Search

Search Results (12703 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-7658 1 Softros 1 Network Time System 2024-11-21 N/A
NTSServerSvc.exe in the server in Softros Network Time System 2.3.4 allows remote attackers to cause a denial of service (daemon crash) by sending exactly 11 bytes.
CVE-2018-7311 1 Privatevpn 1 Privatevpn 2024-11-21 8.8 High
PrivateVPN 2.0.31 for macOS suffers from a root privilege escalation vulnerability. The software installs a privileged helper tool that runs as the root user. This privileged helper tool is installed as a LaunchDaemon and implements an XPC service. The XPC service is responsible for handling new VPN connection operations via the main PrivateVPN application. The privileged helper tool creates new VPN connections by executing the openvpn binary located in the /Applications/PrivateVPN.app/Contents/Resources directory. The openvpn binary can be overwritten by the default user, which allows an attacker that has already installed malicious software as the default user to replace the binary. When a new VPN connection is established, the privileged helper tool will launch this malicious binary, thus allowing an attacker to execute code as the root user. NOTE: the vendor has reportedly indicated that this behavior is "an acceptable part of their software.
CVE-2018-7308 1 Hosting Project 1 Hosting 2024-11-21 N/A
A CSRF issue was found in var/www/html/files.php in DanWin hosting through 2018-02-11 that allows arbitrary remote users to add/delete/modify any files in any hosting account.
CVE-2018-7305 1 Mybb 1 Mybb 2024-11-21 N/A
MyBB 1.8.14 is not checking for a valid CSRF token, leading to arbitrary deletion of user accounts.
CVE-2018-7304 1 Tiki 1 Tiki 2024-11-21 N/A
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection attack can open a CMD.EXE or Calculator window on the victim machine to perform malicious activity, as demonstrated by an "=cmd|' /C calc'!A0" payload during User Creation.
CVE-2018-7303 1 Tiki 1 Tikiwiki Cms\/groupware 2024-11-21 N/A
The Calendar component in Tiki 17.1 allows HTML injection.
CVE-2018-7302 1 Tiki 1 Tiki 2024-11-21 N/A
Tiki 17.1 allows upload of a .PNG file that actually has SVG content, leading to XSS.
CVE-2018-7289 1 Teclib-edition 1 Armadito Antivirus 2024-11-21 N/A
An issue was discovered in armadito-windows-driver/src/communication.c in Armadito 0.12.7.2. Malware with filenames containing pure UTF-16 characters can bypass detection. The user-mode service will fail to open the file for scanning after the conversion is done from Unicode to ANSI. This happens because characters that cannot be converted from Unicode are replaced with '?' characters.
CVE-2018-7281 1 Cactusvpn 1 Cactusvpn 2024-11-21 N/A
CactusVPN 5.3.6 for macOS contains a root privilege escalation vulnerability through a setuid root binary called runme. The binary takes a single command line argument and passes this argument to a system() call, thus allowing low privileged users to execute commands as root.
CVE-2018-7280 1 Ninjaforms 1 Ninja Forms 2024-11-21 N/A
The Ninja Forms plugin before 3.2.14 for WordPress has XSS.
CVE-2018-7278 1 Rletech 4 Fds-pc, Fds-pc-dp, Fds-pc-dp Firmware and 1 more 2024-11-21 N/A
An issue was discovered on RLE Protocol Converter FDS-PC / FDS-PC-DP 2.1 devices. Persistent XSS exists in the web server. Remote attackers can inject malicious JavaScript code using the device's BACnet implementation. This is similar to a Cross Protocol Injection with SNMP.
CVE-2018-7277 1 Rletech 4 Fds-wi, Fds-wi Firmware, Wi-mgr and 1 more 2024-11-21 N/A
An issue was discovered on RLE Wi-MGR/FDS-Wi 6.2 devices. Persistent XSS exists in the web server. Remote attackers can inject malicious JavaScript code using the device's BACnet implementation. This is similar to a Cross Protocol Injection with SNMP.
CVE-2018-7276 1 Lutron 2 Quantum Bacnet Integration, Quantum Bacnet Integration Firmware 2024-11-21 N/A
An issue was discovered on Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) devices. Remote attackers can obtain potentially sensitive information via a /DbXmlInfo.xml request, as demonstrated by the Latitude/Longitude of the device.
CVE-2018-7274 1 Quarx Cms Project 1 Quarx Cms 2024-11-21 6.1 Medium
Yab Quarx through 2.4.3 is prone to multiple persistent cross-site scripting vulnerabilities: Blog (Title), FAQ (Question), Pages (Title), Widgets (Name), and Menus (Name).
CVE-2018-7273 1 Linux 1 Linux Kernel 2024-11-21 N/A
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables using printk calls within the function show_floppy in drivers/block/floppy.c. An attacker can read this information from dmesg and use the addresses to find the locations of kernel code and data and bypass kernel security protections such as KASLR.
CVE-2018-7272 1 Forgerock 1 Access Management 2024-11-21 N/A
The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding an ID value in a log file.
CVE-2018-7271 1 Metinfo 1 Metinfo 2024-11-21 N/A
An issue was discovered in MetInfo 6.0.0. In install/install.php in the installation process, the config/config_db.php configuration file filtering is not rigorous: one can insert malicious code in the installation process to execute arbitrary commands or obtain a web shell.
CVE-2018-7265 1 Shimmie2 Project 1 Shimmie2 2024-11-21 N/A
Shimmie 2 2.6.0 allows an attacker to upload a crafted SVG file that enables stored XSS.
CVE-2018-7263 2 Redhat, Underbit 2 Enterprise Linux, Libmad 2024-11-21 N/A
The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial of service (SIGABRT because of double free or corruption) or possibly have unspecified other impact via a crafted file. NOTE: this may overlap CVE-2017-11552.
CVE-2018-7261 1 Radiantcms 1 Radiant Cms 2024-11-21 N/A
There are multiple Persistent XSS vulnerabilities in Radiant CMS 1.1.4. They affect Personal Preferences (Name and Username) and Configuration (Site Title, Dev Site Domain, Page Parts, and Page Fields).