Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-13312 1 Totolink 2 A3002ru, A3002ru Firmware 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "Input your notice URL" field.
CVE-2018-13308 1 Totolink 2 A3002ru, A3002ru Firmware 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in notice_gen.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript by modifying the "User phrases button" field.
CVE-2018-13309 1 Totolink 2 A3002ru, A3002ru Firmware 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's password.
CVE-2018-13310 1 Totolink 2 A3002ru, A3002ru Firmware 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting in password.htm in TOTOLINK A3002RU version 1.0.8 allows attackers to execute arbitrary JavaScript via the user's username.
CVE-2018-6066 3 Debian, Google, Redhat 5 Debian Linux, Chrome, Linux Desktop and 2 more 2018-12-19 4.3 MEDIUM 6.5 MEDIUM
Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2018-6068 3 Debian, Google, Redhat 5 Debian Linux, Chrome, Linux Desktop and 2 more 2018-12-19 4.3 MEDIUM 4.3 MEDIUM
Object lifecycle issue in Chrome Custom Tab in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2018-6075 3 Debian, Google, Redhat 5 Debian Linux, Chrome, Linux Desktop and 2 more 2018-12-19 4.3 MEDIUM 6.5 MEDIUM
Incorrect handling of specified filenames in file downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page and user interaction.
CVE-2018-6076 3 Debian, Google, Redhat 5 Debian Linux, Chrome, Linux Desktop and 2 more 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based XSS attack via a crafted HTML page.
CVE-2018-19517 1 Sysstat Project 1 Sysstat 2018-12-19 4.3 MEDIUM 5.5 MEDIUM
An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a memset call, as demonstrated by sadf.
CVE-2018-19406 1 Linux 1 Linux Kernel 2018-12-19 4.9 MEDIUM 5.5 MEDIUM
kvm_pv_send_ipi in arch/x86/kvm/lapic.c in the Linux kernel through 4.19.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) via crafted system calls that reach a situation where the apic map is uninitialized.
CVE-2018-19469 1 Articlecms Project 1 Articlecms 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter.
CVE-2018-19544 1 Jeecms 1 Jeecms 2018-12-19 4.3 MEDIUM 6.5 MEDIUM
JEECMS 9.3 has CSRF via the api/admin/content/save URI to add news.
CVE-2018-19547 1 Jtbc 1 Jtbc Php 2018-12-19 4.3 MEDIUM 6.1 MEDIUM
JTBC(PHP) 3.0.1.7 has XSS via the console/xml/manage.php?type=action&action=edit content parameter.
CVE-2018-10099 1 Google 1 Monorail 2018-12-18 4.3 MEDIUM 5.3 MEDIUM
Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with duplicated columns) can be used to obtain sensitive information about the content of bug reports.
CVE-2018-19334 1 Google 1 Monorail 2018-12-18 4.3 MEDIUM 5.3 MEDIUM
Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with an unsupported axis) can be used to obtain sensitive information about the content of bug reports.
CVE-2018-19564 1 Goldplugins 1 Easy Testimonials 2018-12-18 4.3 MEDIUM 6.1 MEDIUM
Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_client and _ikcf_position and _ikcf_other) have Cross-Site Scripting.
CVE-2015-9274 1 Harfbuzz Project 1 Harfbuzz 2018-12-18 4.3 MEDIUM 6.5 MEDIUM
HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-table.hh, hb-ot-layout-gsub-table.hh, and hb-ot-layout-gsubgpos-private.hh.
CVE-2018-19433 1 Showdoc 1 Showdoc 2018-12-18 4.3 MEDIUM 6.1 MEDIUM
ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.
CVE-2018-19376 1 Greencms 1 Greencms 2018-12-18 5.8 MEDIUM 6.5 MEDIUM
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to delete a log file via the index.php?m=admin&c=data&a=clear URI.
CVE-2018-18760 1 Saltos 1 Rhinos 2018-12-17 4.3 MEDIUM 6.5 MEDIUM
RhinOS 3.0 build 1190 allows CSRF.
CVE-2018-19324 1 Kimsq 1 Rb 2018-12-17 3.5 LOW 5.4 MEDIUM
kimsQ Rb 2.3.0 allows XSS via the second input field to the /?r=home&mod=mypage&page=info URI.
CVE-2018-19319 1 Srcms Project 1 Srcms 2018-12-17 4.3 MEDIUM 6.5 MEDIUM
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.
CVE-2018-16619 1 Sonatype 1 Nexus Repository Manager 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
Sonatype Nexus Repository Manager before 3.14 allows XSS.
CVE-2018-19340 1 Guriddo 1 Form Php 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
Guriddo Form PHP 5.3 has XSS via the demos/jqform/defaultnodb/default.php OrderID, ShipName, ShipAddress, ShipCity, ShipPostalCode, ShipCountry, Freight, or details parameter.
CVE-2018-0695 1 Usvn 1 Usvn 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in User-friendly SVN (USVN) Version 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-19187 1 Amazon 1 Payfort-php-sdk 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in a success.php echo statement.
CVE-2018-19190 1 Amazon 1 Payfort-php-sdk 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the error.php error_msg parameter.
CVE-2018-19189 1 Amazon 1 Payfort-php-sdk 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement.
CVE-2018-19188 1 Amazon 1 Payfort-php-sdk 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the success.php fort_id parameter.
CVE-2018-19186 1 Amazon 1 Payfort-php-sdk 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the route.php paymentMethod parameter.
CVE-2008-7320 1 Gnome 1 Seahorse 2018-12-17 2.1 LOW 6.8 MEDIUM
** DISPUTED ** GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow dialog at an unattended workstation, if the keyring is unlocked. NOTE: this is disputed by a software maintainer because the behavior represents a design decision.
CVE-2018-8600 1 Microsoft 1 Azure App Service On Azure Stack 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
A Cross-site Scripting (XSS) vulnerability exists when Azure App Services on Azure Stack does not properly sanitize user provided input, aka "Azure App Service Cross-site Scripting Vulnerability." This affects Azure App.
CVE-2018-19353 1 Ansilove 1 Libansilove 2018-12-17 4.3 MEDIUM 6.5 MEDIUM
The ansilove_ansi function in loaders/ansi.c in libansilove 1.0.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.
CVE-2018-9544 1 Google 1 Android 2018-12-17 2.1 LOW 5.5 MEDIUM
In register_app of btif_hd.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure in the Bluetooth service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-113037220
CVE-2018-8454 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2018-12-17 2.1 LOW 5.5 MEDIUM
An information disclosure vulnerability exists when Windows Audio Service fails to properly handle objects in memory, aka "Windows Audio Service Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019.
CVE-2018-19352 1 Jupyter 1 Notebook 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.
CVE-2018-19350 1 Seacms 1 Seacms 2018-12-17 3.5 LOW 5.4 MEDIUM
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.
CVE-2018-0697 1 Metabase 1 Metabase 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Metabase version 0.29.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-0699 1 Hyuki 1 Yukiwiki 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in YukiWiki 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-14935 1 Polycom 2 Trio 8500, Trio 8500 Firmware 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS.
CVE-2018-0687 1 Neo 2 Debun Imap, Debun Pop 2018-12-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-15705 4 Apache, Canonical, Debian and 1 more 7 Spamassassin, Ubuntu Linux, Debian Linux and 4 more 2018-12-16 5.0 MEDIUM 5.3 MEDIUM
A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags in emails that cause markup to be handled incorrectly leading to scan timeouts. In Apache SpamAssassin, using HTML::Parser, we setup an object and hook into the begin and end tag event handlers In both cases, the "open" event is immediately followed by a "close" event - even if the tag *does not* close in the HTML being parsed. Because of this, we are missing the "text" event to deal with the object normally. This can cause carefully crafted emails that might take more scan time than expected leading to a Denial of Service. The issue is possibly a bug or design decision in HTML::Parser that specifically impacts the way Apache SpamAssassin uses the module with poorly formed html. The exploit has been seen in the wild but not believed to have been purposefully part of a Denial of Service attempt. We are concerned that there may be attempts to abuse the vulnerability in the future.
CVE-2018-19287 1 Ninjaforma 1 Ninja Forms 2018-12-14 4.3 MEDIUM 6.1 MEDIUM
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.
CVE-2018-8558 1 Microsoft 2 Office, Office 365 Proplus 2018-12-14 4.0 MEDIUM 6.5 MEDIUM
An information disclosure vulnerability exists when Microsoft Outlook fails to respect "Default link type" settings configured via the SharePoint Online Admin Center, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office. This CVE ID is unique from CVE-2018-8579.
CVE-2018-6081 3 Debian, Google, Redhat 5 Debian Linux, Chrome, Linux Desktop and 2 more 2018-12-14 4.3 MEDIUM 6.1 MEDIUM
XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension or open Developer Console to inject arbitrary scripts or HTML via a crafted HTML page.
CVE-2018-8605 1 Microsoft 1 Dynamics 365 2018-12-14 3.5 LOW 5.4 MEDIUM
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8606, CVE-2018-8607, CVE-2018-8608.
CVE-2018-8606 1 Microsoft 1 Dynamics 365 2018-12-14 3.5 LOW 5.4 MEDIUM
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8605, CVE-2018-8607, CVE-2018-8608.
CVE-2018-8607 1 Microsoft 1 Dynamics 365 2018-12-14 3.5 LOW 5.4 MEDIUM
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8605, CVE-2018-8606, CVE-2018-8608.
CVE-2018-8608 1 Microsoft 1 Dynamics 365 2018-12-14 3.5 LOW 5.4 MEDIUM
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8605, CVE-2018-8606, CVE-2018-8607.
CVE-2018-8547 1 Microsoft 6 Windows 10, Windows 8.1, Windows Rt 8.1 and 3 more 2018-12-14 3.5 LOW 5.4 MEDIUM
A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Active Directory Federation Services XSS Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.