Search Results (324384 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-16670 1 Circontrol 1 Circarlife Scada 2024-11-21 N/A
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html.
CVE-2018-16669 1 Circontrol 1 Open Charge Point Protocol 2024-11-21 N/A
An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to storage of credentials in XML files, an unprivileged user can look at /services/config/config.xml for the admin credentials of the ocpp and circarlife panels.
CVE-2018-16668 1 Circontrol 1 Circarlife Scada 2024-11-21 5.3 Medium
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /html/repository.
CVE-2018-16667 1 Contiki-ng 1 Contiki-ng. 2024-11-21 N/A
An issue was discovered in Contiki-NG through 4.1. There is a buffer over-read in lookup in os/storage/antelope/lvm.c while parsing AQL (lvm_register_variable, lvm_set_variable_value, create_intersection, create_union).
CVE-2018-16666 1 Contiki-ng 1 Contiki-ng. 2024-11-21 N/A
An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in next_string in os/storage/antelope/aql-lexer.c while parsing AQL (parsing next string).
CVE-2018-16665 1 Contiki-ng 1 Contiki-ng. 2024-11-21 N/A
An issue was discovered in Contiki-NG through 4.1. There is a buffer overflow while parsing AQL in lvm_shift_for_operator in os/storage/antelope/lvm.c.
CVE-2018-16664 1 Contiki-ng 1 Contiki-ng. 2024-11-21 N/A
An issue was discovered in Contiki-NG through 4.1. There is a buffer overflow in lvm_set_type in os/storage/antelope/lvm.c while parsing AQL (lvm_set_op, lvm_set_relation, lvm_set_operand).
CVE-2018-16663 1 Contiki-ng 1 Contiki-ng. 2024-11-21 N/A
An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in parse_relations in os/storage/antelope/aql-parser.c while parsing AQL (storage of relations).
CVE-2018-16660 1 Imperva 1 Securesphere 2024-11-21 N/A
A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated access to execute arbitrary OS commands on a vulnerable installation.
CVE-2018-16659 1 Rausoft 1 Id.prove 2024-11-21 9.8 Critical
An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST parameter. Hypothetically, an attacker can utilize master..xp_cmdshell for the further privilege elevation.
CVE-2018-16658 4 Canonical, Debian, Linux and 1 more 5 Ubuntu Linux, Debian Linux, Linux Kernel and 2 more 2024-11-21 N/A
An issue was discovered in the Linux kernel before 4.18.6. An information leak in cdrom_ioctl_drive_status in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes with bounds checking. This is similar to CVE-2018-10940.
CVE-2018-16657 2 Debian, Kamailio 2 Debian Linux, Kamailio 2024-11-21 N/A
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. The reason is missing input validation in the crcitt_string_array core function for calculating a CRC hash for To tags. (An additional error is present in the check_via_address core function: this function also misses input validation.) This could result in denial of service and potentially the execution of arbitrary code.
CVE-2018-16656 1 Kyocera 4 Taskalfa 4002i, Taskalfa 4002i Firmware, Taskalfa 6002i and 1 more 2024-11-21 N/A
DoBox_CstmBox_Info.model.htm on Kyocera TASKalfa 4002i and 6002i devices allows remote attackers to read the documents of arbitrary users via a modified HTTP request.
CVE-2018-16655 1 Gxlcms 1 Gxlcms 2024-11-21 N/A
Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php.
CVE-2018-16654 1 Zurmo 1 Zurmo Crm 2024-11-21 N/A
Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1.
CVE-2018-16653 1 Rejucms Project 1 Rejucms 2024-11-21 N/A
rejucms 2.1 has XSS via the ucenter/cms_user_add.php u_name parameter.
CVE-2018-16651 1 Phpmyfaq 1 Phpmyfaq 2024-11-21 N/A
The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.
CVE-2018-16650 1 Phpmyfaq 1 Phpmyfaq 2024-11-21 N/A
phpMyFAQ before 2.9.11 allows CSRF.
CVE-2018-16648 1 Artifex 1 Mupdf 2024-11-21 N/A
In Artifex MuPDF 1.13.0, the fz_append_byte function in fitz/buffer.c allows remote attackers to cause a denial of service (segmentation fault) via a crafted pdf file. This is caused by a pdf/pdf-device.c pdf_dev_alpha array-index underflow.
CVE-2018-16647 1 Artifex 1 Mupdf 2024-11-21 N/A
In Artifex MuPDF 1.13.0, the pdf_get_xref_entry function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation fault in fz_write_data in fitz/output.c) via a crafted pdf file.