LiveActive security incident?Get immediate response
CVE archive

May 2018

Browse CVE records published in May 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1309 matching CVEs · Page 19 of 27.

Unknown · CVSS Not scored

CVE-2018-10350: A SQL injection remote code execution vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x...

A SQL injection remote code execution vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw within the handling of parameters provided to wcs\_bwlists\_handler.php. Authentication is required in order to exploit this vulnerability.

Published May 25, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10477: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit R...

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Chain Index objects. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5396.

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10493: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of...

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of the U3D Final Maximum Resolution attribute. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5426.

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10488: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit R...

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Texture Width structures. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, heap-based buffer. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5420.

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10484: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit R...

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Node objects. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5411.

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10487: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of...

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files embedded inside PDF documents. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5419.

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10476: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of...

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Model Node structures. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5395.

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10491: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit R...

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Bone Weight Modifier structures. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5423.

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10478: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of...

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Texture Coord Dimensions objects. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5397.

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10495: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit R...

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF documents. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5586.

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10474: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit R...

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Shading objects. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5393.

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10481: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of...

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D Texture Resource structures. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5408.

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10482: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of...

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the U3D Texture Image Format object. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5409.

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10485: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of...

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within U3D Texture Height structures. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5412.

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10486: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of...

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of the U3D Image Index. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5418.

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10479: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of...

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Key Frame structures. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5399.

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10473: This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit R...

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D CLOD Base Mesh Continuation structures. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5392.

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10475: This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of...

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D Light Node structures. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5394.

Published May 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10355: An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacke...

An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must first obtain access to the user database on the target system in order to exploit this vulnerability.

Published May 23, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10240: SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can b...

SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-forced by an attacker to obtain the corresponding session cookie and hijack the user's session.

Published May 16, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10251: A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4....

A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 could allow an unauthenticated remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges.

Published May 4, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-10252: An issue was discovered on Actiontec WCB6200Q before 1.1.10.20a devices.

An issue was discovered on Actiontec WCB6200Q before 1.1.10.20a devices. The admin login session cookie is insecurely generated making admin session hijacking possible. When an admin logs in, a session cookie is generated using the time of day rounded to 10ms. Since the web server returns its current time of day in responses, it is possible to step backward through possible session values until a working one is found. Once a working session ID is found, an attacker then has admin control of the device and can add a secondary SSID to create a backdoor to the network.

Published May 14, 2018 · Updated Aug 5, 2024