LiveActive security incident?Get immediate response
CVE archive

June 2018

Browse CVE records published in June 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1447 matching CVEs · Page 11 of 29.

Unknown · CVSS Not scored

CVE-2018-20523: Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows cont...

Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.

Published Jun 7, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-20468: An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0.

An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" that are vulnerable to CSV injection. An attacker can embed Excel formulas inside an automation script that, when exported after execution, results in code execution.

Published Jun 17, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-20135: Samsung Galaxy Apps before 4.4.01.7 allows modification of the hostname used for load balancing on installa...

Samsung Galaxy Apps before 4.4.01.7 allows modification of the hostname used for load balancing on installations of applications through a man-in-the-middle attack. An attacker may trick Galaxy Apps into using an arbitrary hostname for which the attacker can provide a valid SSL certificate, and emulate the API of the app store to modify existing apps at installation time. The specific flaw involves an HTTP method to obtain the load-balanced hostname that enforces SSL only after obtaining a hostname from the load balancer, and a missing app signature validation in the application XML. An attacker can exploit this vulnerability to achieve Remote Code Execution on the device. The Samsung ID is SVE-2018-12071.

Published Jun 7, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-20091: An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2.

An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any authenticated user to run arbitrary queries against CDSW's internal database. The database contains user contact information, encrypted CDSW passwords (in the case of local authentication), API keys, and stored Kerberos keytabs.

Published Jun 7, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-19999: The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that...

The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit this vulnerability, an attacker must have local access the the host running Serv-U, and a Serv-U administrator have an active management console session.

Published Jun 7, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-19878: An issue was discovered on Teltonika RTU950 R_31.04.89 devices.

An issue was discovered on Teltonika RTU950 R_31.04.89 devices. The application allows a user to login without limitation. For every successful login request, the application saves a session. A user can re-login without logging out, causing the application to store the session in memory. Exploitation of this vulnerability will increase memory use and consume free space.

Published Jun 19, 2019 · Updated Aug 5, 2024