Security News

CVE-2018-18950

National Vulnerability Database - Mon, 11/05/2018 - 04:29
KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directory in the kindeditor/attached/ folder via the path parameter without authentication.
Categories: Security News

CVE-2018-18952

National Vulnerability Database - Mon, 11/05/2018 - 04:29
JEECMS 9.3 has XSS via an index.do#/content/update?type=update URI.
Categories: Security News

CVE-2018-18928

National Vulnerability Database - Sun, 11/04/2018 - 15:29
International Components for Unicode (ICU) for C/C++ 63.1 has an integer overflow in number::impl::DecimalQuantity::toScientificString() in i18n/number_decimalquantity.cpp.
Categories: Security News

CVE-2018-18919

National Vulnerability Database - Sun, 11/04/2018 - 01:29
The WP Editor.md plugin 10.0.1 for WordPress allows XSS via the comment area.
Categories: Security News

CVE-2018-18924

National Vulnerability Database - Sun, 11/04/2018 - 01:29
The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" because rejected files remain on the server, with predictable filenames, after a "This file is not a valid image" error message.
Categories: Security News

CVE-2018-18925

National Vulnerability Database - Sun, 11/04/2018 - 01:29
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. This is related to session ID handling in the go-macaron/session code for Macaron.
Categories: Security News

CVE-2018-18926

National Vulnerability Database - Sun, 11/04/2018 - 01:29
Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to session ID handling in the go-macaron/session code for Macaron.
Categories: Security News

CVE-2018-18927

National Vulnerability Database - Sun, 11/04/2018 - 01:29
An issue was discovered in PublicCMS V4.0. It allows XSS by modifying the page_list "attached" attribute (which typically has 'class="icon-globe icon-large"' in its value), as demonstrated by an 'UPDATE sys_module SET attached = "[XSS]" WHERE id="page_list"' statement.
Categories: Security News

CVE-2018-18909

National Vulnerability Database - Sat, 11/03/2018 - 12:29
xhEditor 1.2.2 allows XSS via JavaScript code in the SRC attribute of an IFRAME element within the editor's source-code view.
Categories: Security News

CVE-2018-18903

National Vulnerability Database - Sat, 11/03/2018 - 01:29
Vanilla 2.6.x before 2.6.4 allows remote code execution.
Categories: Security News

CVE-2018-18915

National Vulnerability Database - Sat, 11/03/2018 - 00:29
There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted input will lead to a remote denial of service attack.
Categories: Security News

CVE-2018-11062

National Vulnerability Database - Fri, 11/02/2018 - 18:29
Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin' that are protected with default passwords. These accounts have limited privileges and can access certain system files only. A malicious user with the knowledge of the default passwords may potentially log in to the system and gain read and write access to certain system files.
Categories: Security News

CVE-2018-15762

National Vulnerability Database - Fri, 11/02/2018 - 18:29
Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator privileges for Opsman.
Categories: Security News

CVE-2018-16847

National Vulnerability Database - Fri, 11/02/2018 - 18:29
An OOB heap buffer r/w access issue was found in the NVM Express Controller emulation in QEMU. It could occur in nvme_cmb_ops routines in nvme device. A guest user/process could use this flaw to crash the QEMU process resulting in DoS or potentially run arbitrary code with privileges of the QEMU process.
Categories: Security News

CVE-2018-16849

National Vulnerability Database - Fri, 11/02/2018 - 17:29
A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor's filesystem.
Categories: Security News

CVE-2018-3890

National Vulnerability Database - Fri, 11/02/2018 - 13:29
An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted file can cause a logic flaw and command injection, resulting in code execution. An attacker can insert an SD card to trigger this vulnerability.
Categories: Security News

CVE-2018-3891

National Vulnerability Database - Fri, 11/02/2018 - 13:29
An exploitable firmware downgrade vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted file can cause a logic flaw, resulting in a firmware downgrade. An attacker can insert an SD card to trigger this vulnerability.
Categories: Security News

CVE-2018-3892

National Vulnerability Database - Fri, 11/02/2018 - 13:29
An exploitable firmware downgrade vulnerability exists in the time syncing functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted packet can cause a buffer overflow, resulting in code execution. An attacker can intercept and alter network traffic to trigger this vulnerability.
Categories: Security News

CVE-2018-3898

National Vulnerability Database - Fri, 11/02/2018 - 13:29
An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. The trans_info call can overwrite a buffer of size 0x104, which is more than enough to overflow the return address from the ssid_dst field.
Categories: Security News

CVE-2018-3899

National Vulnerability Database - Fri, 11/02/2018 - 13:29
An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. The trans_info call can overwrite a buffer of size 0x104, which is more than enough to overflow the return address from the password_dst field
Categories: Security News

Pages