Latest CVE Feed
-
6.5
MEDIUMCVE-2018-12939
A directory traversal flaw in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows an authenticated attacker to write to (or potentially delete) arbitrary files via a .. (dot dot) in the "op/op.UploadChunks.php" "qquuid" parameter. NOTE: this can be ... Read more
Affected Products : seeddms- Published: Jul. 31, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12934
remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt.... Read more
Affected Products : binutils- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12933
PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact because the attacker controls the pCreatePen->ihPen array index.... Read more
Affected Products : wine- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12932
PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by triggering a large pAlphaBlend->cbBitsSrc value.... Read more
Affected Products : wine- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-12931
ntfs_attr_find in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified other impact via a crafted ntfs file... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-12930
ntfs_end_buffer_async_read in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified other impact via a craft... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-12929
ntfs_read_locked_inode in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a use-after-free read and possibly cause a denial of service (kernel oops or panic) via a crafted ntfs filesystem.... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-12928
In the Linux kernel 4.15.0, a NULL pointer dereference was discovered in hfs_ext_read_extent in hfs.ko. This can occur during a mount of a crafted hfs filesystem.... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12927
Northern Electric & Power (NEP) inverter devices allow remote attackers to obtain potentially sensitive information via a direct request for the nep/status/index/1 URI.... Read more
Affected Products : northern_electric_\&_power_inverter_firmware northern_electric_\&_power_inverter- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12926
Pharos Controls devices allow remote attackers to obtain potentially sensitive information via a direct request for the default/index.lsp or default/log.lsp URI.... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-12925
Baseon Lantronix MSS devices do not require a password for TELNET access.... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-12924
Sollae Serial-Ethernet-Module and Remote-I/O-Device-Server devices have a default password of sollae for the TELNET service.... Read more
Affected Products : cie-h10_firmware cie-h12_firmware cie-h14_firmware cse-m53n_firmware cse-m32_firmware cse-m24_firmware cse-m73_firmware cse-b63n2_firmware cie-h10 cie-h12 +6 more products- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12923
BWS Systems HA-Bridge devices allow remote attackers to obtain potentially sensitive information via a direct request for the #!/system URI.... Read more
Affected Products : ha_bridge- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12922
Emerson Liebert IntelliSlot Web Card devices allow remote attackers to reconfigure access control via the config/configUser.htm or config/configTelnet.htm URI.... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12921
Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a direct request for the meter_information.htm, diag_system.htm, or diag_dnp_lan_wan.htm URI.... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12920
Brickstream 2300 devices allow remote attackers to obtain potentially sensitive information via a direct request for the basic.html#ipsettings or basic.html#datadelivery URI.... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-12919
In CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter.... Read more
Affected Products : craftedweb- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12918
In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcB_register_fields in bootstrap.c.... Read more
Affected Products : pbc- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12917
In libpbc.a in PBC through 2017-03-02, there is a heap-based buffer over-read in _pbcM_ip_new in map.c.... Read more
Affected Products : pbc- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12916
In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcP_message_default in proto.c.... Read more
Affected Products : pbc- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024