CVE-2018-1708
published 2018-10-11CVE-2018-1708: IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to obtain sensitive user information such as passwords through the WebUI. IBM X-Force…
PriorityP431medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.25%
66.0th percentile
IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to obtain sensitive user information such as passwords through the WebUI. IBM X-Force ID: 146343.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | platform_symphony | — | — |
| ibm | platform_symphony | — | — |
| ibm | spectrum_symphony | — | — |
| ibm | spectrum_symphony | — | — |
| ibm | specturm_symphony | — | — |
| ibm | specturm_symphony | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Checkpoint
26th February – Threat Intelligence Report
blogs_checkpoint·2024-02-26
CVE-2024-1708 26th February – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 26th February – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 26th February, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The American Prince George’s County Public Schools (PGCPS) has experienced a ransomware attack that compromised the personal data of nearly 100K individuals. The attack exposed individuals’ full names, financial account information, and Social Security Numbers. The Rhysida ransomware gang is reportedly responsible for t
Bugzilla
CVE-2018-12085 liblouis: Stack-based buffer overflow in compileTranslationTable.c
bugzilla·2018-06-11·CVSS 8.8
CVE-2018-12085 [HIGH] CVE-2018-12085 liblouis: Stack-based buffer overflow in compileTranslationTable.c
CVE-2018-12085 liblouis: Stack-based buffer overflow in compileTranslationTable.c
A flaw was found in Liblouis 3.6.0. A stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440.
References:
https://github.com/liblouis/liblouis/issues/595
Patch:
https://github.com/liblouis/liblouis/commit/dbfa58bb128cae86729578ac596056b3385817ef
Discussion:
Created liblouis tracking bugs for this issue:
Affects: fedora-all [bug 1589943]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:1708 https://access.redhat.com/errata/RHSA-2020:1708
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/se
Bugzilla
CVE-2018-11685 liblouis: Stack-based buffer overflow in function compileHyphenation in compileTranslationTable.c
bugzilla·2018-06-07·CVSS 8.8
CVE-2018-11685 [HIGH] CVE-2018-11685 liblouis: Stack-based buffer overflow in function compileHyphenation in compileTranslationTable.c
CVE-2018-11685 liblouis: Stack-based buffer overflow in function compileHyphenation in compileTranslationTable.c
Liblouis 3.5.0 has a stack-based Buffer Overflow in the function compileHyphenation in compileTranslationTable.c.
Upstream issue:
https://github.com/liblouis/liblouis/issues/593
Upstream patch:
https://github.com/liblouis/liblouis/commit/b5049cb17ae3d15b2b26890de0e24d0fecc080f5
Discussion:
Created liblouis tracking bugs for this issue:
Affects: fedora-all [bug 1588638]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:1708 https://access.redhat.com/errata/RHSA-2020:1708
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/
Bugzilla
CVE-2018-11577 liblouis: Segmentation fault in logging.c:lou_logPrint()
bugzilla·2018-06-05·CVSS 8.8
CVE-2018-11577 [HIGH] CVE-2018-11577 liblouis: Segmentation fault in logging.c:lou_logPrint()
CVE-2018-11577 liblouis: Segmentation fault in logging.c:lou_logPrint()
Liblouis before version 3.6.0 is vulnerable to a segmentation fault in the logging.c:lou_logPrint() function. An attacker could exploit this to cause a denial of service.
Upstream issue:
https://github.com/liblouis/liblouis/issues/582
Upstream patch:
https://github.com/liblouis/liblouis/commit/3cb3a2c7cb10daf42cefa40e70c8d4cc4e8f751f
Discussion:
Created liblouis tracking bugs for this issue:
Affects: fedora-all [bug 1585907]
---
Statement:
Red Hat Product Security has rated this issue as having security impact of Low, and a future update may address this flaw.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:1708 https://access.redhat.com/errata/RHSA
2018-10-11
Published