| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-10636 | Hig | 0.53 | 8.1 | 0.02 | Jun 4, 2018 | grunt-ccompiler is a Closure Compiler Grunt Plugin. grunt-ccompiler downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary… | ||
| CVE-2018-11712 | Hig | 0.49 | 7.5 | 0.01 | Jun 4, 2018 | WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ versions 2.20.0 and 2.20.1, failed to perform TLS certificate verification for WebSocket connections. | ||
| CVE-2018-10615 | Hig | 0.53 | 8.1 | 0.03 | Jun 4, 2018 | Directory traversal may lead to files being exfiltrated or deleted on the GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior host platform. | ||
| CVE-2018-10613 | Hig | 0.50 | 7.5 | 0.18 | Jun 4, 2018 | Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior. | ||
| CVE-2018-11710 | Hig | 0.57 | 8.8 | 0.02 | Jun 4, 2018 | soundlib/pattern.h in libopenmpt before 0.3.9 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted AMS file because of an invalid write near address 0 in an out-of-memory situation. | ||
| CVE-2016-1000343 | — | Hig | 0.42 | 7.5 | 0.03 | Jun 4, 2018 | In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a… | |
| CVE-2016-1000342 | — | Hig | 0.42 | 7.5 | 0.02 | Jun 4, 2018 | In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the… | |
| CVE-2016-1000340 | — | Hig | 0.42 | 7.5 | 0.02 | Jun 4, 2018 | In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in the implementation of squaring for several raw math classes have been fixed (org.bouncycastle.math.raw.Nat???). These classes are used by our custom elliptic curve implementations… | |
| CVE-2018-11698 | Hig | 0.53 | 8.1 | 0.02 | Jun 4, 2018 | An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::handle_error which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service. | ||
| CVE-2018-11697 | Hig | 0.53 | 8.1 | 0.02 | Jun 4, 2018 | An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::exactly() which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service. | ||
| CVE-2018-11696 | Hig | 0.57 | 8.8 | 0.02 | Jun 4, 2018 | An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Inspect::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact. | ||
| CVE-2018-11695 | Hig | 0.00 | 8.8 | 0.02 | Jun 4, 2018 | An issue was discovered in LibSass <3.5.3. A NULL pointer dereference was found in the function Sass::Expand::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact. | ||
| CVE-2018-11694 | Hig | 0.57 | 8.8 | 0.02 | Jun 4, 2018 | An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Functions::selector_append which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact. | ||
| CVE-2018-11693 | Hig | 0.53 | 8.1 | 0.01 | Jun 4, 2018 | An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::skip_over_scopes which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of… | ||
| CVE-2018-11685 | Hig | 0.57 | 8.8 | 0.02 | Jun 4, 2018 | Liblouis 3.5.0 has a stack-based Buffer Overflow in the function compileHyphenation in compileTranslationTable.c. | ||
| CVE-2018-11684 | Hig | 0.57 | 8.8 | 0.02 | Jun 4, 2018 | Liblouis 3.5.0 has a stack-based Buffer Overflow in the function includeFile in compileTranslationTable.c. | ||
| CVE-2018-11683 | Hig | 0.57 | 8.8 | 0.02 | Jun 4, 2018 | Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440. | ||
| CVE-2017-18285 | Hig | 0.46 | 7.1 | 0.00 | Jun 4, 2018 | The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain read and write access to arbitrary files by leveraging access to a certain account for a burp-server.conf change. | ||
| CVE-2017-18284 | Hig | 0.46 | 7.1 | 0.00 | Jun 4, 2018 | The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL. | ||
| CVE-2018-11679 | Hig | 0.57 | 8.8 | 0.01 | Jun 2, 2018 | An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability that can add an article via /index.php?case=table&act=add&table=archive&admin_dir=admin. | ||
| CVE-2018-11194 | Hig | 0.57 | 8.8 | 0.03 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 6 of 6). | ||
| CVE-2018-11193 | Hig | 0.57 | 8.8 | 0.03 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 5 of 6). | ||
| CVE-2018-11192 | Hig | 0.57 | 8.8 | 0.03 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 4 of 6). | ||
| CVE-2018-11191 | Hig | 0.57 | 8.8 | 0.03 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 3 of 6). | ||
| CVE-2018-11190 | Hig | 0.57 | 8.8 | 0.03 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 2 of 6). | ||
| CVE-2018-11189 | Hig | 0.57 | 8.8 | 0.03 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 1 of 6). | ||
| CVE-2018-11188 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 46 of 46). | ||
| CVE-2018-11187 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 45 of 46). | ||
| CVE-2018-11186 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 44 of 46). | ||
| CVE-2018-11185 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 43 of 46). | ||
| CVE-2018-11184 | Hig | 0.47 | 7.2 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 42 of 46). | ||
| CVE-2018-11183 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 41 of 46). | ||
| CVE-2018-11182 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 40 of 46). | ||
| CVE-2018-11181 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 39 of 46). | ||
| CVE-2018-11180 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 38 of 46). | ||
| CVE-2018-11179 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 37 of 46). | ||
| CVE-2018-11178 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 36 of 46). | ||
| CVE-2018-11177 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 35 of 46). | ||
| CVE-2018-11176 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 34 of 46). | ||
| CVE-2018-11175 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 33 of 46). | ||
| CVE-2018-11174 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 32 of 46). | ||
| CVE-2018-11173 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 31 of 46). | ||
| CVE-2018-11172 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 30 of 46). | ||
| CVE-2018-11171 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 29 of 46). | ||
| CVE-2018-11170 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 28 of 46). | ||
| CVE-2018-11169 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 27 of 46). | ||
| CVE-2018-11168 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 26 of 46). | ||
| CVE-2018-11167 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 25 of 46). | ||
| CVE-2018-11166 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 24 of 46). | ||
| CVE-2018-11165 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 23 of 46). |
- risk 0.53cvss 8.1epss 0.02
grunt-ccompiler is a Closure Compiler Grunt Plugin. grunt-ccompiler downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary…
- risk 0.49cvss 7.5epss 0.01
WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ versions 2.20.0 and 2.20.1, failed to perform TLS certificate verification for WebSocket connections.
- risk 0.53cvss 8.1epss 0.03
Directory traversal may lead to files being exfiltrated or deleted on the GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior host platform.
- risk 0.50cvss 7.5epss 0.18
Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior.
- risk 0.57cvss 8.8epss 0.02
soundlib/pattern.h in libopenmpt before 0.3.9 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted AMS file because of an invalid write near address 0 in an out-of-memory situation.
- risk 0.42cvss 7.5epss 0.03
In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a…
- risk 0.42cvss 7.5epss 0.02
In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the…
- risk 0.42cvss 7.5epss 0.02
In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in the implementation of squaring for several raw math classes have been fixed (org.bouncycastle.math.raw.Nat???). These classes are used by our custom elliptic curve implementations…
- risk 0.53cvss 8.1epss 0.02
An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::handle_error which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.
- risk 0.53cvss 8.1epss 0.02
An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::exactly() which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.
- risk 0.57cvss 8.8epss 0.02
An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Inspect::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
- risk 0.00cvss 8.8epss 0.02
An issue was discovered in LibSass <3.5.3. A NULL pointer dereference was found in the function Sass::Expand::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
- risk 0.57cvss 8.8epss 0.02
An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Functions::selector_append which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::skip_over_scopes which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of…
- risk 0.57cvss 8.8epss 0.02
Liblouis 3.5.0 has a stack-based Buffer Overflow in the function compileHyphenation in compileTranslationTable.c.
- risk 0.57cvss 8.8epss 0.02
Liblouis 3.5.0 has a stack-based Buffer Overflow in the function includeFile in compileTranslationTable.c.
- risk 0.57cvss 8.8epss 0.02
Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440.
- risk 0.46cvss 7.1epss 0.00
The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain read and write access to arbitrary files by leveraging access to a certain account for a burp-server.conf change.
- risk 0.46cvss 7.1epss 0.00
The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability that can add an article via /index.php?case=table&act=add&table=archive&admin_dir=admin.
- risk 0.57cvss 8.8epss 0.03
Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 6 of 6).
- risk 0.57cvss 8.8epss 0.03
Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 5 of 6).
- risk 0.57cvss 8.8epss 0.03
Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 4 of 6).
- risk 0.57cvss 8.8epss 0.03
Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 3 of 6).
- risk 0.57cvss 8.8epss 0.03
Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 2 of 6).
- risk 0.57cvss 8.8epss 0.03
Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 1 of 6).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 46 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 45 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 44 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 43 of 46).
- risk 0.47cvss 7.2epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 42 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 41 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 40 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 39 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 38 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 37 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 36 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 35 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 34 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 33 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 32 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 31 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 30 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 29 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 28 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 27 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 26 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 25 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 24 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 23 of 46).