Latest CVE Feed
-
9.8
CRITICALCVE-2018-11747
Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container. In version 1.4.0, a unique certificate will be generated on installation or the user will be able to provide their own TLS certificate for ingress.... Read more
Affected Products : discovery- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11746
In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure channels if a HTTPS server is not available. This can expose the login credentials being used by Puppet Dis... Read more
Affected Products : discovery- Published: Jul. 03, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2018-11744
Cloudera Manager through 5.15 has Incorrect Access Control.... Read more
Affected Products : cloudera_manager- Published: Jul. 11, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11743
The init_copy function in kernel.c in mruby 1.4.1 makes initialize_copy calls for TT_ICLASS objects, which allows attackers to cause a denial of service (mrb_hash_keys uninitialized pointer and application crash) or possibly have unspecified other impact.... Read more
- Published: Jun. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11742
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.... Read more
- Published: Dec. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11741
NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GOTO(8) URIs.... Read more
- Published: Dec. 26, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2018-11740
An issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function tsk_UTF16toUTF8 in tsk/base/tsk_unicode.c which could be leveraged by an attacker to di... Read more
Affected Products : the_sleuth_kit- Published: Jun. 05, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2018-11739
An issue was discovered in libtskimg.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function raw_read in tsk/img/raw.c which could be leveraged by an attacker to disclose informatio... Read more
Affected Products : the_sleuth_kit- Published: Jun. 05, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2018-11738
An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function ntfs_make_data_run in tsk/fs/ntfs.c which could be leveraged by an attacker to disclose i... Read more
Affected Products : the_sleuth_kit- Published: Jun. 05, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2018-11737
An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function ntfs_fix_idxrec in tsk/fs/ntfs_dent.cpp which could be leveraged by an attacker to disclo... Read more
Affected Products : the_sleuth_kit- Published: Jun. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11736
An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file.... Read more
Affected Products : pluck- Published: Jun. 05, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-11735
index.php?action=createaccount in Ximdex 4.0 has XSS via the sname or fname parameter.... Read more
Affected Products : ximdex- Published: Jun. 05, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-11734
In e107 v2.1.7, output without filtering results in XSS.... Read more
Affected Products : e107- Published: Jul. 10, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11731
The libfsntfs_mft_entry_read_attributes function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this ... Read more
Affected Products : libfsntfs- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11730
The libfsntfs_security_descriptor_values_free function in libfsntfs_security_descriptor_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause a denial of service (double-free) via a crafted ntfs file. NOTE: the vendor has disputed this... Read more
Affected Products : libfsntfs- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11729
The libfsntfs_mft_entry_read_header function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as d... Read more
Affected Products : libfsntfs- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11728
The libfsntfs_reparse_point_values_read_data function in libfsntfs_reparse_point_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor ha... Read more
Affected Products : libfsntfs- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11727
The libfsntfs_attribute_read_from_mft function in libfsntfs_attribute.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as... Read more
Affected Products : libfsntfs- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-11726
The mobi_decode_font_resource function in util.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted mobi file.... Read more
Affected Products : libmobi- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-11725
The mobi_parse_index_entry function in index.c in Libmobi 0.3 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted mobi file.... Read more
Affected Products : libmobi- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024