Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-8436 1 Microsoft 2 Windows 10, Windows Server 2016 2018-11-02 5.5 MEDIUM 6.2 MEDIUM
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability." This affects Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8437, CVE-2018-8438.
CVE-2018-8426 1 Microsoft 3 Sharepoint Enterprise Server 2013, Sharepoint Enterprise Server 2016, Sharepoint Server 2010 2018-11-02 3.5 LOW 5.4 MEDIUM
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint.
CVE-2018-17046 1 Translate Man Project 1 Translate Man 2018-11-02 4.3 MEDIUM 6.1 MEDIUM
translate man before 2018-08-21 has XSS via containers/outputBox/outputBox.vue and store/index.js.
CVE-2018-16727 1 Razorcms 1 Razorcms 2018-11-02 3.5 LOW 5.4 MEDIUM
razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component.
CVE-2018-16726 1 Razorcms 1 Razorcms 2018-11-02 3.5 LOW 5.4 MEDIUM
razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component.
CVE-2018-16776 1 Creatiwity 1 Witycms 2018-11-02 3.5 LOW 4.8 MEDIUM
wityCMS 0.6.2 has XSS via the "Site Name" field found in the "Contact" "Configuration" page.
CVE-2018-16653 1 Rejucms Project 1 Rejucms 2018-11-02 4.3 MEDIUM 6.1 MEDIUM
rejucms 2.1 has XSS via the ucenter/cms_user_add.php u_name parameter.
CVE-2018-8443 1 Microsoft 7 Windows 10, Windows 7, Windows 8.1 and 4 more 2018-11-02 2.1 LOW 5.5 MEDIUM
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8336, CVE-2018-8419, CVE-2018-8442, CVE-2018-8445, CVE-2018-8446.
CVE-2018-8442 1 Microsoft 7 Windows 10, Windows 7, Windows 8.1 and 4 more 2018-11-02 2.1 LOW 5.5 MEDIUM
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8336, CVE-2018-8419, CVE-2018-8443, CVE-2018-8445, CVE-2018-8446.
CVE-2018-8336 1 Microsoft 2 Windows 7, Windows Server 2008 2018-11-02 2.1 LOW 5.5 MEDIUM
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8419, CVE-2018-8442, CVE-2018-8443, CVE-2018-8445, CVE-2018-8446.
CVE-2018-15536 1 Tecrail 1 Responsive Filemanager 2018-11-01 5.8 MEDIUM 5.5 MEDIUM
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal.
CVE-2018-14059 1 Pimcore 1 Pimcore 2018-11-01 3.5 LOW 5.4 MEDIUM
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions.
CVE-2018-17091 1 I4a 1 Donlinkage 2018-11-01 5.5 MEDIUM 5.4 MEDIUM
An issue was discovered in DonLinkage 6.6.8. It allows remote attackers to obtain potentially sensitive information via a direct request for files/temporary.txt.
CVE-2018-17090 1 I4a 1 Donlinkage 2018-11-01 3.5 LOW 5.4 MEDIUM
An issue was discovered in DonLinkage 6.6.8. The modules /pages/bazy/bazy_adresow.php and /pages/proxy/add.php are vulnerable to stored XSS that can be triggered by closing <textarea> followed by <script></script> tags.
CVE-2018-8429 1 Microsoft 5 Excel, Excel Viewer, Office and 2 more 2018-11-01 4.3 MEDIUM 5.5 MEDIUM
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.
CVE-2018-17130 1 Phpmywind 1 Phpmywind 2018-11-01 3.5 LOW 5.4 MEDIUM
PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header,
CVE-2016-9345 1 Emerson 1 Deltav 2018-11-01 4.9 MEDIUM 6.8 MEDIUM
An issue was discovered in Emerson DeltaV Easy Security Management DeltaV V12.3, DeltaV V12.3.1, and DeltaV V13.3. Critical vulnerabilities may allow a local attacker to elevate privileges within the DeltaV control system.
CVE-2018-16977 1 Monstra 1 Monstra 2018-10-31 5.0 MEDIUM 5.3 MEDIUM
Monstra CMS V3.0.4 has an information leakage risk (e.g., PATH, DOCUMENT_ROOT, and SERVER_ADMIN) in libraries/Gelato/ErrorHandler/Resources/Views/Errors/exception.php.
CVE-2018-16979 1 Monstra 1 Monstra 2018-10-31 5.8 MEDIUM 6.1 MEDIUM
Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-2943.
CVE-2018-16978 1 Monstra 1 Monstra 2018-10-31 4.3 MEDIUM 6.1 MEDIUM
Monstra CMS V3.0.4 has XSS when ones tries to register an account with a crafted password parameter to users/registration, a different vulnerability than CVE-2018-11473.
CVE-2018-14396 1 Cremecrm 1 Cremecrm 2018-10-31 3.5 LOW 5.4 MEDIUM
An issue was discovered in Creme CRM 1.6.12. The salesman creation page is affected by 10 stored cross-site scripting vulnerabilities involving the firstname, lastname, billing_address-address, billing_address-zipcode, billing_address-city, billing_address-department, shipping_address-address, shipping_address-zipcode, shipping_address-city, and shipping_address-department parameters.
CVE-2018-14397 1 Cremecrm 1 Cremecrm 2018-10-31 3.5 LOW 5.4 MEDIUM
An issue was discovered in Creme CRM 1.6.12. The organization creation page is affected by 9 stored cross-site scripting vulnerabilities involving the name, billing_address-address, billing_address-zipcode, billing_address-city, billing_address-department, shipping_address-address, shipping_address-zipcode, shipping_address-city, and shipping_address-department parameters.
CVE-2018-15896 1 Website Seller Script Project 1 Website Seller Script 2018-10-31 3.5 LOW 5.4 MEDIUM
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via Personal Address or Company Name.
CVE-2018-8315 1 Microsoft 10 Chakracore, Edge, Internet Explorer and 7 more 2018-10-31 4.0 MEDIUM 4.2 MEDIUM
An information disclosure vulnerability exists when the browser scripting engine improperly handle object types, aka "Microsoft Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10.
CVE-2016-1000232 3 Ibm, Redhat, Salesforce 3 Api Connect, Openshift Container Platform, Tough-cookie 2018-10-31 5.0 MEDIUM 5.3 MEDIUM
NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerability appears to have been fixed in 2.3.0.
CVE-2018-11502 1 Moderator Log Notes Project 1 Moderator Log Notes 2018-10-31 5.8 MEDIUM 6.5 MEDIUM
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. An attacker can remotely delete all mod notes and mod note logs in the modCP and ACP via CSRF.
CVE-2018-16397 1 Limesurvey 1 Limesurvey 2018-10-31 4.0 MEDIUM 4.9 MEDIUM
In LimeSurvey before 3.14.7, an admin user can leverage a "file upload" question to read an arbitrary file,
CVE-2018-5244 1 Xen 1 Xen 2018-10-31 4.9 MEDIUM 6.5 MEDIUM
In Xen 4.10, new infrastructure was introduced as part of an overhaul to how MSR emulation happens for guests. Unfortunately, one tracking structure isn't freed when a vcpu is destroyed. This allows guest OS administrators to cause a denial of service (host OS memory consumption) by rebooting many times.
CVE-2018-7542 2 Debian, Xen 2 Debian Linux, Xen 2018-10-31 4.9 MEDIUM 6.5 MEDIUM
An issue was discovered in Xen 4.8.x through 4.10.x allowing x86 PVH guest OS users to cause a denial of service (NULL pointer dereference and hypervisor crash) by leveraging the mishandling of configurations that lack a Local APIC.
CVE-2018-1092 1 Linux 1 Linux Kernel 2018-10-31 7.1 HIGH 5.5 MEDIUM
The ext4_iget function in fs/ext4/inode.c in the Linux kernel through 4.15.15 mishandles the case of a root directory with a zero i_links_count, which allows attackers to cause a denial of service (ext4_process_freed_data NULL pointer dereference and OOPS) via a crafted ext4 image.
CVE-2018-1065 1 Linux 1 Linux Kernel 2018-10-31 4.7 MEDIUM 4.7 MEDIUM
The netfilter subsystem in the Linux kernel through 4.15.7 mishandles the case of a rule blob that contains a jump but lacks a user-defined chain, which allows local users to cause a denial of service (NULL pointer dereference) by leveraging the CAP_NET_RAW or CAP_NET_ADMIN capability, related to arpt_do_table in net/ipv4/netfilter/arp_tables.c, ipt_do_table in net/ipv4/netfilter/ip_tables.c, and ip6t_do_table in net/ipv6/netfilter/ip6_tables.c.
CVE-2018-1095 1 Linux 1 Linux Kernel 2018-10-31 7.1 HIGH 5.5 MEDIUM
The ext4_xattr_check_entries function in fs/ext4/xattr.c in the Linux kernel through 4.15.15 does not properly validate xattr sizes, which causes misinterpretation of a size as an error code, and consequently allows attackers to cause a denial of service (get_acl NULL pointer dereference and system crash) via a crafted ext4 image.
CVE-2018-1000200 1 Linux 1 Linux Kernel 2018-10-31 4.9 MEDIUM 5.5 MEDIUM
The Linux Kernel versions 4.14, 4.15, and 4.16 has a null pointer dereference which can result in an out of memory (OOM) killing of large mlocked processes. The issue arises from an oom killed process's final thread calling exit_mmap(), which calls munlock_vma_pages_all() for mlocked vmas.This can happen synchronously with the oom reaper's unmap_page_range() since the vma's VM_LOCKED bit is cleared before munlocking (to determine if any other vmas share the memory and are mlocked).
CVE-2018-12232 1 Linux 1 Linux Kernel 2018-10-31 7.1 HIGH 5.9 MEDIUM
In net/socket.c in the Linux kernel through 4.17.1, there is a race condition between fchownat and close in cases where they target the same socket file descriptor, related to the sock_close and sockfs_setattr functions. fchownat does not increment the file descriptor reference count, which allows close to set the socket to NULL during fchownat's execution, leading to a NULL pointer dereference and system crash.
CVE-2018-10471 2 Debian, Xen 2 Debian Linux, Xen 2018-10-31 4.9 MEDIUM 6.5 MEDIUM
An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor crash) via unexpected INT 80 processing, because of an incorrect fix for CVE-2017-5754.
CVE-2018-10472 2 Debian, Xen 2 Debian Linux, Xen 2018-10-31 1.9 LOW 5.6 MEDIUM
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot.
CVE-2018-10940 2 Debian, Linux 2 Debian Linux, Linux Kernel 2018-10-31 4.9 MEDIUM 5.5 MEDIUM
The cdrom_ioctl_media_changed function in drivers/cdrom/cdrom.c in the Linux kernel before 4.16.6 allows local attackers to use a incorrect bounds check in the CDROM driver CDROM_MEDIA_CHANGED ioctl to read out kernel memory.
CVE-2017-16648 1 Linux 1 Linux Kernel 2018-10-31 7.2 HIGH 6.6 MEDIUM
The dvb_frontend_free function in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device. NOTE: the function was later renamed __dvb_frontend_free.
CVE-2017-18199 1 Gnu 1 Libcdio 2018-10-31 4.3 MEDIUM 6.5 MEDIUM
realloc_symlink in rock.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (NULL Pointer Dereference) via a crafted iso file.
CVE-2017-12618 1 Apache 1 Portable Runtime Utility 2018-10-31 1.9 LOW 4.7 MEDIUM
Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.
CVE-2018-12151 1 Intel 1 Extreme Tuning Utility 2018-10-30 2.1 LOW 5.5 MEDIUM
Buffer overflow in installer for Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially cause a buffer overflow potentially leading to a denial of service via local access.
CVE-2018-16405 1 Mayan-edms 1 Mayan Edms 2018-10-30 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Mayan EDMS before 3.0.2. The Appearance app sets window.location directly, leading to XSS.
CVE-2018-16406 1 Mayan-edms 1 Mayan Edms 2018-10-30 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Mayan EDMS before 3.0.2. The Cabinets app has XSS via a crafted cabinet label.
CVE-2018-16407 1 Mayan-edms 1 Mayan Edms 2018-10-30 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Mayan EDMS before 3.0.3. The Tags app has XSS because tag label values are mishandled.
CVE-2018-17025 1 Monstra 1 Monstra 2018-10-30 4.3 MEDIUM 6.1 MEDIUM
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page action for a page with no special role.
CVE-2018-17026 1 Monstra 1 Monstra 2018-10-30 3.5 LOW 4.8 MEDIUM
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page&name=error404 action, a different vulnerability than CVE-2018-10121.
CVE-2016-9040 1 Joyent 1 Smartos 2018-10-30 4.9 MEDIUM 5.5 MEDIUM
An exploitable denial of service exists in the the Joyent SmartOS OS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFSADDENTRIES when used with a 32 bit model. An attacker can cause a buffer to be allocated and never freed. When repeatedly exploit this will result in memory exhaustion, resulting in a full system denial of service.
CVE-2018-15157 1 Libfsclfs Project 1 Libfsclfs 2018-10-30 4.3 MEDIUM 6.5 MEDIUM
** DISPUTED ** The libfsclfs_block_read function in libfsclfs_block.c in libfsclfs before 2018-07-25 allows remote attackers to cause a heap-based buffer over-read via a crafted clfs file. NOTE: the vendor has disputed this as described in the GitHub issue comments.
CVE-2018-15158 1 Libesedb Project 1 Libesedb 2018-10-30 4.3 MEDIUM 6.5 MEDIUM
** DISPUTED ** The libesedb_page_read_values function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a crafted esedb file. NOTE: the vendor has disputed this as described in the GitHub issue comments.
CVE-2018-15159 1 Libesedb Project 1 Libesedb 2018-10-30 4.3 MEDIUM 6.5 MEDIUM
** DISPUTED ** The libesedb_page_read_tags function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a crafted esedb file. NOTE: the vendor has disputed this as described in the GitHub issue comments.