LiveActive security incident?Get immediate response
CVE archive

November 2018

Browse CVE records published in November 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1090 matching CVEs · Page 10 of 22.

Unknown · CVSS Not scored

CVE-2018-19059: An issue was discovered in Poppler 0.71.0.

An issue was discovered in Poppler 0.71.0. There is a out-of-bounds read in EmbFile::save2 in FileSpec.cc, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating embedded files before save attempts.

Published Nov 7, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-19075: An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1....

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The firewall feature makes it easier for remote attackers to ascertain credentials and firewall rules because invalid credentials lead to error -2, whereas rule-based blocking leads to error -8.

Published Nov 7, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-19291: An issue was discovered in DiliCMS 2.4.0.

An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI.

Published Nov 15, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-19047: mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstra...

mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substring that triggers a call to getImage in Image/ImageProcessor.php. NOTE: the software maintainer disputes this, stating "If you allow users to pass HTML without sanitising it, you're asking for trouble.

Published Nov 7, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-19198: An issue was discovered in uriparser before 0.9.0.

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.

Published Nov 12, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-19135: ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default).

ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with the file upload capability). With this vulnerability, one can automatically upload files (by default, it allows html, pdf, xml, zip, and many other file types). A file can be accessed publicly under the "/assets/files" directory.

Published Nov 11, 2018 · Updated Aug 5, 2024