CVE-2018-3006
published 2018-07-18CVE-2018-3006: Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime). The supported version that is affected…
PriorityP429medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.54%
72.2th percentile
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jd_edwards_enterpriseone_tools | — | — |
| oracle_corporation | jd_edwards_enterpriseone_tools | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-12395 Mozilla: WebExtension bypass of domain restrictions through header rewriting
bugzilla·2018-10-23·CVSS 7.5
CVE-2018-12395 [HIGH] CVE-2018-12395 Mozilla: WebExtension bypass of domain restrictions through header rewriting
CVE-2018-12395 Mozilla: WebExtension bypass of domain restrictions through header rewriting
By rewriting the `Host` request headers using the `webRequest` API, a WebExtension can bypass domain restrictions through domain fronting. This would allow access to domains that share a host that are otherwise restricted.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/#CVE-2018-12395
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Rob Wu, Andrew Swan
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:3005 https://access.redhat.com/errata/RHSA-2018:3005
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:3006 https://access.redhat.com
Bugzilla
CVE-2018-12392 Mozilla: Crash with nested event loops
bugzilla·2018-10-23·CVSS 9.8
CVE-2018-12392 [CRITICAL] CVE-2018-12392 Mozilla: Crash with nested event loops
CVE-2018-12392 Mozilla: Crash with nested event loops
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/#CVE-2018-12392
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:3005 https://access.redhat.com/errata/RHSA-2018:3005
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:3006 https://access.redhat.com/errata/RHSA-2018:3006
---
This issue has been addressed in the following products:
Red Hat Enterpri
Bugzilla
CVE-2018-12396 Mozilla: WebExtension content scripts can execute in disallowed contexts
bugzilla·2018-10-23·CVSS 6.5
CVE-2018-12396 [MEDIUM] CVE-2018-12396 Mozilla: WebExtension content scripts can execute in disallowed contexts
CVE-2018-12396 Mozilla: WebExtension content scripts can execute in disallowed contexts
A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/#CVE-2018-12396
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Rob Wu
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:3005 https://access.redhat.com/errata/RHSA-2018:3005
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:3006 https://access.redhat.com/
Bugzilla
CVE-2018-12389 Mozilla: Memory safety bugs fixed in Firefox ESR 60.3
bugzilla·2018-10-23·CVSS 8.8
CVE-2018-12389 [HIGH] CVE-2018-12389 Mozilla: Memory safety bugs fixed in Firefox ESR 60.3
CVE-2018-12389 Mozilla: Memory safety bugs fixed in Firefox ESR 60.3
Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/#CVE-2018-12389
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Daniel Veditz, Philipp
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:3005 https://access.redhat.com/errata/RHSA-2018:3005
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:3006 https://access
Bugzilla
CVE-2018-12393 Mozilla: Integer overflow during Unicode conversion while loading JavaScript
bugzilla·2018-10-23·CVSS 7.5
CVE-2018-12393 [HIGH] CVE-2018-12393 Mozilla: Integer overflow during Unicode conversion while loading JavaScript
CVE-2018-12393 Mozilla: Integer overflow during Unicode conversion while loading JavaScript
A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write.
*Note: 64-bit builds are not vulnerable to this issue.*
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-27/#CVE-2018-12393
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:3005 https://access.redhat.com/errata/RHSA-2018:3005
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:3006 https://ac
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securityfocus.com/bid/104789http://www.securitytracker.com/id/1041305http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securityfocus.com/bid/104789http://www.securitytracker.com/id/1041305
2018-07-18
Published