Total
11158 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-13361 | 1 Terra-master | 1 Terramaster Operating System | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
User enumeration in usertable.php in TerraMaster TOS version 3.1.03 allows attackers to list all system users via the "modgroup" parameter. | |||||
CVE-2018-13348 | 1 Mercurial | 1 Mercurial | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 mishandles certain situations where there should be at least 12 bytes remaining after the current position in the patch data, but actually are not, aka OVE-20180430-0001. | |||||
CVE-2018-13346 | 1 Mercurial | 1 Mercurial | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of the original data, aka OVE-20180430-0004. | |||||
CVE-2018-13315 | 1 Totolink | 2 A3002ru, A3002ru Firmware | 2024-11-21 | 5.0 MEDIUM | 9.8 CRITICAL |
Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request. | |||||
CVE-2018-13259 | 2 Canonical, Zsh | 2 Ubuntu Linux, Zsh | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in zsh before 5.6. Shebang lines exceeding 64 characters were truncated, potentially leading to an execve call to a program name that is a substring of the intended one. | |||||
CVE-2018-13115 | 1 Keruigroup | 2 Ypc99, Ypc99 Firmware | 2024-11-21 | 6.4 MEDIUM | 6.5 MEDIUM |
Lack of an authentication mechanism in KERUI Wifi Endoscope Camera (YPC99) allows an attacker to watch or block the camera stream. The RTSP server on port 7070 accepts the command STOP to stop streaming, and the command SETSSID to disconnect a user. | |||||
CVE-2018-13111 | 1 Wanscam | 2 Hw0021, Hw0021 Firmware | 2024-11-21 | 4.3 MEDIUM | 5.9 MEDIUM |
There exists a partial Denial of Service vulnerability in Wanscam HW0021 IP Cameras. An attacker could craft a malicious POST request to crash the ONVIF service on such a device. | |||||
CVE-2018-13056 | 1 Zzcms | 1 Zzcms | 2024-11-21 | 6.4 MEDIUM | 7.5 HIGH |
An issue was discovered on zzcms 8.3. There is a vulnerability at /user/del.php that can delete any file by placing its relative path into the zzcms_main table and then making an img add request. This can be leveraged for database access by deleting install.lock. | |||||
CVE-2018-13042 | 1 1password | 1 1password | 2024-11-21 | 4.3 MEDIUM | 5.9 MEDIUM |
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity or com.agilebits.onepassword.filling.openyolo.OpenYoloRetrieveActivity from an external application (since they are exported), it is possible to crash the 1Password instance. | |||||
CVE-2018-12999 | 1 Zohocorp | 1 Manageengine Desktop Central | 2024-11-21 | 6.4 MEDIUM | 7.5 HIGH |
Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ substring to the /agenttrayicon URI. | |||||
CVE-2018-12988 | 1 Greencms | 1 Greencms | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
GreenCMS 2.3.0603 has an arbitrary file download vulnerability via an index.php?m=admin&c=media&a=downfile URI. | |||||
CVE-2018-12959 | 1 Aditustoken Project | 1 Aditustoken | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
The approveAndCall function of a smart contract implementation for Aditus (ADI), an Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer all contract balances into their account). | |||||
CVE-2018-12941 | 1 Seeddms | 1 Seeddms | 2024-11-21 | 9.0 HIGH | 8.8 HIGH |
This vulnerability allows remote attackers to execute arbitrary code in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 by adding a system command at the end of the "cacheDir" path and following usage of the "Clear Cache" functionality. This allows an authenticated attacker, with permission to the Settings functionality, to inject arbitrary system commands within the application by manipulating the "Cache directory" path. An attacker can use it to perform malicious tasks such as to extract, change, or delete sensitive information or run system commands on the underlying operating system. | |||||
CVE-2018-12807 | 1 Adobe | 1 Experience Manager | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have an input validation bypass vulnerability. Successful exploitation could lead to unauthorized information modification. | |||||
CVE-2018-12712 | 1 Joomla | 1 Joomla\! | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, using the "class_exists" function in PHP. In PHP 5.3, this function validates invalid names as valid, which can result in a Local File Inclusion. | |||||
CVE-2018-12703 | 1 Block18 | 1 Block18 | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
The approveAndCallcode function of a smart contract implementation for Block 18 (18T), an tradable Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer the contract's balances into their account) because the callcode (i.e., _spender.call(_extraData)) is not verified, aka the "evilReflex" issue. NOTE: a PeckShield disclosure states "some researchers have independently discussed the mechanism of such vulnerability." | |||||
CVE-2018-12702 | 1 Gve | 1 Globalvillage Ecosystem | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
The approveAndCallcode function of a smart contract implementation for Globalvillage ecosystem (GVE), an Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer the contract's balances into their account) because the callcode (i.e., _spender.call(_extraData)) is not verified, aka the "evilReflex" issue. NOTE: a PeckShield disclosure states "some researchers have independently discussed the mechanism of such vulnerability." | |||||
CVE-2018-12694 | 1 Tp-link | 2 Tl-wa850re, Tl-wa850re Firmware | 2024-11-21 | 7.8 HIGH | 7.5 HIGH |
TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote attackers to cause a denial of service (reboot) via data/reboot.json. | |||||
CVE-2018-12688 | 1 Tinyexr Project | 1 Tinyexr | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
tinyexr 0.9.5 has a segmentation fault in the wav2Decode function. | |||||
CVE-2018-12635 | 1 Circontrol | 1 Scada | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
CirCarLife Scada v4.2.4 allows unauthorized upgrades via requests to the html/upgrade.html and services/system/firmware.upgrade URIs. |