Latest CVE Feed
-
5.3
MEDIUMCVE-2018-11409
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by discovering a license key.... Read more
Affected Products : splunk- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-11408
The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a containe... Read more
- Published: Jun. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11407
An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, whi... Read more
Affected Products : symfony- Published: Jun. 13, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-11406
An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is logged out. This behavio... Read more
- Published: Jun. 13, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-11405
Kliqqi 2.0.2 has CSRF in admin/admin_users.php.... Read more
Affected Products : kliqqi_cms- Published: May. 24, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-11404
DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.... Read more
Affected Products : domainmod- Published: May. 24, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-11403
DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.... Read more
Affected Products : domainmod- Published: May. 24, 2018
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2018-11402
SimpliSafe Original has Unencrypted Keypad Transmissions, which allows physically proximate attackers to discover the PIN.... Read more
- Published: May. 24, 2018
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2018-11401
In SimpliSafe Original, RF Interference (e.g., an extremely strong 433.92 MHz signal) by a physically proximate attacker does not cause a notification.... Read more
- Published: May. 24, 2018
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2018-11400
In SimpliSafe Original, the Base Station fails to detect tamper attempts: it does not send a notification if a physically proximate attacker removes the battery and external power.... Read more
- Published: May. 24, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-11399
SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentially sensitive information about the specific times when alarm-system events occur.... Read more
- Published: May. 24, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-11396
ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrated by a crafted window.open call.... Read more
Affected Products : epiphany- Published: May. 23, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-11392
An arbitrary file upload vulnerability in /classes/profile.class.php in Jigowatt "PHP Login & User Management" before 4.1.1, as distributed in the Envato Market, allows any remote authenticated user to upload .php files to the web server via a profile ava... Read more
Affected Products : php_login_\&_user_management- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2018-11386
An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under ... Read more
- Published: Jun. 13, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2018-11385
An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login feature may allow an attack... Read more
- Published: Jun. 13, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11384
The sh_op() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted ELF file.... Read more
Affected Products : radare2- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11383
The r_strbuf_fini() function in radare2 2.5.0 allows remote attackers to cause a denial of service (invalid free and application crash) via a crafted ELF file because of an uninitialized variable in the CPSE handler in libr/anal/p/anal_avr.c.... Read more
Affected Products : radare2- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11382
The _inst__sts() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.... Read more
Affected Products : radare2- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11381
The string_scan_range() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.... Read more
Affected Products : radare2- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11380
The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted Mach-O file.... Read more
Affected Products : radare2- Published: May. 22, 2018
- Modified: Nov. 21, 2024