Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In April 2018
mc-admin/post-edit.php in MiniCMS 1.10 allows full path disclosure via a modified id field.
CVSS Score
2.7
EPSS Score
0.002
Published
2018-04-26
TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service. This service establishes a NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "OpenVPNConnect" method accepts a server list argument that provides attacker control of the OpenVPN command line. An attacker can specify a dynamic library plugin that should run for every new VPN connection attempt. This plugin will execute code in the context of the SYSTEM user.
CVSS Score
9.8
EPSS Score
0.006
Published
2018-04-26
Heap-based buffer overflow vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.
CVSS Score
7.8
EPSS Score
0.008
Published
2018-04-25
Double free vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files may allow remote code execution.
CVSS Score
7.8
EPSS Score
0.004
Published
2018-04-25
Processing specially crafted .pm3 files in Advantech WebAccess HMI Designer 2.1.7.32 and prior may cause the system to write outside the intended buffer area and may allow remote code execution.
CVSS Score
7.8
EPSS Score
0.004
Published
2018-04-25
An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC file.
CVSS Score
5.5
EPSS Score
0.001
Published
2018-04-25
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.
CVSS Score
8.1
EPSS Score
0.935
Published
2018-04-25
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.
CVSS Score
5.5
EPSS Score
0.03
Published
2018-04-25
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.
CVSS Score
5.5
EPSS Score
0.045
Published
2018-04-25
There was an argument injection vulnerability in Sourcetree for Windows via Mercurial repository tag name that is going to be deleted. An attacker with permission to create a tag on a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system. All versions of Sourcetree for Windows before 2.5.5.0 are affected by this vulnerability.
CVSS Score
8.8
EPSS Score
0.006
Published
2018-04-25


Contact Us

Shodan ® - All rights reserved