Latest CVE Feed
-
4.7
MEDIUMCVE-2018-0746
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are h... Read more
- Published: Jan. 04, 2018
- Modified: Nov. 21, 2024
-
4.7
MEDIUMCVE-2018-0745
The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Windows Information Disclosure Vulnerability". This ... Read more
- Published: Jan. 04, 2018
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2018-0744
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in... Read more
- Published: Jan. 04, 2018
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2018-0743
Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Subsystem for Linux Elevation of Pr... Read more
- Published: Jan. 04, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-0742
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege ... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-0741
The Color Management Module (Icm32.dll) in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Microsoft Color Management Information Disclosure Vulnerabili... Read more
- Published: Jan. 04, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0739
Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within... Read more
- Published: Mar. 27, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2018-0737
The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could recover the private key. Fixed in ... Read more
- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2018-0735
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL ... Read more
Affected Products : ubuntu_linux debian_linux cloud_backup steelstore cn1610_firmware mysql peoplesoft_enterprise_peopletools oncommand_unified_manager element_software openssl +13 more products- Published: Oct. 29, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2018-0734
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (A... Read more
Affected Products : ubuntu_linux debian_linux cloud_backup e-business_suite_technology_stack steelstore cn1610_firmware peoplesoft_enterprise_peopletools oncommand_unified_manager snapcenter openssl +10 more products- Published: Oct. 30, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2018-0733
Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least significant bit of each byte. This allows an attacker to forge messages that would be considered as authenticated in an amount of tries ... Read more
Affected Products : openssl- Published: Mar. 27, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0732
During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting i... Read more
- Published: Jun. 12, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0730
This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.... Read more
Affected Products : qts- Published: Dec. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0729
This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions.... Read more
- Published: Dec. 04, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0728
This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions.... Read more
- Published: Dec. 04, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0724
Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascript code in the compromised application, a different vulnerability than CVE-2018-0723.... Read more
Affected Products : q\'center_virtual_appliance- Published: Dec. 26, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0723
Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascript code in the compromised application, a different vulnerability than CVE-2018-0724.... Read more
Affected Products : q\'center_virtual_appliance- Published: Dec. 26, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0722
Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the device.... Read more
- Published: Feb. 01, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-0721
Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; version 4.3.3 and prior versions on build 20180725; version 4.3.4 and p... Read more
Affected Products : qts- Published: Nov. 27, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-0719
Cross-site Scripting (XSS) vulnerability in NAS devices of QNAP Systems Inc. QTS allows attackers to inject javascript. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; version 4.3.3 and prior versions on build... Read more
Affected Products : qts- Published: Nov. 27, 2018
- Modified: Nov. 21, 2024