Latest CVE Feed
-
6.5
MEDIUMCVE-2018-10998
An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call.... Read more
- Published: May. 12, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-10997
Etere EtereWeb before 28.1.20 has a pre-authentication blind SQL injection in the POST parameters txUserName and txPassword.... Read more
Affected Products : etereweb- Published: Jun. 17, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-10996
The weblogin_log function in /htdocs/cgibin on D-Link DIR-629-B1 devices allows attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a session.cgi?ACTION=logout request involving a long REMOTE_ADDR environment variable.... Read more
- Published: May. 12, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-10995
SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields).... Read more
- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-10994
js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL.... Read more
- Published: May. 14, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10992
lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by a --... Read more
Affected Products : lilypond- Published: May. 11, 2018
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2018-10990
On Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices, a logout action does not immediately destroy all state on the device related to the validity of the "credential" cookie, which might make it easier for attackers to obtain access at a later ... Read more
- Published: May. 14, 2018
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2018-10989
Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices are distributed by some ISPs with a default password of "password" for the admin account that is used over an unencrypted http://192.168.0.1 connection, which might allow remote attackers to byp... Read more
- Published: May. 14, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10988
An issue was discovered on Diqee Diqee360 devices. A firmware update process, integrated into the firmware, starts at boot and tries to find the update folder on the microSD card. It executes code, without a digital signature, as root from the /mnt/sdcard... Read more
- Published: Jul. 05, 2018
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2018-10987
An issue was discovered on Dongguan Diqee Diqee360 devices. The affected vacuum cleaner suffers from an authenticated remote code execution vulnerability. An authenticated attacker can send a specially crafted UDP packet, and execute commands on the vacuu... Read more
- Published: Jul. 05, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGH- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10982
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (unexpectedly high interrupt number, array overrun, and hypervisor crash) or possibly gain hypervisor privileges by setting up an HPET timer to deli... Read more
- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10981
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users to cause a denial of service (host OS infinite loop) in situations where a QEMU device model attempts to make invalid transitions between states of a request.... Read more
- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10977
In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x002220E4.... Read more
- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10976
In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x00222050.... Read more
- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10975
In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x00222104.... Read more
- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10974
In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x00222100.... Read more
- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-10973
An integer overflow in the transferMulti function of a smart contract implementation for KoreaShow, an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets via crafted _value parameters.... Read more
Affected Products : koreashow- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10972
An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The TransformPaletteC::process function in transform/palette_C.hpp allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impac... Read more
Affected Products : free_lossless_image_format- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-10971
An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The Plane function in image/image.hpp allows remote attackers to cause a denial of service (attempted excessive memory allocation) via a crafted file.... Read more
Affected Products : flif- Published: May. 10, 2018
- Modified: Nov. 21, 2024