Latest CVE Feed
-
6.1
MEDIUMCVE-2018-11041
Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for internal UAA redir... Read more
- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-11040
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers an... Read more
Affected Products : debian_linux weblogic_server application_testing_suite enterprise_manager_ops_center retail_predictive_application_server mysql_enterprise_monitor hospitality_guest_access retail_xstore_point_of_service flexcube_private_banking communications_services_gatekeeper +19 more products- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2018-11039
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. ... Read more
Affected Products : debian_linux weblogic_server application_testing_suite enterprise_manager_ops_center retail_predictive_application_server mysql_enterprise_monitor hospitality_guest_access retail_xstore_point_of_service primavera_p6_enterprise_project_portfolio_management agile_plm +24 more products- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-11037
In Exiv2 0.26, the Exiv2::PngImage::printStructure function in pngimage.cpp allows remote attackers to cause an information leak via a crafted file.... Read more
Affected Products : exiv2- Published: May. 14, 2018
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2018-11036
Ruckus SmartZone (formerly Virtual SmartCell Gateway or vSCG) 3.5.0, 3.5.1, 3.6.0, and 3.6.1 (Essentials and High Scale) on vSZ, SZ-100, SZ-300, and SCG-200 devices allows remote attackers to obtain sensitive information or modify data.... Read more
Affected Products : sz-300_firmware sz-100_firmware vsz_firmware scg-200_firmware sz-100 sz-300 vsz scg-200- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-11035
In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x80002019.... Read more
- Published: May. 14, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-11034
In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x8000200D.... Read more
- Published: May. 14, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-11033
The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JPEG data.... Read more
Affected Products : xpdf- Published: May. 14, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11032
PHPRAP 1.0.4 through 1.0.8 has SQL Injection via the application/home/controller/project.php search() function.... Read more
Affected Products : phprap- Published: May. 14, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-11031
application/home/controller/debug.php in PHPRAP 1.0.4 through 1.0.8 has SSRF via the /debug URI, as demonstrated by an api[url]=file:////etc/passwd&api[method]=get POST request.... Read more
Affected Products : phprap- Published: May. 14, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-11027
A reflected XSS vulnerability on Ruckus ICX7450-48 devices allows remote attackers to inject arbitrary web script or HTML.... Read more
- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-11025
kernel/omap/drivers/mfd/twl6030-gpadc.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/twl6030-gpadc with the command 24832 and cause a kernel... Read more
- Published: Oct. 16, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-11024
kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 1077435789 and cause a ke... Read more
- Published: Oct. 16, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-11023
kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 3222560159 and cause a ke... Read more
- Published: Oct. 16, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-11022
kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 3224132973 and cause a ker... Read more
- Published: Oct. 16, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-11021
kernel/omap/drivers/video/omap2/dsscomp/device.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/dsscomp with the command 1118064517 and cause ... Read more
- Published: Oct. 16, 2018
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2018-11020
kernel/omap/drivers/rpmsg/rpmsg_omx.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device file /dev/rpmsg-omx1 with the command 3221772291, and cause a ... Read more
- Published: Oct. 16, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-11019
kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 3221773726 and cause a ker... Read more
- Published: Oct. 16, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-11018
An issue was discovered in PbootCMS v1.0.7. Cross-site request forgery (CSRF) vulnerability in apps/admin/controller/system/RoleController.php allows remote attackers to add administrator accounts via admin.php/role/add.html.... Read more
Affected Products : pbootcms- Published: May. 13, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-11017
The newVar_N function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or po... Read more
Affected Products : libming- Published: May. 13, 2018
- Modified: Nov. 21, 2024