LiveActive security incident?Get immediate response
CVE archive

June 2018

Browse CVE records published in June 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1447 matching CVEs · Page 3 of 29.

Unknown · CVSS Not scored

CVE-2018-5525: A local file vulnerability exists in the F5 BIG-IP Configuration utility on versions 13.0.0, 12.1.0-12.1.2,...

A local file vulnerability exists in the F5 BIG-IP Configuration utility on versions 13.0.0, 12.1.0-12.1.2, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 that exposes files containing F5-provided data only and do not include any configuration data, proxied traffic, or other potentially sensitive customer data.

Published Jun 1, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2018-1268: Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x...

Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not validate app GUID structure in requests. A remote authenticated malicious user knowing the GUID of an app may construct malicious requests to read from or write to the logs of that app.

Published Jun 6, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2018-11680: An issue was discovered in CmsEasy 6.1_20180508.

An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability in the rich text editor that can add an IFRAME element. This might be used in a DoS attack if a referenced remote URL is refreshed at a rapid rate.

Published Jun 2, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2018-1333: DoS for HTTP/2 connections by crafted requests

By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).

Published Jun 18, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2018-1269: Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x...

Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not handle errors thrown while constructing certain http requests. A remote authenticated user may construct malicious requests to cause the traffic controller to leave dangling TCP connections, which could cause denial of service.

Published Jun 6, 2018 · Updated Sep 17, 2024

Medium · CVSS 6.5

CVE-2018-1253: Stored cross-site scripting vulnerability

RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulnerability. A malicious Operations Console administrator could potentially exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console administrators open the affected page, the injected scripts could potentially be executed in their browser.

Published Jun 21, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2018-11449: A vulnerability has been identified in SCALANCE M875 (All versions).

A vulnerability has been identified in SCALANCE M875 (All versions). An attacker with access to the local file system might obtain passwords for administrative users. Successful exploitation requires read access to files on the local file system. A successful attack could allow an attacker to obtain administrative passwords. At the time of advisory publication no public exploitation of this security vulnerability was known.

Published Jun 26, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2018-1000603: A exposure of sensitive information vulnerability exists in Jenkins Openstack Cloud Plugin 2.35 and earlier...

A exposure of sensitive information vulnerability exists in Jenkins Openstack Cloud Plugin 2.35 and earlier in BootSource.java, InstancesToRun.java, JCloudsCleanupThread.java, JCloudsCloud.java, JCloudsComputer.java, JCloudsPreCreationThread.java, JCloudsRetentionStrategy.java, JCloudsSlave.java, JCloudsSlaveTemplate.java, LauncherFactory.java, OpenstackCredentials.java, OpenStackMachineStep.java, SlaveOptions.java, SlaveOptionsDescriptor.java that allows attackers with Overall/Read access to Jenkins to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins, and to cause Jenkins to submit HTTP requests to attacker-specified URLs.

Published Jun 26, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2018-3756: Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature ve...

Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transaction and block validator allowing a single node to sign a transaction and/or block multiple times, each with a random nonce, and have other validating nodes accept them as separate valid signatures.

Published Jun 1, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2018-1252: RSA Web Threat Detection SQL Injection Vulnerability

RSA Web Threat Detection versions prior to 6.4, contain an SQL injection vulnerability in the Administration and Forensics applications. An authenticated malicious user with low privileges could potentially exploit this vulnerability to execute SQL commands on the back-end database to gain unauthorized access to the tool's monitoring and user information by supplying specially crafted input data to the affected application.

Published Jun 5, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2018-5843: In the function wma_pdev_div_info_evt_handler() in all Android releases from CAF (Android for MSM, Firefox...

In the function wma_pdev_div_info_evt_handler() in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, there is no upper bound check on the value event->num_chains_valid received from firmware which can lead to a buffer overwrite of the fixed size chain_rssi_result structure.

Published Jun 12, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2018-1000183: A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHu...

A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubServerConfig.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Published Jun 5, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2018-12257: An issue was discovered on Momentum Axel 720P 5.1.8 devices.

An issue was discovered on Momentum Axel 720P 5.1.8 devices. There is Authenticated Custom Firmware Upgrade via DNS Hijacking. An authenticated root user with CLI access is able to remotely upgrade firmware to a custom image due to lack of SSL validation by changing the nameservers in /etc/resolv.conf to the attacker's server, and serving the expected HTTPS response containing new firmware for the device to download.

Published Jun 12, 2018 · Updated Sep 17, 2024