LiveActive security incident?Get immediate response
CVE archive

July 2018

Browse CVE records published in July 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2018 matching CVEs · Page 12 of 41.

Unknown · CVSS Not scored

CVE-2018-5529: The svpn component of the F5 BIG-IP APM client prior to version 7.1.7 for Linux and Mac OS X runs as a priv...

The svpn component of the F5 BIG-IP APM client prior to version 7.1.7 for Linux and Mac OS X runs as a privileged process and can allow an unprivileged user to assume super-user privileges on the local client host. A malicious local unprivileged user may gain knowledge of sensitive information, manipulate certain data, or disrupt service.

Published Jul 12, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-1000620: Eran Hammer cryptiles version 4.1.1 earlier contains a CWE-331: Insufficient Entropy vulnerability in rando...

Eran Hammer cryptiles version 4.1.1 earlier contains a CWE-331: Insufficient Entropy vulnerability in randomDigits() method that can result in An attacker is more likely to be able to brute force something that was supposed to be random.. This attack appear to be exploitable via Depends upon the calling application.. This vulnerability appears to have been fixed in 4.1.2.

Published Jul 9, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-1999018: Pydio version 8.2.1 and prior contains an Unvalidated user input leading to Remote Code Execution (RCE) vul...

Pydio version 8.2.1 and prior contains an Unvalidated user input leading to Remote Code Execution (RCE) vulnerability in plugins/action.antivirus/AntivirusScanner.php: Line 124, scanNow($nodeObject) that can result in An attacker gaining admin access and can then execute arbitrary commands on the underlying OS. This attack appear to be exploitable via The attacker edits the Antivirus Command in the antivirus plugin, and executes the payload by uploading any file within Pydio.

Published Jul 23, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-13409: An issue was discovered in Jirafeau before 3.4.1.

An issue was discovered in Jirafeau before 3.4.1. The "search file by hash" form is affected by reflected XSS that could allow, by targeting an administrator, stealing a session and gaining administrative privileges.

Published Jul 6, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-14066: The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for...

The content://wappush content provider in com.android.provider.telephony, as found in some custom ROMs for Android phones, allows SQL injection. One consequence is that an application without the READ_SMS permission can read SMS messages. This affects Infinix X571 phones, as well as various Lenovo phones (such as the A7020) that have since been fixed by Lenovo.

Published Jul 15, 2018 · Updated Sep 16, 2024

Medium · CVSS 6.5

CVE-2018-0039: Contrail Service Orchestration: Hardcoded credentials for Grafana service

Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to information stored in Grafana or exploit other weaknesses or vulnerabilities in Grafana.

Published Jul 11, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-1000208: MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanager...

MODX Revolution version <=2.6.4 contains a Directory Traversal vulnerability in /core/model/modx/modmanagerrequest.class.php that can result in remove files. This attack appear to be exploitable via web request via security/login processor. This vulnerability appears to have been fixed in pull 13980.

Published Jul 13, 2018 · Updated Sep 16, 2024

High · CVSS 7.5

CVE-2018-0032: Junos OS: RPD crash when receiving a crafted BGP UPDATE

The receipt of a crafted BGP UPDATE can lead to a routing process daemon (RPD) crash and restart. Repeated receipt of the same crafted BGP UPDATE can result in an extended denial of service condition for the device. This issue only affects the specific versions of Junos OS listed within this advisory. Earlier releases are unaffected by this vulnerability. This crafted BGP UPDATE does not propagate to other BGP peers. Affected releases are Juniper Networks Junos OS: 16.1X65 versions prior to 16.1X65-D47; 17.2X75 versions prior to 17.2X75-D91, 17.2X75-D110; 17.3 versions prior to 17.3R1-S4, 17.3R2; 17.4 versions prior to 17.4R1-S3, 17.4R2.

Published Jul 11, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-5535: On F5 BIG-IP 14.0.0, 13.0.0-13.1.0, 12.1.0-12.1.3, or 11.5.1-11.6.3 specifically crafted HTTP responses, wh...

On F5 BIG-IP 14.0.0, 13.0.0-13.1.0, 12.1.0-12.1.3, or 11.5.1-11.6.3 specifically crafted HTTP responses, when processed by a Virtual Server with an associated QoE profile that has Video enabled, may cause TMM to incorrectly buffer response data causing the TMM to restart resulting in a Denial of Service.

Published Jul 19, 2018 · Updated Sep 16, 2024

Medium · CVSS 4.4

CVE-2018-0035: Junos OS: QFX5200 and QFX10002: Unintended ONIE partition was shipped with certain Junos OS .bin and .iso images

QFX5200 and QFX10002 devices that have been shipped with Junos OS 15.1X53-D21, 15.1X53-D30, 15.1X53-D31, 15.1X53-D32, 15.1X53-D33 and 15.1X53-D60 or have been upgraded to these releases using the .bin or .iso images may contain an unintended additional Open Network Install Environment (ONIE) partition. This additional partition allows the superuser to reboot to the ONIE partition which will wipe out the content of the Junos partition and its configuration. Once rebooted, the ONIE partition will not have root password configured, thus any user can access the console or SSH, using an IP address acquired from DHCP, as root without password. Once the device has been shipped or upgraded with the ONIE partition installed, the issue will persist. Simply upgrading to higher release via the CLI will not resolve the issue. No other Juniper Networks products or platforms are affected by this issue.

Published Jul 11, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-14387: An issue was discovered in WonderCMS before 2.5.2.

An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the associated session identifier. The attacker then causes the victim to authenticate against the server using the same session identifier. The attacker can access the user's account through the active session. The Session Fixation attack fixes a session on the victim's browser, so the attack starts before the user logs in.

Published Jul 18, 2018 · Updated Sep 16, 2024

High · CVSS 8.8

CVE-2018-3858: An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0.

An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain the ability to execute code. A different vulnerability than CVE-2018-3857.

Published Jul 19, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-8031: The Apache TomEE console (tomee-webapp) has a XSS vulnerability which could allow javascript to be executed...

The Apache TomEE console (tomee-webapp) has a XSS vulnerability which could allow javascript to be executed if the user is given a malicious URL. This web application is typically used to add TomEE features to a Tomcat installation. The TomEE bundles do not ship with this application included. This issue can be mitigated by removing the application after TomEE is setup (if using the application to install TomEE), using one of the provided pre-configured bundles, or by upgrading to TomEE 7.0.5. This issue is resolve in this commit: b8bbf50c23ce97dd64f3a5d77f78f84e47579863.

Published Jul 23, 2018 · Updated Sep 16, 2024

High · CVSS 8.8

CVE-2018-3860: An exploitable out-of-bounds write exists in the TIFF parsing functionality of Canvas Draw version 4.0.0.

An exploitable out-of-bounds write exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain the ability to execute code. A different vulnerability than CVE-2018-3859.

Published Jul 19, 2018 · Updated Sep 16, 2024