LiveActive security incident?Get immediate response
CVE archive

September 2018

Browse CVE records published in September 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1155 matching CVEs · Page 4 of 24.

Unknown · CVSS Not scored

CVE-2018-1000658: LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can re...

LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an attacker gaining code execution via webshell. This attack appear to be exploitable via an authenticated user uploading a zip archive which can contains malicious php files that can be called under certain circumstances. This vulnerability appears to have been fixed in after commit 91d143230eb357260a19c8424b3005deb49a47f7 / version 3.14.4.

Published Sep 6, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-14829: Rockwell Automation RSLinx Classic Versions 4.00.01 and prior.

Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to intentionally send a malformed CIP packet to Port 44818, causing the software application to stop responding and crash. This vulnerability also has the potential to exploit a buffer overflow condition, which may allow the threat actor to remotely execute arbitrary code.

Published Sep 20, 2018 · Updated Sep 16, 2024

Medium · CVSS 6.3

CVE-2018-15611: Communication Manager Local Administrator PrivEsc

A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privileges. Affected versions include 6.3.x and all 7.x version prior to 7.1.3.1.

Published Sep 27, 2018 · Updated Sep 16, 2024

High · CVSS 7.5

CVE-2018-3915: An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the...

An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call overflows the destination buffer, which has a size of 64 bytes. An attacker can send an arbitrarily long "bucket" value in order to exploit this vulnerability.

Published Sep 21, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-1000659: LimeSurvey version 3.14.4 and earlier contains a directory traversal in file upload that allows upload of w...

LimeSurvey version 3.14.4 and earlier contains a directory traversal in file upload that allows upload of webshell vulnerability in file upload functionality that can result in remote code execution as authenticated user. This attack appear to be exploitable via An authenticated user can upload a specially crafted zip file to get remote code execution. This vulnerability appears to have been fixed in after commit 72a02ebaaf95a80e26127ee7ee2b123cccce05a7 / version 3.14.4.

Published Sep 6, 2018 · Updated Sep 16, 2024

Critical · CVSS 9.9

CVE-2018-3897: An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTT...

An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub with Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. The strncpy call overflows the destination buffer, which has a size of 52 bytes. An attacker can send an arbitrarily long "callbackUrl" value in order to exploit this vulnerability.

Published Sep 10, 2018 · Updated Sep 16, 2024

High · CVSS 7.1

CVE-2018-1669: IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2...

IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 144950.

Published Sep 25, 2018 · Updated Sep 16, 2024

Medium · CVSS 5.4

CVE-2018-3885: An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6.

An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The order_by parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.

Published Sep 12, 2018 · Updated Sep 16, 2024

Medium · CVSS 5.4

CVE-2018-3884: An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6.

An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.

Published Sep 12, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-16546: Amcrest networked devices use the same hardcoded SSL private key across different customers' installations,...

Amcrest networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation, as demonstrated by Amcrest_IPC-HX1X3X-LEXUS_Eng_N_AMCREST_V2.420.AC01.3.R.20180206.

Published Sep 5, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-11086: Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13...

Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be able to access an artifact which contains the CF admin credential, allowing them to escalate to an admin role.

Published Sep 17, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-17176: A replay issue was discovered on Neato Botvac Connected 2.2.0 devices.

A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. There are no nonces, and timestamps are not checked at all.

Published Sep 18, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-1330: When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due t...

When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly planted assertion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.

Published Sep 13, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-12243: The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) ex...

The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI schemes or relative paths in the system identifier to access files that should not normally be accessible.

Published Sep 19, 2018 · Updated Sep 16, 2024

Critical · CVSS 9.9

CVE-2018-3873: An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server...

An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 128 bytes. An attacker can send an arbitrarily long "secretKey" value in order to exploit this vulnerability.

Published Sep 21, 2018 · Updated Sep 16, 2024

Medium · CVSS 5.4

CVE-2018-1560: IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-si...

IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142958.

Published Sep 25, 2018 · Updated Sep 16, 2024