Latest CVE Feed
-
6.1
MEDIUMCVE-2018-11562
An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious link for an event view and then clicks on the deleted attributes quick filter.... Read more
- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-11561
An integer overflow in the unprotected distributeToken function of a smart contract implementation for EETHER (EETHER), an Ethereum ERC20 token, will lead to an unauthorized increase of an attacker's digital assets.... Read more
Affected Products : erc20token- Published: Aug. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11560
The webService binary on Insteon HD IP Camera White 2864-222 devices has a stack-based Buffer Overflow leading to Control-Flow Hijacking via a crafted usr key, as demonstrated by a long remoteIp parameter to cgi-bin/CGIProxy.fcgi on port 34100.... Read more
- Published: Jun. 23, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-11559
DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_last_name parameter.... Read more
Affected Products : domainmod- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-11558
DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_first_name parameter.... Read more
Affected Products : domainmod- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-11557
YIBAN Easy class education platform 2.0 has XSS via the articlelist.php k parameter.... Read more
Affected Products : easy_class_education_platform- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-11556
tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerability because the issue is based on an sample p... Read more
- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-11555
tificc in Little CMS 2.9 has an out-of-bounds write in the PrecalculatedXFORM function in cmsxform.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerability because the issue is based on an sample program using ... Read more
- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11554
The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Discrepancy Information Exposure issue and an unexpectedly long lifetime for a verification code, which makes it easier for remote attacke... Read more
Affected Products : yzmcms- Published: Jun. 05, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-11553
SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php.... Read more
Affected Products : xiangyun_platform- Published: Jun. 06, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-11552
There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field. The vulnerability exists due to insufficient filtration of user-supplied data. A remote attacker can execute arbitrary HTML and script code in a brows... Read more
Affected Products : axon_pbx- Published: Jun. 01, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-11551
AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability exists because a DLL file is loaded by 'pbxsetup.exe' improperly.... Read more
Affected Products : axon_pbx- Published: Jun. 01, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-11548
An issue was discovered in EOS.IO DAWN 4.2. plugins/net_plugin/net_plugin.cpp does not limit the number of P2P connections from the same source IP address.... Read more
Affected Products : eos- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11547
md_is_link_reference_definition_helper in md4c 0.2.5 has a heap-based buffer over-read because md_is_link_label mishandles loop termination.... Read more
Affected Products : md4c- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11546
md4c 0.2.5 has a heap-based buffer over-read because md_is_named_entity_contents has an off-by-one error.... Read more
Affected Products : md4c- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11545
md4c 0.2.5 has a heap-based buffer overflow in md_merge_lines because md_is_link_label mishandles the case of a link label composed solely of backslash escapes.... Read more
Affected Products : md4c- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11544
The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.ftpserver_preferences.xml file as the prefUsername and p... Read more
Affected Products : ftp_server- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-11543
A Local File Inclusion (LFI) vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows for the downloading of arbitrary files via an unspecified vector. It affects the 1000 and 2000 devices 6.0.x up to Build 446, 6.1.x up to Build... Read more
- Published: Jul. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11542
A Remote Command Execution (RCE) vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows for the execution of arbitrary commands via an unspecified vector. It affects the 1000 and 2000 devices 6.0.x up to Build 446, 6.1.x up to ... Read more
- Published: Jul. 09, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-11541
A root privilege escalation vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows unauthorised access to privileged content via an unspecified vector. It affects the 1000 and 2000 devices 6.0.x up to Build 446, 6.1.x up to Bui... Read more
Affected Products : sonus_sbc_1000_firmware sonus_sbc_2000_firmware sbc_swe_lite_web sonus_sbc_1000 sonus_sbc_2000- Published: Jul. 09, 2018
- Modified: Nov. 21, 2024