Unknown · CVSS Not scored
There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack.
Published May 6, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.
Published May 16, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.
Published May 5, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary code via crafted packets.
Published May 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
Published May 5, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Axublog 1.1.0 allows remote Code Execution as demonstrated by injection of PHP code (contained in the webkeywords parameter) into the cmsconfig.php file.
Published May 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Owned smart contract implementation for Aurora DAO (AURA), an Ethereum ERC20 token, allows attackers to acquire contract ownership because the setOwner function is declared as public. An attacker can then conduct a lockBalances() denial of service attack.
Published May 9, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility.
Published May 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.
Published May 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An integer overflow in the transferMulti function of a smart contract implementation for Social Chain (SCA), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets, aka the "multiOverflow" issue.
Published May 10, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.
Published May 16, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.
Published May 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 allow reading the configuration file by an unauthenticated user.
Published May 17, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Cylance CylancePROTECT before 1470, an unprivileged local user can obtain SYSTEM privileges because users have Modify access to the %PROGRAMFILES%\Cylance\Desktop\log folder, the CyUpdate process grants users Modify access to new files created in this folder, and a new file can be a symlink chain to a pathname of an arbitrary DLL that CyUpdate uses.
Published May 4, 2018 · Updated Aug 5, 2024
Critical · CVSS 9.8
An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without any authentication using "anonymous" access that is automatically created. Once logged in, a misconfiguration present by default (auto-deployment) permits an anonymous user to deploy a malicious .war file, leading to remote code execution. NOTE: the vendor indicates that anonymous access is not available in the default installation; however, it remains optional because there are several use cases for it, including development environments and network architectures that have a proxy server for access control to the WildFly server
Published May 9, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Vesta Control Panel 0.9.8-20. There is Reflected XSS via $_REQUEST['path'] to the view/file/index.php URI, which can lead to remote PHP code execution via vectors involving a file_put_contents call in web/upload/UploadHandler.php.
Published May 6, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file.
Published May 2, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.
Published May 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.
Published May 13, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
Published May 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmap.c because the device and devno arrays are too small, as demonstrated by an invalid free when using the btt program with a crafted file.
Published May 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successfully access the server without authentication. NOTE: the Security Realms documentation in the product's Admin Guide indicates that "without a security realm reference" implies "effectively unsecured." The vendor explicitly supports these unsecured configurations because they have valid use cases during development
Published May 9, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the lzma_decompress_buf function of stream.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
Published May 2, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
Published May 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Z-BlogPHP 1.5.2 has a stored Cross Site Scripting Vulnerability exploitable by an administrator who navigates to "Web site settings --> Basic setting --> Website title" and enters an XSS payload via the zb_system/cmd.php ZC_BLOG_NAME parameter. NOTE: the vendor disputes the security relevance, noting it is "just a functional bug.
Published May 2, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.
Published May 2, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Owned smart contract implementation for Aurora IDEX Membership (IDXM), an Ethereum ERC20 token, allows attackers to acquire contract ownership because the setOwner function is declared as public. A new owner can subsequently modify variables.
Published May 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
Published May 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
Published May 10, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
D-Link DIR-601 A1 1.02NA devices do not require the old password for a password change, which occurs in cleartext.
Published May 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
Published May 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
Published May 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
SaferVPN 4.2.5 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "SaferVPN.Service" service. The "SaferVPN.Service" service executes "openvpn.exe" using OpenVPN config files located within the current user's %LOCALAPPDATA%\SaferVPN\OvpnConfig directory. An authenticated attacker may modify these configuration files to specify a dynamic library plugin that should run for every new VPN connection attempt. This plugin will execute code in the context of the SYSTEM user.
Published May 2, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-config/config.php contains a function called TestConfig() that calls the vulnerable function eval().
Published May 2, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.
Published May 1, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Octopus Deploy 3.4.x before 2018.4.7, an authenticated user is able to view/update/save variable values within the Tenant Variables area for Environments that do not exist within their associated Team scoping. This occurs in situations where this authenticated user also belongs to multiple teams, where one of the Teams has the VariableEdit permission or VariableView permissions for the Environment.
Published May 1, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
XSS exists in Flexense DiskPulse Enterprise from v10.4 to v10.7.
Published May 2, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
XSS exists in Flexense DiskSavvy Enterprise from v10.4 to v10.7.
Published May 2, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An XSS in Flexense SyncBreeze affects all versions (tested from SyncBreeze Enterprise from v10.1 to v10.7).
Published May 2, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. Incorrect validation of the "old password" field in the change password form allows an attacker to bypass validation of this field.
Published May 2, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. File upload functionality allows any users authenticated on the web interface to upload files containing code to the web root, allowing these files to be executed as root.
Published May 2, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Clod Progressive Mesh objects. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5410.
Published May 17, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPEG images embedded inside U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5422.
Published May 17, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Meross MSS110 devices through 1.1.24 contain an unauthenticated admin.htm administrative interface.
Published May 2, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D 3DView objects. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5493.
Published May 17, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
error.php in ILIAS 5.2.x through 5.3.x before 5.3.4 allows XSS via the text of a PDO exception.
Published May 18, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Clod Progressive Mesh Declaration structures. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5421.
Published May 17, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Clod Progressive Mesh Continuation structures. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5424.
Published May 17, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the U3D Node Name buffer. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5401.
Published May 17, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
XSS exists in Flexense VX Search Enterprise from v10.1.12 to v10.7.
Published May 2, 2018 · Updated Aug 5, 2024