Latest CVE Feed
-
6.1
MEDIUMCVE-2018-11450
A reflected Cross-Site-Scripting (XSS) vulnerability has been identified in Siemens PLM Software TEAMCENTER (V9.1.2.5). If a user visits the login portal through the URL crafted by the attacker, the attacker can insert html/javascript and thus alter/rewri... Read more
Affected Products : teamcenter_product_lifecycle_management- Published: Jul. 09, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-11449
A vulnerability has been identified in SCALANCE M875 (All versions). An attacker with access to the local file system might obtain passwords for administrative users. Successful exploitation requires read access to files on the local file system. A succes... Read more
- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-11448
A vulnerability has been identified in SCALANCE M875 (All versions). The web interface on port 443/tcp could allow a stored Cross-Site Scripting (XSS) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requi... Read more
- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-11447
A vulnerability has been identified in SCALANCE M875 (All versions). The web interface on port 443/tcp could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requi... Read more
- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-11446
The buy function of a smart contract implementation for Gold Reward (GRX), an Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the buyer because of overflow of the multiplication of its argument amount and a ma... Read more
Affected Products : gold_reward- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-11445
A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing 1.0. A User can be added with the Admin role.... Read more
Affected Products : easyservice_billing- Published: May. 25, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11444
A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0.... Read more
Affected Products : easyservice_billing- Published: May. 25, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-11443
The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.... Read more
Affected Products : easyservice_billing- Published: May. 25, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-11442
A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= URI, as demonstrated by adding a new quotation.... Read more
Affected Products : easyservice_billing- Published: May. 25, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-11440
Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c.... Read more
- Published: May. 25, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-11439
The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted audio file.... Read more
- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-11438
The mobi_decompress_lz77 function in compression.c in Libmobi 0.3 allows remote attackers to cause remote code execution (heap-based buffer overflow) via a crafted mobi file.... Read more
Affected Products : libmobi- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-11437
The mobi_reconstruct_parts function in parse_rawml.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file.... Read more
Affected Products : libmobi- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-11436
The buffer_addraw function in buffer.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.... Read more
Affected Products : libmobi- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-11435
The mobi_decompress_huffman_internal function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file.... Read more
Affected Products : libmobi- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-11434
The buffer_fill64 function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.... Read more
Affected Products : libmobi- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-11433
The mobi_get_kf8boundary_seqnumber function in util.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.... Read more
Affected Products : libmobi- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-11432
The mobi_parse_mobiheader function in read.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.... Read more
Affected Products : libmobi- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-11430
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea.... Read more
Affected Products : moderator_log_notes- Published: May. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-11429
ATLANT (ATL) is a smart contract running on Ethereum. The mint function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner.... Read more
Affected Products : atlant- Published: Jul. 04, 2018
- Modified: Nov. 21, 2024