National Vulnerability Database

Subscribe to National Vulnerability Database feed
This feed contains the most recent CVE cyber vulnerabilities published within the National Vulnerability Database.
Updated: 5 hours 25 min ago

CVE-2018-2379

Wed, 02/14/2018 - 07:29
In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint.
Categories: Security News

CVE-2018-2381

Wed, 02/14/2018 - 07:29
SAP ERP Financials Information System (SAP_APPL 6.00, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16; SAP_FIN 6.17, 6.18, 7.00, 7.20, 7.30 S4CORE 1.00, 1.01, 1.02) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Categories: Security News

CVE-2018-2382

Wed, 02/14/2018 - 07:29
A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to store graphics in a controlled area and as such gain information from system area, which is not available to the user otherwise.
Categories: Security News

CVE-2017-15699

Tue, 02/13/2018 - 17:29
A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vulnerability, a remote user must be able to establish an AMQP connection to the Qpid Dispatch Router and send a specifically crafted AMQP frame which will cause it to segfault and shut down.
Categories: Security News

CVE-2018-5459

Tue, 02/13/2018 - 16:29
An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some unauthenticated commands such as reading, writing, or deleting arbitrary files, or manipulate the PLC application during runtime by sending specially-crafted TCP packets to Port 2455.
Categories: Security News

CVE-2018-6910

Tue, 02/13/2018 - 16:29
DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.
Categories: Security News

CVE-2017-15709

Tue, 02/13/2018 - 15:29
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
Categories: Security News

CVE-2017-1711

Tue, 02/13/2018 - 15:29
IBM iNotes 8.5 and 9.0 SUService can be misguided into running malicious code from a DLL masquerading as a windows DLL in the temp directory. IBM X-Force ID: 134532.
Categories: Security News

CVE-2017-1714

Tue, 02/13/2018 - 15:29
IBM Notes and Domino NSD 8.5 and 9.0 could allow an authenticated local user without adminstrative privileges to gain System privilege. IBM X-Force ID: 134633.
Categories: Security News

CVE-2017-1720

Tue, 02/13/2018 - 15:29
IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC. IBM X-Force ID: 134807.
Categories: Security News

CVE-2018-1383

Tue, 02/13/2018 - 15:29
A software logic bug creates a vulnerability in an AIX 6.1, 7.1, and 7.2 daemon which could allow a user with root privileges on one system, to obtain root access on another machine. IBM X-force ID: 138117.
Categories: Security News

CVE-2018-6953

Tue, 02/13/2018 - 15:29
In CCN-lite 2, the Parser of NDNTLV does not verify whether a certain component's length field matches the actual component length, which has a resultant buffer overflow and out-of-bounds memory accesses.
Categories: Security News

CVE-2018-6954

Tue, 02/13/2018 - 15:29
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.
Categories: Security News

CVE-2015-9252

Tue, 02/13/2018 - 14:29
An issue was discovered in QPDF before 7.0.0. Endless recursion causes stack exhaustion in QPDFTokenizer::resolveLiteral() in QPDFTokenizer.cc, related to the QPDF::resolve function in QPDF.cc.
Categories: Security News

CVE-2016-10713

Tue, 02/13/2018 - 14:29
An issue was discovered in GNU patch before 2.7.6. Out-of-bounds access within pch_write_line() in pch.c can possibly lead to DoS via a crafted input file.
Categories: Security News

CVE-2017-18183

Tue, 02/13/2018 - 14:29
An issue was discovered in QPDF before 7.0.0. There is an infinite loop in the QPDFWriter::enqueueObject() function in libqpdf/QPDFWriter.cc.
Categories: Security News

CVE-2017-18184

Tue, 02/13/2018 - 14:29
An issue was discovered in QPDF before 7.0.0. There is a stack-based out-of-bounds read in the function iterate_rc4 in QPDF_encryption.cc.
Categories: Security News

CVE-2017-18185

Tue, 02/13/2018 - 14:29
An issue was discovered in QPDF before 7.0.0. There is a large heap-based out-of-bounds read in the Pl_Buffer::write function in Pl_Buffer.cc. It is caused by an integer overflow in the PNG filter.
Categories: Security News

CVE-2017-18186

Tue, 02/13/2018 - 14:29
An issue was discovered in QPDF before 7.0.0. There is an infinite loop due to looping xref tables in QPDF.cc.
Categories: Security News

CVE-2018-6951

Tue, 02/13/2018 - 14:29
An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a "mangled rename" issue.
Categories: Security News

Pages