Unknown · CVSS Not scored
A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web domains.
Published Jun 4, 2019 · Updated Oct 25, 2024
Unknown · CVSS Not scored
A local file vulnerability exists in the F5 BIG-IP Configuration utility on versions 13.0.0, 12.1.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 that exposes files containing F5-provided data only and do not include any configuration data, proxied traffic, or other potentially sensitive customer data.
Published Jun 1, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON).
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite loop when handling corrupt RAR files.
Published Jun 14, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
An issue was discovered on Momentum Axel 720P 5.1.8 devices. The root password can be obtained in cleartext by issuing the command 'showKey' from the root CLI. This password may be the same on all devices
Published Jun 12, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcP_message_default in proto.c.
Published Jun 27, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not validate app GUID structure in requests. A remote authenticated malicious user knowing the GUID of an app may construct malicious requests to read from or write to the logs of that app.
Published Jun 6, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability in the rich text editor that can add an IFRAME element. This might be used in a DoS attack if a referenced remote URL is refreshed at a rapid rate.
Published Jun 2, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to randomness (i.e., uninitialized memory) which supplementary groups are actually being set while lowering privileges.
Published Jun 21, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by triggering a large pAlphaBlend->cbBitsSrc value.
Published Jun 28, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
Published Jun 1, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
An issue was discovered on Momentum Axel 720P 5.1.8 devices. A password of EHLGVG is hard-coded for the root and admin accounts, which makes it easier for physically proximate attackers to login at the console.
Published Jun 13, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
index.php?action=createaccount in Ximdex 4.0 has XSS via the sname or fname parameter.
Published Jun 5, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
U-Boot contains a CWE-20: Improper Input Validation vulnerability in Verified boot signature validation that can result in Bypass verified boot. This attack appear to be exploitable via Specially crafted FIT image and special device memory functionality.
Published Jun 26, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).
Published Jun 18, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow can occur In the WLAN driver if the pmkid_count value is larger than the PMKIDCache size in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
Published Jun 6, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to it, which allows a malicious user to read content of any file with known path.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not handle errors thrown while constructing certain http requests. A remote authenticated user may construct malicious requests to cause the traffic controller to leave dangling TCP connections, which could cause denial of service.
Published Jun 6, 2018 · Updated Sep 17, 2024
High · CVSS 7.1
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.
Published Jun 17, 2019 · Updated Sep 17, 2024
Unknown · CVSS Not scored
While sending a probe request indication in lim_send_sme_probe_req_ind() in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a buffer overflow can occur.
Published Jun 6, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
A server-side request forgery vulnerability exists in Jenkins URLTrigger Plugin 0.41 and earlier in URLTrigger.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
Published Jun 26, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image.
Published Jun 18, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilename, which allows a malicious user to read content of any file with known path.
Published Jun 7, 2018 · Updated Sep 17, 2024
Medium · CVSS 6.5
RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulnerability. A malicious Operations Console administrator could potentially exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console administrators open the affected page, the injected scripts could potentially be executed in their browser.
Published Jun 21, 2018 · Updated Sep 17, 2024
Medium · CVSS 5.9
IBM WebSphere MQ 8.0 and 9.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL certificate. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 142598.
Published Jun 27, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
library/DBTech/Security/Action/Sessions.php in DragonByte vBSecurity 3.x through 3.3.0 for vBulletin 3 and vBulletin 4 allows self-XSS via $session['user_agent'] in the "Login Sessions" feature.
Published Jun 19, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
A vulnerability has been identified in SCALANCE M875 (All versions). An attacker with access to the local file system might obtain passwords for administrative users. Successful exploitation requires read access to files on the local file system. A successful attack could allow an attacker to obtain administrative passwords. At the time of advisory publication no public exploitation of this security vulnerability was known.
Published Jun 26, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
A exposure of sensitive information vulnerability exists in Jenkins Openstack Cloud Plugin 2.35 and earlier in BootSource.java, InstancesToRun.java, JCloudsCleanupThread.java, JCloudsCloud.java, JCloudsComputer.java, JCloudsPreCreationThread.java, JCloudsRetentionStrategy.java, JCloudsSlave.java, JCloudsSlaveTemplate.java, LauncherFactory.java, OpenstackCredentials.java, OpenStackMachineStep.java, SlaveOptions.java, SlaveOptionsDescriptor.java that allows attackers with Overall/Read access to Jenkins to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins, and to cause Jenkins to submit HTTP requests to attacker-specified URLs.
Published Jun 26, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
xowl/request.php in Ximdex 4.0 has XSS via the content parameter.
Published Jun 13, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a specially crafted link.
Published Jun 18, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transaction and block validator allowing a single node to sign a transaction and/or block multiple times, each with a random nonce, and have other validating nodes accept them as separate valid signatures.
Published Jun 1, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Under certain conditions, on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.6.1 HF2-11.6.3.1, virtual servers configured with Client SSL or Server SSL profiles which make use of network hardware security module (HSM) functionality are exposed and impacted by this issue.
Published Jun 1, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
RSA Web Threat Detection versions prior to 6.4, contain an SQL injection vulnerability in the Administration and Forensics applications. An authenticated malicious user with low privileges could potentially exploit this vulnerability to execute SQL commands on the back-end database to gain unauthorized access to the tool's monitoring and user information by supplying specially crafted input data to the affected application.
Published Jun 5, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests which allows a man in the middle to modify or view traffic.
Published Jun 18, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
On F5 BIG-IP 13.0.0, 12.0.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, when processing DIAMETER transactions with carefully crafted attribute-value pairs, TMM may crash.
Published Jun 1, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly.
Published Jun 13, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filenames.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script via $_FILE in /webmasterst/general.php, as demonstrated by a .php file with the image/jpeg content type.
Published Jun 8, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page.
Published Jun 7, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
In the function wma_pdev_div_info_evt_handler() in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, there is no upper bound check on the value event->num_chains_valid received from firmware which can lead to a buffer overwrite of the fixed size chain_rssi_result structure.
Published Jun 12, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Under certain conditions, on F5 BIG-IP ASM 13.1.0-13.1.0.5, Behavioral DOS (BADOS) protection may fail during an attack.
Published Jun 1, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow in TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to cause a denial of service (outage) via a long type parameter to /data/syslog.filter.json.
Published Jun 23, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubServerConfig.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Published Jun 5, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
In the KGSL driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, a Use After Free condition can occur when printing information about sparse memory allocations
Published Jun 12, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
An issue was discovered on Momentum Axel 720P 5.1.8 devices. There is Authenticated Custom Firmware Upgrade via DNS Hijacking. An authenticated root user with CLI access is able to remotely upgrade firmware to a custom image due to lack of SSL validation by changing the nameservers in /etc/resolv.conf to the attacker's server, and serving the expected HTTPS response containing new firmware for the device to download.
Published Jun 12, 2018 · Updated Sep 17, 2024
Unknown · CVSS Not scored
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a string.
Published Jun 14, 2018 · Updated Sep 17, 2024