Unknown · CVSS Not scored
There is a heap-based buffer overflow at fromsixel.c (function: image_buffer_resize) in libsixel 1.8.2 that will cause a denial of service or possibly unspecified other impact.
Published Nov 30, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.
Published Nov 2, 2020 · Updated Sep 16, 2024
High · CVSS 7.6
The web application of the TIBCO Statistica component of TIBCO Software Inc.'s TIBCO Statistica Server contains vulnerabilities which may allow an authenticated user to perform cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Statistica Server versions up to and including 13.4.0.
Published Nov 26, 2018 · Updated Sep 16, 2024
High · CVSS 8.9
IBM API Connect 5.0.0.0, 5.0.8.4, 2018.1 and 2018.3.6 is vulnerable to CSV injection via the developer portal and analytics that could contain malicious commands that would be executed once opened by an administrator. IBM X-Force ID: 148692.
Published Nov 9, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74950468.
Published Nov 6, 2018 · Updated Sep 16, 2024
Medium · CVSS 4.8
IBM Case Manager 5.2.0.0, 5.2.0.4, 5.2.1.0, 5.2.1.7, 5.3.0.0, and 5.3.3.0 is vulnerable to a "zip slip" vulnerability which could allow a remote attacker to execute code using directory traversal techniques. IBM X-Force ID: 151970.
Published Nov 12, 2018 · Updated Sep 16, 2024
Medium · CVSS 4.3
The Report Builder of Jazz Reporting Service 5.0 through 5.0.2 and 6.0 through 6.0.6 could allow an authenticated user to obtain sensitive information beyond its assigned privileges. IBM X-Force ID: 144579.
Published Nov 16, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a memset call, as demonstrated by sadf.
Published Nov 24, 2018 · Updated Sep 16, 2024
High · CVSS 7.8
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local db2 instance owner to obtain root access by exploiting a symbolic link attack to read/write/corrupt a file that they originally did not have permission to access. IBM X-Force ID: 148803.
Published Nov 9, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In avct_bcb_msg_ind of avct_bcb_act.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android ID: A-79944113.
Published Nov 6, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php.
Published Nov 14, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI.
Published Nov 12, 2018 · Updated Sep 16, 2024
High · CVSS 8.1
Cloud Foundry Bits Service Release, versions prior to 2.14.0, uses an insecure hashing algorithm to sign URLs. A remote malicious user may obtain a signed URL and extract the signing key, allowing them complete read and write access to the the Bits Service storage.
Published Nov 9, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In avrc_proc_vendor_command of avrc_api.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-79541338.
Published Nov 6, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Data from Faulting Address controls Branch Selection starting at U3DBrowser!PlugInMain+0x00000000000d11bb" issue.
Published Nov 17, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An issue was discovered in XiaoCms 20141229. There is XSS related to the template\default\show_product.html file.
Published Nov 12, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
DomainMOD through 4.11.01 has XSS via the assets/edit/ip-address.php ipid parameter.
Published Nov 9, 2018 · Updated Sep 16, 2024
Medium · CVSS 6.5
IBM StoredIQ 7.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 153118.
Published Nov 30, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 during application installation on Windows 7 in elevated privilege mode, where a local user who initiates a browser session may obtain escalation of privileges on the browser.
Published Nov 27, 2018 · Updated Sep 16, 2024
Medium · CVSS 5.1
IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 7.1 and 8.1 creates directories/files in the CIT sub directory that are read/writable by everyone. IBM X-Force ID: 155551.
Published Nov 25, 2019 · Updated Sep 16, 2024
Critical · CVSS 9
Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator privileges for Opsman.
Published Nov 2, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In Flarum Core 0.1.0-beta.7.1, a serious leak can get everyone's email address.
Published Nov 9, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds write due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-80145946.
Published Nov 6, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of bounds write with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-65853588 References: Upstream kernel.
Published Nov 6, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.
Published Nov 9, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Netwide Assembler (NASM) through 2.14rc16 has memory leaks that may lead to DoS, related to nasm_malloc in nasmlib/malloc.c.
Published Nov 12, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In get_futex_key of futex.c, there is a use-after-free due to improper locking. This could lead to local escalation of privilege with no additional privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-74250718 References: Upstream kernel.
Published Nov 6, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
MiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename.
Published Nov 1, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An issue was discovered in LAOBANCMS 2.0. It allows SQL Injection via the admin/login.php guanliyuan parameter.
Published Nov 12, 2018 · Updated Sep 16, 2024
Medium · CVSS 5.5
IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code on the system, caused by a missing restriction in which file types can be uploaded to the control room. By uploading a malicious file and tricking a victim to run it, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 142889.
Published Nov 2, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).
Published Nov 1, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An issue was discovered in LAOBANCMS 2.0. It allows a /install/mysql_hy.php?riqi=0&i=0 attack to reset the admin password, even if install.txt exists.
Published Nov 12, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Portainer through 1.19.2 provides an API endpoint (/api/users/admin/check) to verify that the admin user is already created. This API endpoint will return 404 if admin was not created and 204 if it was already created. Attackers can set an admin password in the 404 case.
Published Nov 20, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
There is a heap-based buffer over-read at stb_image_write.h (function: stbi_write_png_to_mem) in libsixel 1.8.2 that will cause a denial of service.
Published Nov 30, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3.
Published Nov 20, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin' that are protected with default passwords. These accounts have limited privileges and can access certain system files only. A malicious user with the knowledge of the default passwords may potentially log in to the system and gain read and write access to certain system files.
Published Nov 2, 2018 · Updated Sep 16, 2024
Medium · CVSS 4.1
The Identity and Access Management (IAM) services (IBM Cloud Private 3.1.0) do not use a secure channel, such as SSL, to exchange information only when accessed internally from within the cluster. It could be possible for an attacker with access to network traffic to sniff packets from the connection and uncover data. IBM X-Force ID: 150903
Published Nov 21, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability than CVE-2018-19246.
Published Nov 22, 2018 · Updated Sep 16, 2024
High · CVSS 7.5
The administrative daemon (tibdgadmind) of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO ActiveSpaces - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition: 3.3.0; 3.4.0; 3.5.0, TIBCO ActiveSpaces - Developer Edition: 3.0.0; 3.1.0; 3.3.0; 3.4.0; 3.5.0, and TIBCO ActiveSpaces - Enterprise Edition: 3.0.0; 3.1.0; 3.2.0; 3.3.0; 3.4.0; 3.5.0.
Published Nov 7, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.
Published Nov 6, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
kimsQ Rb 2.3.0 allows XSS via the second input field to the /?r=home&mod=mypage&page=info URI.
Published Nov 17, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-78286118.
Published Nov 6, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php.
Published Nov 11, 2018 · Updated Sep 16, 2024
Low · CVSS 3.6
IBM Cognos Analytics 11 Configuration tool, under certain circumstances, will bypass OIDC namespace signature verification on its id_token. IBM X-Force ID: 150902.
Published Nov 9, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A type confusion vulnerability exists when processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, which may allow an attacker to execute code in the context of the application.
Published Nov 5, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size is supposed to match an expanded length but actually matches a compressed length.
Published Nov 14, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
CuppaCMS before 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the reference_id parameter.
Published Nov 26, 2018 · Updated Sep 16, 2024
Medium · CVSS 5.4
IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148616.
Published Nov 29, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted requests to upgrade_handle.php to execute OS commands as root.
Published Nov 30, 2018 · Updated Sep 16, 2024
High · CVSS 7.5
A incorrect variable in a SUSE specific patch for pam_access rule matching in PAM 1.3.0 in openSUSE Leap 15.0 and SUSE Linux Enterprise 15 could lead to pam_access rules not being applied (fail open).
Published Nov 27, 2018 · Updated Sep 16, 2024