Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In April 2018
An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "Status Bar" component. It allows invisible microphone access via a crafted app.
CVSS Score
5.5
EPSS Score
0.001
Published
2018-04-13
joyplus-cms 1.6.0 has XSS via the device_name parameter in a manager/admin_ajax.php?action=save flag=add request.
CVSS Score
4.8
EPSS Score
0.002
Published
2018-04-13
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, executes code at a user-defined (local or SMB) path as SYSTEM when the execute_installer parameter is used in an HTTP message. This occurs without properly authenticating the user.
CVSS Score
9.8
EPSS Score
0.421
Published
2018-04-13
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, contains an HTTP message parsing function that takes a user-defined path and writes non-user controlled data as SYSTEM to the file when the extract_files parameter is used. This occurs without properly authenticating the user.
CVSS Score
9.1
EPSS Score
0.004
Published
2018-04-13
diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.
CVSS Score
9.8
EPSS Score
0.005
Published
2018-04-13
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.
CVSS Score
7.8
EPSS Score
0.001
Published
2018-04-13
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.
CVSS Score
8.8
EPSS Score
0.002
Published
2018-04-13
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-04-13
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-04-13
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a XSS vulnerability in SearchHighlighter::highlightText() with non-default configurations.
CVSS Score
4.7
EPSS Score
0.003
Published
2018-04-13


Contact Us

Shodan ® - All rights reserved