CVE-2018-1415
published 2018-02-22CVE-2018-1415: IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus…
PriorityP423medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.74%
50.4th percentile
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138821.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | maximo_asset_management | — | — |
| ibm | maximo_asset_management | — | — |
| ibm | maximo_asset_management | — | — |
| ibm | maximo_asset_management | — | — |
| ibm | maximo_asset_management | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5183 Mozilla: Backport critical security fixes in Skia
bugzilla·2018-05-09·CVSS 9.8
CVE-2018-5183 [CRITICAL] CVE-2018-5183 Mozilla: Backport critical security fixes in Skia
CVE-2018-5183 Mozilla: Backport critical security fixes in Skia
Mozilla developers backported selected changes in the Skia library to the ESR52 branch of Firefox. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5183
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Mozilla Developers
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1414 https://access.redhat.com/errata/RHSA-2018:1414
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1415 https://access.redhat.com/errata/RHSA-2018:1415
---
This issu
Bugzilla
CVE-2018-5178 Mozilla: Buffer overflow during UTF-8 to Unicode string conversion through legacy extension
bugzilla·2018-05-09·CVSS 8.1
CVE-2018-5178 [HIGH] CVE-2018-5178 Mozilla: Buffer overflow during UTF-8 to Unicode string conversion through legacy extension
CVE-2018-5178 Mozilla: Buffer overflow during UTF-8 to Unicode string conversion through legacy extension
A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the use of a malicious or vulnerable legacy extension in order to occur.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5178
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Root Object
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1414 https://access.redhat.com/errata/RHSA-2018:1414
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1415 https://access.re
Bugzilla
CVE-2018-5154 Mozilla: Use-after-free with SVG animations and clip paths
bugzilla·2018-05-09·CVSS 9.8
CVE-2018-5154 [CRITICAL] CVE-2018-5154 Mozilla: Use-after-free with SVG animations and clip paths
CVE-2018-5154 Mozilla: Use-after-free with SVG animations and clip paths
A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5154
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1414 https://access.redhat.com/errata/RHSA-2018:1414
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1415 https://access.redhat.com/errata/RHSA-2018:1415
---
This issue has been addressed in the following products:
Red Hat Enter
Bugzilla
CVE-2018-5157 Mozilla: Same-origin bypass of PDF Viewer to view protected PDF files
bugzilla·2018-05-09·CVSS 7.5
CVE-2018-5157 [HIGH] CVE-2018-5157 Mozilla: Same-origin bypass of PDF Viewer to view protected PDF files
CVE-2018-5157 Mozilla: Same-origin bypass of PDF Viewer to view protected PDF files
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5157
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Wladimir Palant
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1414 https://access.redhat.com/errata/RHSA-2018:1414
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1415 https://ac
Bugzilla
CVE-2018-5158 Mozilla: Malicious PDF can inject JavaScript into PDF Viewer
bugzilla·2018-05-09·CVSS 8.8
CVE-2018-5158 [HIGH] CVE-2018-5158 Mozilla: Malicious PDF can inject JavaScript into PDF Viewer
CVE-2018-5158 Mozilla: Malicious PDF can inject JavaScript into PDF Viewer
The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5158
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Wladimir Palant
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1414 https://access.redhat.com/errata/RHSA-2018:1414
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1415 https://access.redhat.com/errata
Bugzilla
CVE-2018-5159 Mozilla: Integer overflow and out-of-bounds write in Skia
bugzilla·2018-05-09·CVSS 9.8
CVE-2018-5159 [CRITICAL] CVE-2018-5159 Mozilla: Integer overflow and out-of-bounds write in Skia
CVE-2018-5159 Mozilla: Integer overflow and out-of-bounds write in Skia
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5159
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Ivan Fratric
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1414 https://access.redhat.com/errata/RHSA-2018:1414
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1415 https://access.redhat.com/errata
Bugzilla
CVE-2018-5155 Mozilla: Use-after-free with SVG animations and text paths
bugzilla·2018-05-09·CVSS 9.8
CVE-2018-5155 [CRITICAL] CVE-2018-5155 Mozilla: Use-after-free with SVG animations and text paths
CVE-2018-5155 Mozilla: Use-after-free with SVG animations and text paths
A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5155
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1414 https://access.redhat.com/errata/RHSA-2018:1414
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1415 https://access.redhat.com/errata/RHSA-2018:1415
---
This issue has been addressed in the following products:
Red Hat Enterprise
http://www.ibm.com/support/docview.wss?uid=swg22013796http://www.securityfocus.com/bid/103169https://exchange.xforce.ibmcloud.com/vulnerabilities/138821http://www.ibm.com/support/docview.wss?uid=swg22013796http://www.securityfocus.com/bid/103169https://exchange.xforce.ibmcloud.com/vulnerabilities/138821
2018-02-22
Published