Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In June 2018
Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privileges via a crafted command line. NOTE: It is unclear whether there are any common situations in which redis-cli is used with, for example, a -h (aka hostname) argument from an untrusted source.
CVSS Score
8.4
EPSS Score
0.15
Published
2018-06-17
The _addguess function of a simplelottery smart contract implementation for 1000 Guess, an Ethereum gambling game, generates a random value with publicly readable variables such as the current block information and a private variable (which can be read with a getStorageAt call). Therefore, it allows attackers to always win and get rewards.
CVSS Score
7.5
EPSS Score
0.003
Published
2018-06-17
Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-service via an XGROUP command in which the key is not a stream.
CVSS Score
7.5
EPSS Score
0.286
Published
2018-06-16
tinyexr 0.9.5 has a heap-based buffer over-read in LoadEXRImageFromMemory in tinyexr.h.
CVSS Score
9.8
EPSS Score
0.004
Published
2018-06-16
tinyexr 0.9.5 has an assertion failure in ComputeChannelLayout in tinyexr.h.
CVSS Score
7.5
EPSS Score
0.003
Published
2018-06-16
Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335.
CVSS Score
6.1
EPSS Score
0.033
Published
2018-06-16
The path of Whale update service was unquoted in NAVER Whale before 1.0.40.7. This vulnerability can be used for persistent privilege escalation if it's available to create an executable file with System privilege by other vulnerable applications.
CVSS Score
8.1
EPSS Score
0.005
Published
2018-06-16
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote authenticated users to obtain sensitive information about external guest users via vectors related to the "groups" and "users" APIs.
CVSS Score
6.5
EPSS Score
0.013
Published
2018-06-16
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors involving non-decimal representations of IP addresses and special IPv6 related addresses.
CVSS Score
8.8
EPSS Score
0.02
Published
2018-06-16
The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev20 allows remote attackers to spoof the origin of e-mails via unicode characters in the "personal part" of a (1) From or (2) Sender address.
CVSS Score
6.5
EPSS Score
0.018
Published
2018-06-16


Contact Us

Shodan ® - All rights reserved