Latest CVE Feed
-
5.5
MEDIUMCVE-2018-10534
The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, processes a negative Data Directory size with an unbounded loop that increases the value of ... Read more
Affected Products : enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation binutils- Published: Apr. 29, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10532
An issue was discovered on EE 4GEE HH70VB-2BE8GB3 HH70_E1_02.00_19 devices. Hardcoded root SSH credentials were discovered to be stored within the "core_app" binary utilised by the EE router for networking services. An attacker with knowledge of the defau... Read more
- Published: Oct. 30, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-10531
An issue was discovered in the America's Army Proving Grounds platform for the Unreal Engine. With a false packet sent via UDP, the application server responds with several bytes, giving the possibility of DoS amplification, even being able to be used in ... Read more
Affected Products : proving_grounds- Published: Jul. 10, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10529
An issue was discovered in LibRaw 0.18.9. There is an out-of-bounds read affecting the X3F property table list implementation in libraw_x3f.cpp and libraw_cxx.cpp.... Read more
- Published: Apr. 29, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10528
An issue was discovered in LibRaw 0.18.9. There is a stack-based buffer overflow in the utf2char function in libraw_cxx.cpp.... Read more
- Published: Apr. 29, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-10527
EasyCMS 1.3 is prone to Stored XSS when posting an article; four fields are affected: title, keyword, abstract, and content, as demonstrated by the /admin/index/index.html#listarticle URI.... Read more
- Published: Apr. 28, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-10523
CMS Made Simple (CMSMS) through 2.2.7 contains a physical path leakage Vulnerability via /modules/DesignManager/action.ajax_get_templates.php, /modules/DesignManager/action.ajax_get_stylesheets.php, /modules/FileManager/dunzip.php, or /modules/FileManager... Read more
Affected Products : cms_made_simple- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2018-10522
In CMS Made Simple (CMSMS) through 2.2.7, the "file view" operation in the admin dashboard contains a sensitive information disclosure vulnerability, exploitable by ordinary users, because the product exposes unrestricted access to the PHP file_get_conten... Read more
Affected Products : cms_made_simple- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2018-10521
In CMS Made Simple (CMSMS) through 2.2.7, the "file move" operation in the admin dashboard contains an arbitrary file movement vulnerability that can cause DoS, exploitable by an admin user, because config.php can be moved into an incorrect directory.... Read more
Affected Products : cms_made_simple- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2018-10520
In CMS Made Simple (CMSMS) through 2.2.7, the "module remove" operation in the admin dashboard contains an arbitrary file deletion vulnerability that can cause DoS, exploitable by an admin user, because the attacker can remove all lib/ files in all direct... Read more
Affected Products : cms_made_simple- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10519
CMS Made Simple (CMSMS) 2.2.7 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value within $_COOKIE[$this->_loginkey] to equal 1, because files in the tmp/ directory are accessible through HTTP r... Read more
Affected Products : cms_made_simple- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2018-10518
In CMS Made Simple (CMSMS) through 2.2.7, the "file delete" operation in the admin dashboard contains an arbitrary file deletion vulnerability that can cause DoS, exploitable by an admin user, because the attacker can remove all lib/ files in all director... Read more
Affected Products : cms_made_simple- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-10517
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element.... Read more
Affected Products : cms_made_simple- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10516
In CMS Made Simple (CMSMS) through 2.2.7, the "file rename" operation in the admin dashboard contains a sensitive information disclosure vulnerability, exploitable by an admin user, that can cause DoS by moving config.php to the upload/ directory.... Read more
Affected Products : cms_made_simple- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-10515
In CMS Made Simple (CMSMS) through 2.2.7, the "file unpack" operation in the admin dashboard contains a remote code execution vulnerability exploitable by an admin user because a .php file can be present in the extracted ZIP archive.... Read more
Affected Products : cms_made_simple- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10514
A Missing Impersonation Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute low-privilege... Read more
Affected Products : antivirus_\+_security internet_security maximum_security premium_security windows- Published: Aug. 30, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10513
A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to execute l... Read more
Affected Products : antivirus_\+_security internet_security maximum_security premium_security windows- Published: Aug. 30, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-10512
A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to manipulate a reverse proxy .dll on vulnerable installations, which may lead to a denial of server (DoS).... Read more
- Published: Aug. 15, 2018
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2018-10511
A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack on vulnerable installations.... Read more
Affected Products : control_manager- Published: Aug. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10510
A Directory Traversal Remote Code Execution vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to execute arbitrary code on vulnerable installations.... Read more
- Published: Aug. 15, 2018
- Modified: Nov. 21, 2024