Latest CVE Feed
-
8.8
HIGHCVE-2018-0509
Cross-site request forgery (CSRF) vulnerability in epg search result viewer (kkcald) 0.7.21 and earlier allows an attacker to hijack the authentication of administrators via unspecified vectors.... Read more
Affected Products : kkcald- Published: Feb. 01, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0508
Cross-site scripting vulnerability in epg search result viewer (kkcald) 0.7.21 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : kkcald- Published: Feb. 01, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0507
Untrusted search path vulnerability in FLET'S VIRUS CLEAR Easy Setup & Application Tool ver.11 and earlier versions, FLET'S VIRUS CLEAR v6 Easy Setup & Application Tool ver.11 and earlier versions allow an attacker to gain privileges via a Trojan horse DL... Read more
- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-0506
Nootka 1.4.4 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.... Read more
Affected Products : nootka- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0505
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock... Read more
- Published: Oct. 04, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0504
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid... Read more
- Published: Oct. 04, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-0503
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimits entry for 'user' overrides that for 'newbie'.... Read more
- Published: Oct. 04, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0502
An issue was discovered in zsh before 5.6. The beginning of a #! script file was mishandled, potentially leading to an execve call to a program named on the second line.... Read more
- Published: Sep. 05, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2018-0501
The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verification for the InRelease file of a fallback mirror, aka mirrorfail.... Read more
- Published: Aug. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0500
Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that might be exploitable by an attacker who can control the data that curl transmits over SMTP with certain settings (i.e., use of a nonstanda... Read more
- Published: Jul. 11, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0499
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().... Read more
- Published: Jul. 02, 2018
- Modified: Nov. 21, 2024
-
4.7
MEDIUMCVE-2018-0498
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack.... Read more
- Published: Jul. 28, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2018-0497
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuite) via a timing-based side-channel attack. This vulnerability exists because of an incorrect fix (with a w... Read more
- Published: Jul. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0496
Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allow an attacker to overwrite arbitrary files on the user's system.... Read more
- Published: Jun. 12, 2018
- Modified: Nov. 21, 2024
-
4.7
MEDIUMCVE-2018-0495
Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the R... Read more
- Published: Jun. 13, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0494
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.... Read more
- Published: May. 06, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-0493
remctld in remctl before 3.14, when an attacker is authorized to execute a command that uses the sudo option, has a use-after-free that leads to a daemon crash, memory corruption, or arbitrary command execution.... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2018-0492
Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0491
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a channel to be added more than once in the pending list.... Read more
Affected Products : tor- Published: Mar. 05, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0490
An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-authority protocol-list subprotocol implementation allows remote attackers to cause a denial of service (NULL pointer dereference and direc... Read more
- Published: Mar. 05, 2018
- Modified: Nov. 21, 2024