Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2018-12523EPSS 7%
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provides a directory listing.
Monitoring And Debugging Dashboard
No fix yet
MEDIUM 5.3
CVE-2018-12524EPSS 7%
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provides a directory listing.
Monitoring And Debugging Dashboard
No fix yet
MEDIUM 5.3
CVE-2018-12525EPSS 7%
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ provides a directory listing.
Monitoring And Debugging Dashboard
No fix yet
HIGH 8.8
CVE-2018-12027
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation…
Passenger
5.3.2+
MEDIUM 5.9
CVE-2018-12329
Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentication factor via cloning.
Secure Boot Stick Firmware
No fix yet
CRITICAL 9.8
CVE-2018-12336
Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote root SSH acc…
Secure Boot Stick Firmware
Mitigation only
MEDIUM 6.5
CVE-2018-5751EPSS 9%
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev…
Open Xchange Appsuite
after 7.6.3
CRITICAL 9.8
CVE-2018-12481
The Olive Tree Ftp Server application 1.32 for Android has a "Sensitive Data on the Clipboard" vulnerability, as demonstrated by reading the "User pa…
The Olive Tree Ftp Server
Mitigation only
MEDIUM 6.5
CVE-2018-6672
Information disclosure vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows authenticated users to v…
Epolicy Orchestrator
after 5.9.1
MEDIUM 5.9
CVE-2018-12435
Botan 2.5.0 through 2.6.0 before 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or …
Botan
after 2.7.0
MEDIUM 5.5
CVE-2018-8239EPSS 58%
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Infor…
Windows 10
Patch available
MEDIUM 5.5
CVE-2018-8246EPSS 18%
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information…
Excel
Patch available
HIGH 8.0
CVE-2018-8209
An information disclosure vulnerability exists when Windows allows a normal user to access the Wireless LAN profile of an administrative user, aka "W…
Windows 10
Patch available
MEDIUM 5.3
CVE-2018-12227
An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert bef…
Debian Linux
13.21.1 / 14.7.7+
HIGH 7.5
CVE-2018-5181
If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process the tab will open a local fi…
Ubuntu Linux
60.0+
HIGH 7.5
CVE-2018-5182
If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the addressbar the specified local…
Ubuntu Linux
60.0+
HIGH 7.5
CVE-2018-5157
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow th…
Enterprise Linux Desktop
Mitigation only
MEDIUM 5.9
CVE-2018-5131
Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache hea…
Debian Linux
52.7.0 / 59.0+
MEDIUM 6.5
CVE-2018-5132
The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a mali…
Firefox
59.0+
MEDIUM 6.5
CVE-2018-5133
If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It…
Firefox
59.0+
HIGH 7.5
CVE-2018-5134
WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache", bypassing restrictions that …
Firefox
59.0+
HIGH 7.5
CVE-2018-5137
A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a…
Firefox
59.0+
MEDIUM 5.3
CVE-2018-5140
Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise prohibited. This could allow f…
Firefox
59.0+
MEDIUM 5.3
CVE-2018-5106
Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a user selects error links when…
Firefox
after 57.0.4
MEDIUM 5.3
CVE-2018-5114
If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document …
Firefox
after 57.0.4
HIGH 7.5
CVE-2018-5115
If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded for…
Firefox
after 57.0.4
MEDIUM 5.3
CVE-2018-5118
The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta tags of websites. An issue wa…
Firefox
after 57.0.4
MEDIUM 5.3
CVE-2018-5119
The reader view will display cross-origin content when CORS headers are set to prohibit the loading of cross-origin content by a site. This could all…
Firefox
after 57.0.4
MEDIUM 5.3
CVE-2017-7831
A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_exposedProps_" mechanism on proxy o…
Firefox
after 56.0.2
MEDIUM 5.3
CVE-2017-7842
If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" elements instead of one. One o…
Firefox
after 56.0.2