Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-20898 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 4.3 MEDIUM
cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).
CVE-2018-20925 1 Cpanel 1 Cpanel 2019-08-12 4.6 MEDIUM 6.7 MEDIUM
cPanel before 70.0.23 allows local privilege escalation via the WHM Legacy Language File Upload interface (SEC-379).
CVE-2016-10842 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 6.5 MEDIUM
cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74).
CVE-2016-10840 1 Cpanel 1 Cpanel 2019-08-12 9.0 HIGH 8.8 HIGH
cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).
CVE-2017-18406 1 Cpanel 1 Cpanel 2019-08-12 5.0 MEDIUM 7.5 HIGH
cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).
CVE-2017-18407 1 Cpanel 1 Cpanel 2019-08-12 5.8 MEDIUM 4.8 MEDIUM
cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279).
CVE-2017-18408 1 Cpanel 1 Cpanel 2019-08-12 3.5 LOW 5.4 MEDIUM
cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).
CVE-2017-18409 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 6.5 MEDIUM
In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283).
CVE-2017-18410 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 6.5 MEDIUM
In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284).
CVE-2017-18462 1 Cpanel 1 Cpanel 2019-08-12 5.0 MEDIUM 7.5 HIGH
cPanel before 62.0.17 allows a CPHulk one-day ban bypass when IP based protection is enabled (SEC-224).
CVE-2017-18464 1 Cpanel 1 Cpanel 2019-08-12 5.5 MEDIUM 4.9 MEDIUM
cPanel before 62.0.17 allows arbitrary file-overwrite operations via the WHM Zone Template editor (SEC-226).
CVE-2017-18476 1 Cpanel 1 Cpanel 2019-08-12 5.0 MEDIUM 7.5 HIGH
Leech Protect in cPanel before 62.0.4 does not protect certain directories (SEC-205).
CVE-2017-18465 1 Cpanel 1 Cpanel 2019-08-12 2.1 LOW 4.4 MEDIUM
cPanel before 62.0.17 does not have a sufficient list of reserved usernames (SEC-227).
CVE-2017-18475 1 Cpanel 1 Cpanel 2019-08-12 6.5 MEDIUM 8.8 HIGH
In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204).
CVE-2017-18474 1 Cpanel 1 Cpanel 2019-08-12 6.8 MEDIUM 6.5 MEDIUM
cPanel before 62.0.4 allows arbitrary file-read operations via Exim valiases (SEC-201).
CVE-2016-10775 1 Cpanel 1 Cpanel 2019-08-12 6.8 MEDIUM 6.5 MEDIUM
cPanel before 60.0.25 allows arbitrary file-chown operations via reassign_post_terminate_cruft (SEC-173).
CVE-2017-18416 1 Cpanel 1 Cpanel 2019-08-12 3.6 LOW 5.5 MEDIUM
cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303).
CVE-2017-18466 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 2.7 LOW
cPanel before 62.0.17 does not properly recognize domain ownership during addition of parked domains to a mail configuration (SEC-228).
CVE-2017-18467 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 4.3 MEDIUM
cPanel before 62.0.17 allows access to restricted resources because of a URL filtering error (SEC-229).
CVE-2017-18427 1 Cpanel 1 Cpanel 2019-08-12 2.1 LOW 3.3 LOW
In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).
CVE-2017-18482 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 6.5 MEDIUM
cPanel before 62.0.4 allows resellers to use the WHM enqueue_transfer_item API for queueing non-rearrange modules (SEC-213).
CVE-2017-18479 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 6.5 MEDIUM
In cPanel before 62.0.4, WHM SSL certificate generation uses an unreserved e-mail address (SEC-209).
CVE-2017-18428 1 Cpanel 1 Cpanel 2019-08-12 1.9 LOW 2.5 LOW
In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290).
CVE-2017-18480 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 6.5 MEDIUM
cPanel before 62.0.4 does not enforce account ownership for has_mycnf_for_cpuser WHM API calls (SEC-210).
CVE-2017-18468 1 Cpanel 1 Cpanel 2019-08-12 6.5 MEDIUM 6.3 MEDIUM
cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232).
CVE-2017-18478 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 6.5 MEDIUM
In cPanel before 62.0.4 incorrect ACL checks could occur in xml-api for Rearrange Account actions (SEC-207).
CVE-2017-18477 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 6.5 MEDIUM
In cPanel before 62.0.4, Exim transports could execute in the context of the nobody account (SEC-206).
CVE-2017-18470 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 8.8 HIGH
cPanel before 62.0.4 has a fixed password for the Munin MySQL test account (SEC-196).
CVE-2017-18415 1 Cpanel 1 Cpanel 2019-08-12 4.6 MEDIUM 7.8 HIGH
cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).
CVE-2017-18411 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 6.8 MEDIUM
The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-285).
CVE-2017-18414 1 Cpanel 1 Cpanel 2019-08-12 5.8 MEDIUM 7.4 HIGH
cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).
CVE-2016-10860 1 Cpanel 1 Cpanel 2019-08-12 5.5 MEDIUM 8.1 HIGH
cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66).
CVE-2016-10832 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 6.5 MEDIUM
cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102).
CVE-2016-10833 1 Cpanel 1 Cpanel 2019-08-12 5.0 MEDIUM 7.5 HIGH
cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104).
CVE-2016-10834 1 Cpanel 1 Cpanel 2019-08-12 6.5 MEDIUM 8.8 HIGH
cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).
CVE-2016-10835 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 4.3 MEDIUM
cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107).
CVE-2018-20937 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 4.3 MEDIUM
cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321).
CVE-2016-10829 1 Cpanel 1 Cpanel 2019-08-12 6.8 MEDIUM 6.5 MEDIUM
cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99).
CVE-2017-18412 1 Cpanel 1 Cpanel 2019-08-12 1.9 LOW 2.5 LOW
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).
CVE-2016-10831 1 Cpanel 1 Cpanel 2019-08-12 6.5 MEDIUM 7.2 HIGH
cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101).
CVE-2016-10830 1 Cpanel 1 Cpanel 2019-08-12 5.5 MEDIUM 8.1 HIGH
cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100).
CVE-2017-18413 1 Cpanel 1 Cpanel 2019-08-12 4.6 MEDIUM 7.8 HIGH
In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).
CVE-2016-10825 1 Cpanel 1 Cpanel 2019-08-12 5.5 MEDIUM 8.1 HIGH
cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).
CVE-2017-18387 1 Cpanel 1 Cpanel 2019-08-12 9.0 HIGH 7.2 HIGH
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).
CVE-2018-20934 1 Cpanel 1 Cpanel 2019-08-12 6.4 MEDIUM 6.5 MEDIUM
cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned accounts (SEC-411).
CVE-2019-14747 1 Diaowen 1 Dwsurvey 2019-08-12 4.3 MEDIUM 6.1 MEDIUM
DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter.
CVE-2019-7163 1 Tcl 2 Alcatel Linkzone, Alcatel Linkzone Firmware 2019-08-12 7.5 HIGH 9.8 CRITICAL
The web interface of Alcatel LINKZONE MW40-V-V1.0 MW40_LU_02.00_02 devices is vulnerable to an authentication bypass that allows an unauthenticated user to have access to the web interface without knowing the administrator's password.
CVE-2019-14531 1 Sleuthkit 1 The Sleuth Kit 2019-08-12 7.5 HIGH 9.8 CRITICAL
An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an out of bounds read on iso9660 while parsing System Use Sharing Protocol data in fs/iso9660.c.
CVE-2007-6763 1 Sas 1 Sas Drug Development 2019-08-12 6.5 MEDIUM 8.8 HIGH
SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources by pressing a back or forward button in a web browser.
CVE-2019-14283 1 Linux 1 Linux Kernel 2019-08-11 4.6 MEDIUM 6.8 MEDIUM
In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c does not validate the sect and head fields, as demonstrated by an integer overflow and out-of-bounds read. It can be triggered by an unprivileged local user when a floppy disk has been inserted. NOTE: QEMU creates the floppy device by default.