LiveActive security incident?Get immediate response
CVE archive

November 2018

Browse CVE records published in November 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1090 matching CVEs · Page 6 of 22.

High · CVSS 7.6

CVE-2018-18807: TIBCO Statistica Server Vulnerable to Cross Site Scripting

The web application of the TIBCO Statistica component of TIBCO Software Inc.'s TIBCO Statistica Server contains vulnerabilities which may allow an authenticated user to perform cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Statistica Server versions up to and including 13.4.0.

Published Nov 26, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-9356: In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free.

In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74950468.

Published Nov 6, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-9448: In avct_bcb_msg_ind of avct_bcb_act.cc, there is a possible out of bounds read due to a missing bounds check.

In avct_bcb_msg_ind of avct_bcb_act.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android ID: A-79944113.

Published Nov 6, 2018 · Updated Sep 16, 2024

High · CVSS 8.1

CVE-2018-15796: Signing Key Extraction in Bits Service Release

Cloud Foundry Bits Service Release, versions prior to 2.14.0, uses an insecure hashing algorithm to sign URLs. A remote malicious user may obtain a signed URL and extract the signing key, allowing them complete read and write access to the the Bits Service storage.

Published Nov 9, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-9450: In avrc_proc_vendor_command of avrc_api.cc, there is a possible out of bounds write due to a missing bounds...

In avrc_proc_vendor_command of avrc_api.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-79541338.

Published Nov 6, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-19347: The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allo...

The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Data from Faulting Address controls Branch Selection starting at U3DBrowser!PlugInMain+0x00000000000d11bb" issue.

Published Nov 17, 2018 · Updated Sep 16, 2024

Critical · CVSS 9

CVE-2018-15762: Pivotal Operations Manager gives all users heightened privileges

Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator privileges for Opsman.

Published Nov 2, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-9446: In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds write due to memory corr...

In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds write due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-80145946.

Published Nov 6, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-9363: In the hidp_process_report in bluetooth, there is an integer overflow.

In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of bounds write with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-65853588 References: Upstream kernel.

Published Nov 6, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-9422: In get_futex_key of futex.c, there is a use-after-free due to improper locking.

In get_futex_key of futex.c, there is a use-after-free due to improper locking. This could lead to local escalation of privilege with no additional privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-74250718 References: Upstream kernel.

Published Nov 6, 2018 · Updated Sep 16, 2024

Medium · CVSS 5.5

CVE-2018-1552: IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute a...

IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code on the system, caused by a missing restriction in which file types can be uploaded to the control room. By uploading a malicious file and tricking a victim to run it, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 142889.

Published Nov 2, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-11062: Dell EMC Integrated Data Protection Appliance Undocumented Accounts Vulnerability

Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin' that are protected with default passwords. These accounts have limited privileges and can access certain system files only. A malicious user with the knowledge of the default passwords may potentially log in to the system and gain read and write access to certain system files.

Published Nov 2, 2018 · Updated Sep 16, 2024

Medium · CVSS 4.1

CVE-2018-1843: The Identity and Access Management (IAM) services (IBM Cloud Private 3.1.0) do not use a secure channel, su...

The Identity and Access Management (IAM) services (IBM Cloud Private 3.1.0) do not use a secure channel, such as SSL, to exchange information only when accessed internally from within the cluster. It could be possible for an attacker with access to network traffic to sniff packets from the connection and uncover data. IBM X-Force ID: 150903

Published Nov 21, 2018 · Updated Sep 16, 2024

High · CVSS 7.5

CVE-2018-12411: TIBCO ActiveSpaces Administrative Daemon Vulnerable to CSRF Attacks

The administrative daemon (tibdgadmind) of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO ActiveSpaces - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition: 3.3.0; 3.4.0; 3.5.0, TIBCO ActiveSpaces - Developer Edition: 3.0.0; 3.1.0; 3.3.0; 3.4.0; 3.5.0, and TIBCO ActiveSpaces - Enterprise Edition: 3.0.0; 3.1.0; 3.2.0; 3.3.0; 3.4.0; 3.5.0.

Published Nov 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-18980: An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Mana...

An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.

Published Nov 6, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2018-9454: In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check.

In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-78286118.

Published Nov 6, 2018 · Updated Sep 16, 2024

Medium · CVSS 5.4

CVE-2018-1762: IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to c...

IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148616.

Published Nov 29, 2018 · Updated Sep 16, 2024