Monthly Archive: February 2018

CVE-2018-0518

LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. Date published : 2018-02-23...

CVE-2017-5250

In version 1.9.7 and prior of Insteon’s Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner. Date published...

CVE-2017-5249

In version 6.1.0.19 and prior of Wink Labs’s Wink – Smart Home Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner....

CVE-2018-7408

An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgrade -g npm" command, and also announced in the vendor’s blog without mention...

CVE-2018-7319

SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system1, or laundry parameter. Date published : 2018-02-22 https://exploit-db.com/exploits/44165

CVE-2018-7315

SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, caste, or country parameter. Date published : 2018-02-22 https://exploit-db.com/exploits/44161