VARIoT IoT vulnerabilities database
| VAR-201904-0754 | CVE-2018-4195 | Safari User interface mismatch vulnerability |
CVSS V2: 4.3 CVSS V3: 6.5 Severity: MEDIUM |
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 12. Apple Safari is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions. Apple Safari is a web browser developed by Apple (Apple), and is the default browser included with MacOSX and iOS operating systems. Attackers can use malicious websites to exploit this vulnerability to forge user interfaces. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
APPLE-SA-2018-9-24-3 Additional information for
APPLE-SA-2018-9-17-4 Safari 12
Safari 12 addresses the following:
Safari
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14
Impact: A user may be unable to delete browsing history items
Description: Clearing a history item may not clear visits with
redirect chains.
CVE-2018-4329: Hugo S.
CVE-2018-4195: xisigr of Tencent's Xuanwu Lab (www.tencent.com)
Security
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14
Impact: A malicious website may be able to exfiltrate autofilled data
in Safari
Description: A logic issue was addressed with improved state
management.
CVE-2018-4307: Rafay Baloch of Pakistan Telecommunications Authority
WebKit
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14
Impact: Unexpected interaction causes an ASSERT failure
Description: A memory corruption issue was addressed with improved
validation.
CVE-2018-4191: found by OSS-Fuzz
Entry added September 24, 2018
WebKit
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14
Impact: Cross-origin SecurityErrors includes the accessed frame's
origin
Description: The issue was addressed by removing origin information.
CVE-2018-4311: Erling Alf Ellingsen (@steike)
Entry added September 24, 2018
WebKit
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14
Impact: Processing maliciously crafted web content may lead to
arbitrary code execution
Description: A memory corruption issue was addressed with improved
state management.
CVE-2018-4316: crixer, Hanming Zhang (@4shitak4) of Qihoo 360 Vulcan
Team
Entry added September 24, 2018
WebKit
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14
Impact: Processing maliciously crafted web content may lead to
arbitrary code execution
Description: Multiple memory corruption issues were addressed with
improved memory handling.
CVE-2018-4299: Samuel GroI2 (saelo) working with Trend Micro's Zero
Day Initiative
CVE-2018-4323: Ivan Fratric of Google Project Zero
CVE-2018-4328: Ivan Fratric of Google Project Zero
CVE-2018-4358: @phoenhex team (@bkth_ @5aelo @_niklasb) working with
Trend Micro's Zero Day Initiative
CVE-2018-4359: Samuel GroA (@5aelo)
Entry added September 24, 2018
WebKit
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14
Impact: A malicious website may cause unexepected cross-origin
behavior
Description: A cross-origin issue existed with "iframe" elements.
This was addressed with improved tracking of security origins.
CVE-2018-4319: John Pettitt of Google
Entry added September 24, 2018
WebKit
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14
Impact: A malicious website may be able to execute scripts in the
context of another website
Description: A cross-site scripting issue existed in Safari.
CVE-2018-4309: an anonymous researcher working with Trend Micro's
Zero Day Initiative
Entry added September 24, 2018
WebKit
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14
Impact: Processing maliciously crafted web content may lead to
arbitrary code execution
Description: A use after free issue was addressed with improved
memory management.
CVE-2018-4197: Ivan Fratric of Google Project Zero
CVE-2018-4306: Ivan Fratric of Google Project Zero
CVE-2018-4312: Ivan Fratric of Google Project Zero
CVE-2018-4314: Ivan Fratric of Google Project Zero
CVE-2018-4315: Ivan Fratric of Google Project Zero
CVE-2018-4317: Ivan Fratric of Google Project Zero
CVE-2018-4318: Ivan Fratric of Google Project Zero
Entry added September 24, 2018
WebKit
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14
Impact: A malicious website may exfiltrate image data cross-origin
Description: A cross-site scripting issue existed in Safari.
CVE-2018-4345: an anonymous researcher
Entry added September 24, 2018
WebKit
Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS
Mojave 10.14
Impact: Unexpected interaction causes an ASSERT failure
Description: A memory consumption issue was addressed with improved
memory handling.
CVE-2018-4361: found by Google OSS-Fuzz
Entry added September 24, 2018
Additional recognition
WebKit
We would like to acknowledge Cary Hartline, Hanming Zhang from 360
Vuclan team, Tencent Keen Security Lab working with Trend Micro's
Zero Day Initiative, and Zach Malone of CA Technologies for their
assistance.
Installation note:
Safari 12 may be obtained from the Mac App Store.
Information will also be posted to the Apple Security Updates
web site: https://support.apple.com/kb/HT201222
This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEDNXJVNCJJEAVmJdZeC9tht7TK3EFAlupFUIACgkQeC9tht7T
K3EOzBAAr4Kr9hZVKV603mOTE9cq6boEBYJLYJUN2/VjLzBPYWYr/e8tPg0P1EWr
i67b/0pWifR6A73F53oCxMzdumfwC4by2n106ABrx5KPYmbz5YBk8X/YEEWokBdK
zK/AJpQo768pTUIxlVuhIOsCLOieMRX3kiPWIg10WeIEggEnyavK9/emNyUu08GV
AXviCAz2vohBgG0pAvgKt2HD/yTxG2n+gdP9krOT9mMh0aH1tTlZ8107cF2bTWwv
yZw9LSCELre6cKOx4iDaY+vpPWGXwI+8+6hXYqKjNBomgJhLeQVqIdBo29IM0HTO
FZcyrQ5djoNDl8ZfGUAwFtyDhD4Fmdb/JyDdvLXME/GL2fPWG8hqDS5EGU/cNIus
ugQv/zsm6pXqLWt+sxbP5lU4Uuwfkw4H7HwwBxoE04ufGfxurEBgTIIQn+KwYg9J
ODrdoqsIDThOtqQHxzp0//+rs0hg49jGm4P8eSG86Oycoyw/Q9/pzCKeQGazfyfF
cTNX3wsZA84RVbHLVWbp0ZnYhVrH1iL61ipzH2hDTUbjelvv4u4pN6flIM6Kw9uN
J5bYuFOXzv61bxMe8fdAlZixqFXqJ5oNBTZOdaicZEKmfRTTh4p1BLTWcFSRbp7K
wCXqHSwmD7RjGr0Qbr/CvJFb/+kOrzQIHX7sCR6ZIusZPLpTYXI=
=4ySP
-----END PGP SIGNATURE-----
| VAR-201809-1333 | No CVE | High Password Network Firmware Router Has Weak Password Vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Shanghai Guoyun Information Technology Co., Ltd. is a provider of intelligent network products and services.
A high-level network firmware router has a weak password vulnerability. Allow attackers to brute force account passwords, log in to the system, and obtain sensitive information.
| VAR-201809-0769 | CVE-2018-17068 | D-Link DIR-816 A2 Command injection vulnerabilities in devices |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/Diagnosis route. This could lead to command injection via shell metacharacters in the sendNum parameter. D-Link DIR-816 A2 The device contains a command injection vulnerability.Information is acquired, information is falsified, and denial of service (DoS) May be in a state. D-LinkDIR-816A2 is a wireless router product of D-Link. There is a command injection vulnerability in D-LinkDIR-816A21.10B05. This vulnerability is caused by the program using the 'sendNum' parameter value when building the 'ping-c%s...' command
| VAR-201809-0767 | CVE-2018-17066 | D-Link DIR-816 A2 Command injection vulnerability in devices |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/form2systime.cgi route. This could lead to command injection via shell metacharacters in the datetime parameter. D-Link DIR-816 A2 The device contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. D-LinkDIR-816 is a home router product from Friends of the company. A command injection vulnerability exists in D-LinkDIR-816A21.10B05. This vulnerability is caused by the program using the \342\200\230datetime\342\200\231 parameter value to construct the \342\200\230date-s\342\200\235%s\342\200\235 command, which can be exploited by an attacker
| VAR-201809-0765 | CVE-2018-17064 | D-Link DIR-816 A2 Command injection vulnerability in devices |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/sylogapply route. This could lead to command injection via the syslogIp parameter after /goform/clearlog is invoked. D-Link DIR-816 A2 The device contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. D-LinkDIR-816 is a home router product from Friends of the company. A command injection vulnerability exists in D-LinkDIR-816A21.10B05, which is caused by a program using HTTP requests to build commands that an attacker can use to inject commands. The /goform/sylogapply in D-Link DIR-816 A2 version 1.10 B05 has an operating system command injection vulnerability
| VAR-201809-0768 | CVE-2018-17067 | D-Link DIR-816 A2 Device buffer error vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. A very long password to /goform/formLogin could lead to a stack-based buffer overflow and overwrite the return address. D-Link DIR-816 A2 The device contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. D-LinkDIR-816A2 is a wireless router product of D-Link. A stack buffer overflow vulnerability exists in D-LinkDIR-816A21.10B05
| VAR-201809-0764 | CVE-2018-17063 | D-Link DIR-816 A2 Command injection vulnerability in devices |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/NTPSyncWithHost route. This could lead to command injection via shell metacharacters. D-Link DIR-816 A2 The device contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. D-LinkDIR-816A2 is a wireless router product of D-Link. A command injection vulnerability exists in D-LinkDIR-816A21.10B05, which is caused by a program using HTTP requests to build commands that an attacker can use to send arbitrary code to execute arbitrary code on the system. The /goform/NTPSyncWithHost in D-Link DIR-816 A2 version 1.10 B05 has an operating system command injection vulnerability
| VAR-201809-0766 | CVE-2018-17065 | D-Link DIR-816 A2 Device buffer error vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/DDNS route, a very long password could lead to a stack-based buffer overflow and overwrite the return address. D-Link DIR-816 A2 The device contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. D-LinkDIR-816A2 is a wireless router product of D-Link. A stack-based buffer overflow vulnerability exists in D-Link DIR-816 A2 version 1.10 B05
| VAR-201809-0942 | CVE-2018-16242 | Hangzhou Luoping Smart Locker Access control vulnerability |
CVSS V2: 2.9 CVSS V3: 5.3 Severity: MEDIUM |
oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol. Hangzhou Luoping Smart Locker Contains an access control vulnerability.Information may be tampered with. oBike is a bicycle sharing system of Singapore oBike Company. There is a security flaw in oBike
| VAR-201809-1341 | No CVE | Hikvision hik-connect.com Certification Vulnerability |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
Hikvision is a video-centric IoT solution provider. Hikvisionhik-connect.com has an authentication vulnerability. An attacker could exploit the vulnerability to change the cookie value to someone else's user ID that would result in logging in with that user.
| VAR-201809-1207 | No CVE | Hollysys LE5109L PLC Denial of Service Vulnerability (CNVD-2018-18910) |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hollysys Group is a professional automation company integrating R & D, production, sales and technical services.
Hollysys LE5109L PLC has a denial-of-service vulnerability. An attacker can construct a specific network packet without authorization, and the vulnerability can cause the PLC to deny service
| VAR-201809-1208 | No CVE | Hollysys LE5109L PLC has remote controller removal vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Hollysys Group is a professional automation company integrating R & D, production, sales and technical services.
Hollysys LE5109L PLC has a remote controller removal vulnerability. An attacker can remotely clear all programs and configuration information of the controller in the PLC by constructing a specific modbus data packet
| VAR-201809-1214 | No CVE | Hollysys LE5109L PLC has remote control vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hollysys Group is a professional automation company integrating R & D, production, sales and technical services.
Hollysys LE5109L PLC has a remote control vulnerability. An attacker can use the vulnerability to cause the PLC to be remotely controlled by constructing a specific private protocol data packet
| VAR-201809-1196 | No CVE | Hollysys LE5109L PLC Denial of Service Vulnerability (CNVD-2018-18909) |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hollysys Group is a professional automation company integrating R & D, production, sales and technical services.
Hollysys LE5109L PLC has a denial of service vulnerability. An attacker can use the vulnerability to cause the PLC to deny service by constructing specific private protocol data packets
| VAR-201809-1193 | No CVE | Hollysys LE5109L PLC Has Arbitrary Program Clearance Vulnerabilities |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Hollysys Group is a professional automation company integrating R & D, production, sales and technical services.
Hollysys LE5109L PLC has an arbitrary program removal vulnerability. An attacker can construct a specific network data packet by unauthorized use. The vulnerability can cause the program in the PLC controller to be maliciously removed
| VAR-201809-1213 | No CVE | Hollysys LE5109L PLC has arbitrary memory tampering vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Hollysys Group is a professional automation company integrating R & D, production, sales and technical services.
Hollysys LE5109L PLC has an arbitrary memory tampering vulnerability. An attacker can use the vulnerability to remotely tamper with PLC register values by constructing a specific modbus data packet
| VAR-201809-1195 | No CVE | Hollysys LE5109L PLC Denial of Service Vulnerability (CNVD-2018-18906) |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Hollysys Group is a professional automation company integrating R & D, production, sales and technical services.
Hollysys LE5109L PLC has a denial of service vulnerability. An attacker can use the vulnerability to cause the PLC to be remotely controlled by constructing a specific private protocol data packet. PLC Be remotely controlled
| VAR-201809-1194 | No CVE | Hollysys LE5109L PLC has an arbitrary memory read vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hollysys Group is a professional automation company integrating R & D, production, sales and technical services.
Hollysys LE5109L PLC has an arbitrary memory read vulnerability. An attacker can construct a specific modbus data packet and use the vulnerability to cause any register value in the PLC to be read arbitrarily
| VAR-201809-1114 | CVE-2018-7929 | Huawei Mate RS Vulnerability related to access control in smartphones |
CVSS V2: 4.6 CVSS V3: 6.8 Severity: MEDIUM |
Huawei Mate RS smartphones with the versions before NEO-AL00D 8.1.0.167(C786) have a lock-screen bypass vulnerability. An attacker could unlock and use the phone through certain operations. Huawei Mate RS Smartphones have access control vulnerabilities.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state
| VAR-201809-0093 | CVE-2018-12086 | OPC UA Application buffer error vulnerability |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests. OPC UA The application contains a buffer error vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. OPC UA applications is a platform-independent service-oriented unified architecture application from the OPC (OLE for Process Control) Foundation. SAP Plant Connectivity is prone to multiple denial-of-service vulnerabilities.
Attackers can exploit these issues to cause denial-of-service conditions, denying service to legitimate users. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-4359-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
December 27, 2018 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : wireshark
CVE ID : CVE-2018-12086 CVE-2018-18225 CVE-2018-18226
CVE-2018-18227 CVE-2018-19622 CVE-2018-19623
CVE-2018-19624 CVE-2018-19625 CVE-2018-19626
CVE-2018-19627 CVE-2018-19628
Multiple vulnerabilities have been discovered in Wireshark, a network
protocol analyzer, which could result in denial of service or the
execution of arbitrary code.
For the stable distribution (stretch), these problems have been fixed in
version 2.6.5-1~deb9u1.
We recommend that you upgrade your wireshark packages.
For the detailed security status of wireshark please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/wireshark
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlwk6BkACgkQEMKTtsN8
TjZeQg//epVGPGld0oOwn+9I3rD4C0GZMKOCtHW7xR5x+YKMntG7VzLAcSv33EEi
hDj2V0ZFr8NIWab0qtTun4BQMMZ7J80hy//hFr9OcAu1apdG38KW0drMG2/sBBL8
HH6ndYLgrtxqbtmqNBxPrabq+Fj01jlCwTmrd9ig0/ZQOSlRbfM+Snfjxpmwlsgl
x8ZoWi9TPD+ILZe2V6m4w81aR6FF3e540W6ADAJ233gpJbQ5mHvOlX1tJzPDTQOe
8KqGZ4FhYan7wO6u41gRHCtqMEymh1LRc+zTzeow9jNs7u83GRMT4bqerCkVKI3W
JPr1+EbYNyZApWYzeigomGQSXiTMKvURm1NxevhhZW81y0xJgHS7q7gsvu1zitQl
hUqA9r/F74Ts6uru+ubknk1OeA0UrY/ZXVMZUgsYAZ4vFvcvPzK2gqZoBMI0tAy5
PxAnScxMalJA8faUsjl/0O5URG/Sv0MKzLo9hexog7dE/vH0j5iuZqbhT7UDmvdL
B2l7XwVlZCKI5pLgNhCqBSxf3mL7sr/wzpPF2YYuFGTGQ+doTy6C9GL1Z/J/087w
Hbd7i5Pnu+GM+SXswSIsDNsq4fMYHrBJvJz+w2YWImdKuR9+fKSPAtdto/id5t9m
s61uMXB9ul+5H0pw19otWQUvJog5qcCrTFLEe5F+CMUJDjWDqrY=xlYz
-----END PGP SIGNATURE-----