LiveActive security incident?Get immediate response
CVE archive

May 2018

Browse CVE records published in May 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1309 matching CVEs · Page 22 of 27.

Unknown · CVSS Not scored

CVE-2018-8168: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize...

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8149, CVE-2018-8155, CVE-2018-8156.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8155: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize...

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8149, CVE-2018-8156, CVE-2018-8168.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8133: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in...

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0943, CVE-2018-8130, CVE-2018-8145, CVE-2018-8177.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8167: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improp...

An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka "Windows Common Log File System Driver Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8145: An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory,...

An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-0943, CVE-2018-8130, CVE-2018-8133, CVE-2018-8177.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8177: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in...

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-0943, CVE-2018-8130, CVE-2018-8133, CVE-2018-8145.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8130: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in...

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0943, CVE-2018-8133, CVE-2018-8145, CVE-2018-8177.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8164: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handl...

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8120, CVE-2018-8124, CVE-2018-8166.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8149: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize...

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8155, CVE-2018-8156, CVE-2018-8168.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8127: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory...

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8141.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8136: A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka "Window...

A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8128: A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory...

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE-2018-0953, CVE-2018-0954, CVE-2018-0955, CVE-2018-1022, CVE-2018-8114, CVE-2018-8122, CVE-2018-8137, CVE-2018-8139.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8156: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize...

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint, Microsoft Project Server. This CVE ID is unique from CVE-2018-8149, CVE-2018-8155, CVE-2018-8168.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8124: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handl...

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8120, CVE-2018-8164, CVE-2018-8166.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8114: A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory...

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE-2018-0953, CVE-2018-0954, CVE-2018-0955, CVE-2018-1022, CVE-2018-8122, CVE-2018-8128, CVE-2018-8137, CVE-2018-8139.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8122: A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory...

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE-2018-0953, CVE-2018-0954, CVE-2018-0955, CVE-2018-1022, CVE-2018-8114, CVE-2018-8128, CVE-2018-8137, CVE-2018-8139.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8137: A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory...

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE-2018-0953, CVE-2018-0954, CVE-2018-0955, CVE-2018-1022, CVE-2018-8114, CVE-2018-8122, CVE-2018-8128, CVE-2018-8139.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8139: A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory...

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE-2018-0953, CVE-2018-0954, CVE-2018-0955, CVE-2018-1022, CVE-2018-8114, CVE-2018-8122, CVE-2018-8128, CVE-2018-8137.

Published May 9, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8060: HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send an IOCTL to the devic...

HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send an IOCTL to the device driver. If input and/or output buffer pointers are NULL or if these buffers' data are invalid, a NULL/invalid pointer access occurs, resulting in a Windows kernel panic aka Blue Screen. This affects IOCTLs higher than 0x85FE2600 with the HWiNFO32 symbolic device name.

Published May 10, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-8014: The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0...

The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.

Published May 16, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-7941: Huawei iBMC V200R002C60 have an authentication bypass vulnerability.

Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft specific messages to upload authentication certificate to the affected products. Due to improper validation of the upload authority, successful exploit may cause privilege elevation.

Published May 10, 2018 · Updated Aug 5, 2024