CVE-2018-7829
published 2019-05-22CVE-2018-7829: An Improper Neutralization of Special Elements in Query vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which…
PriorityP355high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.72%
74.9th percentile
An Improper Neutralization of Special Elements in Query vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which allows an attacker to execute arbitrary system commands.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | d6220_firmware | >= 2.11 | — |
| schneider-electric | d6220l_firmware | >= 2.11 | — |
| schneider-electric | d6230_firmware | >= 2.11 | — |
| schneider-electric | d6230l_firmware | >= 2.11 | — |
| schneider-electric | ime119-1ei_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime119-1ep_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime119-1es_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime119-1i_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime119-1p_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime119-1s_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime119-1vi_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime119-1vp_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime119-1vs_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime219-1ei_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime219-1ep_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime219-1es_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime219-1i_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime219-1p_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime219-1s_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime219-1vi_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime219-1vp_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime219-1vs_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime3122-1ei_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime3122-1ep_firmware | < 2.2.3.0 | 2.2.3.0 |
| schneider-electric | ime3122-1es_firmware | < 2.2.3.0 | 2.2.3.0 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7846 Mozilla: JavaScript Execution via RSS in mailbox:// origin
bugzilla·2018-01-02·CVSS 5.3
CVE-2017-7846 [MEDIUM] CVE-2017-7846 Mozilla: JavaScript Execution via RSS in mailbox:// origin
CVE-2017-7846 Mozilla: JavaScript Execution via RSS in mailbox:// origin
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via “View -> Feed article -> Website” or in the standard format of “View -> Feed article -> default format”.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: cure53
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-30/#CVE-2017-7829
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0061 https://access.redhat.com/errata/RHSA-2018:0061
Bugzilla
CVE-2017-7829 Mozilla: From address with encoded null character is cut off in message header display
bugzilla·2018-01-02·CVSS 5.3
CVE-2017-7829 [MEDIUM] CVE-2017-7829 Mozilla: From address with encoded null character is cut off in message header display
CVE-2017-7829 Mozilla: From address with encoded null character is cut off in message header display
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Sabri Haddouche
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-30/#CVE-2017-7829
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0061 https://access.redhat.com/errata/RHSA-2018:0061
2019-05-22
Published