CVE-2018-1414
published 2018-02-22CVE-2018-1414: IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the…
PriorityP352high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.54%
72.0th percentile
IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 138820.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | maximo_asset_management | — | — |
| ibm | maximo_asset_management | — | — |
| ibm | maximo_asset_management | — | — |
| ibm | maximo_asset_management | — | — |
| ibm | maximo_asset_management_essentials | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5183 Mozilla: Backport critical security fixes in Skia
bugzilla·2018-05-09·CVSS 9.8
CVE-2018-5183 [CRITICAL] CVE-2018-5183 Mozilla: Backport critical security fixes in Skia
CVE-2018-5183 Mozilla: Backport critical security fixes in Skia
Mozilla developers backported selected changes in the Skia library to the ESR52 branch of Firefox. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5183
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Mozilla Developers
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1414 https://access.redhat.com/errata/RHSA-2018:1414
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1415 https://access.redhat.com/errata/RHSA-2018:1415
---
This issu
Bugzilla
CVE-2018-5178 Mozilla: Buffer overflow during UTF-8 to Unicode string conversion through legacy extension
bugzilla·2018-05-09·CVSS 8.1
CVE-2018-5178 [HIGH] CVE-2018-5178 Mozilla: Buffer overflow during UTF-8 to Unicode string conversion through legacy extension
CVE-2018-5178 Mozilla: Buffer overflow during UTF-8 to Unicode string conversion through legacy extension
A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the use of a malicious or vulnerable legacy extension in order to occur.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5178
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Root Object
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1414 https://access.redhat.com/errata/RHSA-2018:1414
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1415 https://access.re
Bugzilla
CVE-2018-5150 Mozilla: Memory safety bugs fixed in Firefox 60 and Firefox ESR 52.8
bugzilla·2018-05-09·CVSS 9.8
CVE-2018-5150 [CRITICAL] CVE-2018-5150 Mozilla: Memory safety bugs fixed in Firefox 60 and Firefox ESR 52.8
CVE-2018-5150 Mozilla: Memory safety bugs fixed in Firefox 60 and Firefox ESR 52.8
Mozilla developers and community members reported memory safety bugs present in Firefox 59 and Firefox ESR 52.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5150
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Christoph Diehl, Randell Jesup, Tyson Smith, Alex Gaynor, Ronald Crane, Julian Hector, Kannan Vijayan, Jason Kratzer
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1414 https://access.redhat.com/errata/RHSA-2018:1414
--
Bugzilla
CVE-2018-5154 Mozilla: Use-after-free with SVG animations and clip paths
bugzilla·2018-05-09·CVSS 9.8
CVE-2018-5154 [CRITICAL] CVE-2018-5154 Mozilla: Use-after-free with SVG animations and clip paths
CVE-2018-5154 Mozilla: Use-after-free with SVG animations and clip paths
A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5154
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1414 https://access.redhat.com/errata/RHSA-2018:1414
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1415 https://access.redhat.com/errata/RHSA-2018:1415
---
This issue has been addressed in the following products:
Red Hat Enter
Bugzilla
CVE-2018-5157 Mozilla: Same-origin bypass of PDF Viewer to view protected PDF files
bugzilla·2018-05-09·CVSS 7.5
CVE-2018-5157 [HIGH] CVE-2018-5157 Mozilla: Same-origin bypass of PDF Viewer to view protected PDF files
CVE-2018-5157 Mozilla: Same-origin bypass of PDF Viewer to view protected PDF files
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5157
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Wladimir Palant
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1414 https://access.redhat.com/errata/RHSA-2018:1414
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1415 https://ac
Bugzilla
CVE-2018-5158 Mozilla: Malicious PDF can inject JavaScript into PDF Viewer
bugzilla·2018-05-09·CVSS 8.8
CVE-2018-5158 [HIGH] CVE-2018-5158 Mozilla: Malicious PDF can inject JavaScript into PDF Viewer
CVE-2018-5158 Mozilla: Malicious PDF can inject JavaScript into PDF Viewer
The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5158
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Wladimir Palant
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1414 https://access.redhat.com/errata/RHSA-2018:1414
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1415 https://access.redhat.com/errata
Bugzilla
CVE-2018-5159 Mozilla: Integer overflow and out-of-bounds write in Skia
bugzilla·2018-05-09·CVSS 9.8
CVE-2018-5159 [CRITICAL] CVE-2018-5159 Mozilla: Integer overflow and out-of-bounds write in Skia
CVE-2018-5159 Mozilla: Integer overflow and out-of-bounds write in Skia
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5159
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Ivan Fratric
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1414 https://access.redhat.com/errata/RHSA-2018:1414
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1415 https://access.redhat.com/errata
Bugzilla
CVE-2018-5155 Mozilla: Use-after-free with SVG animations and text paths
bugzilla·2018-05-09·CVSS 9.8
CVE-2018-5155 [CRITICAL] CVE-2018-5155 Mozilla: Use-after-free with SVG animations and text paths
CVE-2018-5155 Mozilla: Use-after-free with SVG animations and text paths
A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5155
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1414 https://access.redhat.com/errata/RHSA-2018:1414
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1415 https://access.redhat.com/errata/RHSA-2018:1415
---
This issue has been addressed in the following products:
Red Hat Enterprise
Bugzilla
CVE-2018-5168 Mozilla: Lightweight themes can be installed without user interaction
bugzilla·2018-05-09·CVSS 5.3
CVE-2018-5168 [MEDIUM] CVE-2018-5168 Mozilla: Lightweight themes can be installed without user interaction
CVE-2018-5168 Mozilla: Lightweight themes can be installed without user interaction
Sites can bypass security checks on permissions to install lightweight themes by manipulating the `baseURI` property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5168
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Wladimir Palant
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1414 https://access.redhat.com/errata/RHSA-2018:1414
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-
http://www.ibm.com/support/docview.wss?uid=swg22013797http://www.securityfocus.com/bid/103154https://exchange.xforce.ibmcloud.com/vulnerabilities/138820http://www.ibm.com/support/docview.wss?uid=swg22013797http://www.securityfocus.com/bid/103154https://exchange.xforce.ibmcloud.com/vulnerabilities/138820
2018-02-22
Published