay/browser.html?Type= or html/js/editor/fckeditor/editor/filemanager/browser/liferay/browser.html URI. NOTE: the vendor disputes this issue because file upload is an expected feature, subject to Role Based Access Control checks where only authenticated users with proper permissions can upload files

Published May 7, 2018 · Updated Aug 5, 2024