Latest CVE Feed
-
9.8
CRITICALCVE-2018-0510
Buffer overflow in epg search result viewer (kkcald) 0.7.19 and earlier allows remote attackers to perform unintended operations or execute DoS (denial of service) attacks via unspecified vectors.... Read more
Affected Products : kkcald- Published: Feb. 01, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-0509
Cross-site request forgery (CSRF) vulnerability in epg search result viewer (kkcald) 0.7.21 and earlier allows an attacker to hijack the authentication of administrators via unspecified vectors.... Read more
Affected Products : kkcald- Published: Feb. 01, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0508
Cross-site scripting vulnerability in epg search result viewer (kkcald) 0.7.21 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : kkcald- Published: Feb. 01, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0507
Untrusted search path vulnerability in FLET'S VIRUS CLEAR Easy Setup & Application Tool ver.11 and earlier versions, FLET'S VIRUS CLEAR v6 Easy Setup & Application Tool ver.11 and earlier versions allow an attacker to gain privileges via a Trojan horse DL... Read more
- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-0506
Nootka 1.4.4 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.... Read more
Affected Products : nootka- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0505
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock... Read more
- Published: Oct. 04, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0504
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid... Read more
- Published: Oct. 04, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-0503
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimits entry for 'user' overrides that for 'newbie'.... Read more
- Published: Oct. 04, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0502
An issue was discovered in zsh before 5.6. The beginning of a #! script file was mishandled, potentially leading to an execve call to a program named on the second line.... Read more
- Published: Sep. 05, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2018-0501
The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verification for the InRelease file of a fallback mirror, aka mirrorfail.... Read more
- Published: Aug. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0500
Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that might be exploitable by an attacker who can control the data that curl transmits over SMTP with certain settings (i.e., use of a nonstanda... Read more
- Published: Jul. 11, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0499
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().... Read more
- Published: Jul. 02, 2018
- Modified: Nov. 21, 2024
-
4.7
MEDIUMCVE-2018-0498
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack.... Read more
- Published: Jul. 28, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2018-0497
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuite) via a timing-based side-channel attack. This vulnerability exists because of an incorrect fix (with a w... Read more
- Published: Jul. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0496
Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allow an attacker to overwrite arbitrary files on the user's system.... Read more
- Published: Jun. 12, 2018
- Modified: Nov. 21, 2024
-
4.7
MEDIUMCVE-2018-0495
Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the R... Read more
- Published: Jun. 13, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0494
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.... Read more
- Published: May. 06, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-0493
remctld in remctl before 3.14, when an attacker is authorized to execute a command that uses the sudo option, has a use-after-free that leads to a daemon crash, memory corruption, or arbitrary command execution.... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2018-0492
Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0491
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a channel to be added more than once in the pending list.... Read more
Affected Products : tor- Published: Mar. 05, 2018
- Modified: Nov. 21, 2024