CVE Database

Comprehensive vulnerability intelligence with advanced analytics

6.3

CVE-2018-0161

Medium KEV

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition, aka a GET MIB Object ID Denial of Service Vulnerability. The vulnerability is due…

Published: Mar 28, 2018
Modified: Jan 14, 2026
Product: cisco ios
EPSS: 1.66%
View Details
7.5

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation…

Published: Mar 28, 2018
Modified: Jan 14, 2026
Product: cisco ios_xe
EPSS: 6.44%
View Details
8.6

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is…

Published: Mar 28, 2018
Modified: Jan 12, 2026
Product: cisco ios
EPSS: 11.32%
View Details
7.5

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of packet data. An attacker…

Published: Mar 28, 2018
Modified: Jan 13, 2026
Product: cisco ios_xe
EPSS: 9.70%
View Details
8.6

A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial of service (DoS) condition. The vulnerability is due to insufficient error…

Published: Mar 28, 2018
Modified: Jan 13, 2026
Product: cisco ios
EPSS: 11.22%
View Details
7.5

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient handling of VPN traffic by the affected…

Published: Mar 28, 2018
Modified: Jan 13, 2026
Product: cisco ios
EPSS: 8.96%
View Details
9.8

CVE-2018-0151

Critical KEV

A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges. The vulnerability is due to incorrect bounds checking of certain values…

Published: Mar 28, 2018
Modified: Jan 13, 2026
Product: cisco ios_xe
EPSS: 5.86%
View Details
6.1

CVE-2018-6882

Medium KEV

Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment.

Published: Mar 27, 2018
Modified: Nov 04, 2025
Product: synacor zimbra_collaboration_suite
EPSS: 63.35%
View Details
5.9

CVE-2017-12319

Medium KEV

A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result…

Published: Mar 27, 2018
Modified: Jan 13, 2026
Product: cisco ios
EPSS: 0.94%
View Details
9.8

CVE-2018-0147

Critical KEV

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could…

Published: Mar 08, 2018
Modified: Jan 12, 2026
Product: cisco secure_access_control_system
EPSS: 3.00%
View Details
9.8

CVE-2018-6530

Critical KEV

OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.

Published: Mar 06, 2018
Modified: Nov 07, 2025
Product: dlink dir-880l_firmware
EPSS: 94.04%
View Details
9.8

CVE-2018-0125

Critical KEV

A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. The attacker could also cause an affected…

Published: Feb 08, 2018
Modified: Oct 28, 2025
Product: cisco rv132w_firmware
EPSS: 39.59%
View Details
7.8

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0797 and CVE-2018-0812.

Published: Jan 10, 2018
Modified: Oct 28, 2025
Product: microsoft word
EPSS: 94.07%
View Details
8.8

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability".

Published: Jan 10, 2018
Modified: Oct 28, 2025
Product: microsoft word
EPSS: 94.06%
View Details
7.8

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack…

Published: Nov 09, 2017
Modified: Oct 22, 2025
Product: roundcube webmail
EPSS: 30.22%
View Details
8.8

Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

Published: Oct 27, 2017
Modified: Oct 22, 2025
Product: redhat enterprise_linux_server
EPSS: 71.10%
View Details
8.8

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.

Published: Oct 22, 2017
Modified: Oct 22, 2025
Product: adobe flash_player_desktop_runtime
EPSS: 21.24%
View Details
7.8

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.

Published: Oct 13, 2017
Modified: Oct 22, 2025
Product: microsoft word
EPSS: 90.48%
View Details
7.8

Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability."

Published: Oct 13, 2017
Modified: Oct 22, 2025
Product: microsoft outlook
EPSS: 82.85%
View Details
9.8

CVE-2017-12149

Critical KEV

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.

Published: Oct 04, 2017
Modified: Oct 22, 2025
Product: redhat jboss_enterprise_application_platform
EPSS: 94.29%
View Details
9.8

CVE-2017-12240

Critical KEV

The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system. The attacker could also cause an affected system to reload, resulting in a…

Published: Sep 29, 2017
Modified: Jan 12, 2026
EPSS: 7.92%
View Details
6.5

CVE-2017-12238

Medium KEV

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition. The vulnerability is…

Published: Sep 29, 2017
Modified: Jan 12, 2026
EPSS: 1.15%
View Details
7.5

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of…

Published: Sep 29, 2017
Modified: Jan 12, 2026
EPSS: 5.32%
View Details
7.5

A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper parsing of ingress…

Published: Sep 29, 2017
Modified: Jan 12, 2026
EPSS: 4.93%
View Details