Latest CVE Feed
-
4.7
MEDIUMCVE-2018-0498
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack.... Read more
- Published: Jul. 28, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2018-0497
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuite) via a timing-based side-channel attack. This vulnerability exists because of an incorrect fix (with a w... Read more
- Published: Jul. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0496
Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allow an attacker to overwrite arbitrary files on the user's system.... Read more
- Published: Jun. 12, 2018
- Modified: Nov. 21, 2024
-
4.7
MEDIUMCVE-2018-0495
Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the R... Read more
- Published: Jun. 13, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0494
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.... Read more
- Published: May. 06, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-0493
remctld in remctl before 3.14, when an attacker is authorized to execute a command that uses the sudo option, has a use-after-free that leads to a daemon crash, memory corruption, or arbitrary command execution.... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2018-0492
Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0491
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a channel to be added more than once in the pending list.... Read more
Affected Products : tor- Published: Mar. 05, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0490
An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-authority protocol-list subprotocol implementation allows remote attackers to cause a denial of service (NULL pointer dereference and direc... Read more
- Published: Mar. 05, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0489
Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct impersonation a... Read more
- Published: Feb. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0488
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted application packet within a TLS... Read more
- Published: Feb. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0487
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted certificate chain that is mishandled during RSASSA-PSS signature verification within... Read more
- Published: Feb. 13, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0486
Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct imperso... Read more
- Published: Jan. 13, 2018
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2018-0485
A vulnerability in the SM-1T3/E3 firmware on Cisco Second Generation Integrated Services Routers (ISR G2) and the Cisco 4451-X Integrated Services Router (ISR4451-X) could allow an unauthenticated, remote attacker to cause the ISR G2 Router or the SM-1T3/... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0484
A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in the access-clas... Read more
Affected Products : ios- Published: Jan. 10, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-0483
A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient validation of user-supplied ... Read more
Affected Products : jabber- Published: Jan. 10, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-0482
A vulnerability in the web-based management interface of Cisco Prime Network Control System could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected system. The... Read more
Affected Products : prime_infrastructure- Published: Jan. 10, 2019
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-0481
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exist because the affected software imp... Read more
Affected Products : ios_xe- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0480
A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash, leading to a denial of service (DoS) condition. The vulnerability is due to a race condition that o... Read more
Affected Products : ios_xe- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-0477
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exist because the affected software imp... Read more
Affected Products : ios_xe- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024