SecPod

Learn Search

Search across all Learn content

← Back to Security Research

SCAP Feed Release : 01-Nov-2018

The following SCAP content has been released to SCAP Repo and SecPod Saner Solution. SecPod Saner will automatically pull the relevant content on its next scheduled update.

Oct 31, 2018By Kumarswamy S4 min read

The following SCAP content has been released to SCAP Repo and SecPod Saner Solution. SecPod Saner will automatically pull the relevant content on its next scheduled update.

oval:org.secpod.oval:def:48559 CVE-2018-17615 Arbitrary code execution vulnerability in Foxit Reader while handling Mouse Exit events
oval:org.secpod.oval:def:48560 CVE-2018-17616 Arbitrary code execution vulnerability in Foxit Reader while handling onBlur events
oval:org.secpod.oval:def:48561 CVE-2018-17617 Arbitrary code execution vulnerability in Foxit Reader while handling onFocus events
oval:org.secpod.oval:def:48562 CVE-2018-17618 Arbitrary code execution vulnerability in Foxit Reader while handling Selection Change events
oval:org.secpod.oval:def:48563 CVE-2018-17619 Arbitrary code execution vulnerability in Foxit Reader while handling Validate events
oval:org.secpod.oval:def:48564 CVE-2018-17620 Arbitrary code execution vulnerability in Foxit Reader – CVE-2018-17620
oval:org.secpod.oval:def:48565 CVE-2018-17621 Arbitrary code execution vulnerability in Foxit Reader while handling Format events
oval:org.secpod.oval:def:48566 CVE-2018-17622 Information disclosure vulnerability in Foxit Reader while handling Calculate events
oval:org.secpod.oval:def:48567 CVE-2018-17623 Arbitrary code execution vulnerability in Foxit Reader while handling Link objects
oval:org.secpod.oval:def:48568 CVE-2018-17624 Arbitrary code execution vulnerability in Foxit Reader while handling OCG objects
oval:org.secpod.oval:def:48569 CVE-2018-17706 Arbitrary code execution vulnerability in in fxhtml2pdf in Foxit PhantomPDF
oval:org.secpod.oval:def:48570 CVE-2018-3136
CVE-2018-3139
CVE-2018-3149
CVE-2018-3169
CVE-2018-3180
CVE-2018-3183
CVE-2018-3214
USN-3804-1
USN-3804-1 — openjdk vulnerabilities
oval:org.secpod.oval:def:48571 CVE-2018-4398 Unspecified vulnerability in Apple iTunes and iCloud due to a weakness in the Miller-Rabin primality test
oval:org.secpod.oval:def:48572 CVE-2018-4394 Memory corruption vulnerability in Apple iTunes – CVE-2018-4394
oval:org.secpod.oval:def:48573 CVE-2018-4374 Universal XSS vulnerability in the Safari Reader feature in Apple iTunes and iCloud – CVE-2018-4374
oval:org.secpod.oval:def:48574 CVE-2018-4377 Universal XSS vulnerability in the Safari Reader feature in Apple iTunes and iCloud
oval:org.secpod.oval:def:48575 CVE-2018-4372 Memory corruption vulnerability in Webkit in Apple iTunes and iCloud – CVE-2018-4372
oval:org.secpod.oval:def:48576 CVE-2018-4373 Memory corruption vulnerability in Webkit in Apple iTunes and iCloud – CVE-2018-4373
oval:org.secpod.oval:def:48577 CVE-2018-4375 Memory corruption vulnerability in Webkit in Apple iTunes and iCloud – CVE-2018-4375
oval:org.secpod.oval:def:48578 CVE-2018-4376 Memory corruption vulnerability in Webkit in Apple iTunes and iCloud – CVE-2018-4376
oval:org.secpod.oval:def:48579 CVE-2018-4382 Memory corruption vulnerability in Webkit in Apple iTunes and iCloud – CVE-2018-4382
oval:org.secpod.oval:def:48580 CVE-2018-4386 Memory corruption vulnerability in Webkit in Apple iTunes and iCloud – CVE-2018-4386
oval:org.secpod.oval:def:48581 CVE-2018-4392 Memory corruption vulnerability in Webkit in Apple iTunes and iCloud – CVE-2018-4392
oval:org.secpod.oval:def:48582 CVE-2018-4416 Denial of service vulnerability in Webkit in Apple iTunes and iCloud
oval:org.secpod.oval:def:48583 CVE-2018-4378 Memory corruption vulnerability in Webkit in Apple iTunes and iCloud – CVE-2018-4378
oval:org.secpod.oval:def:48584 CVE-2018-4409 Denial of service vulnerability in Webkit in Apple iTunes and iCloud
oval:org.secpod.oval:def:48585 APPLE-SA-2018-10-30-6
CVE-2018-4372
CVE-2018-4373
CVE-2018-4374
CVE-2018-4375
CVE-2018-4376
CVE-2018-4377
CVE-2018-4378
CVE-2018-4382
CVE-2018-4386
CVE-2018-4392
CVE-2018-4394
CVE-2018-4398
CVE-2018-4409
CVE-2018-4416
Multiple vulnerabilities in Apple iTunes – APPLE-SA-2018-10-30-6
oval:org.secpod.oval:def:48586 APPLE-SA-2018-10-30-7
CVE-2018-4372
CVE-2018-4373
CVE-2018-4374
CVE-2018-4375
CVE-2018-4376
CVE-2018-4377
CVE-2018-4378
CVE-2018-4382
CVE-2018-4386
CVE-2018-4392
CVE-2018-4398
CVE-2018-4409
CVE-2018-4416
Multiple vulnerabilities in Apple iCloud – APPLE-SA-2018-10-30-7
oval:org.secpod.oval:def:48587 APPLE-SA-2018-10-30-3
CVE-2018-4372
CVE-2018-4373
CVE-2018-4374
CVE-2018-4375
CVE-2018-4376
CVE-2018-4377
CVE-2018-4378
CVE-2018-4382
CVE-2018-4386
CVE-2018-4392
CVE-2018-4409
CVE-2018-4416
Multiple vulnerabilities in Apple Safari – APPLE-SA-2018-10-30-3
oval:org.secpod.oval:def:48588 CVE-2018-4374 Cross site scripting vulnerability in Apple Safari via a malicious website – CVE-2018-4374
oval:org.secpod.oval:def:48589 CVE-2018-4377 Cross site scripting vulnerability in Apple Safari via a malicious website – CVE-2018-4377
oval:org.secpod.oval:def:48590 CVE-2018-4372 Memory corruption vulnerability in WebKit in Apple Safari – CVE-2018-4372
oval:org.secpod.oval:def:48591 CVE-2018-4373 Memory corruption vulnerability in WebKit in Apple Safari – CVE-2018-4373
oval:org.secpod.oval:def:48592 CVE-2018-4375 Memory corruption vulnerability in WebKit in Apple Safari – CVE-2018-4375
oval:org.secpod.oval:def:48593 CVE-2018-4376 Memory corruption vulnerability in WebKit in Apple Safari – CVE-2018-4376
oval:org.secpod.oval:def:48594 CVE-2018-4382 Memory corruption vulnerability in WebKit in Apple Safari – CVE-2018-4382
oval:org.secpod.oval:def:48595 CVE-2018-4386 Memory corruption vulnerability in WebKit in Apple Safari – CVE-2018-4386
oval:org.secpod.oval:def:48596 CVE-2018-4392 Memory corruption vulnerability in WebKit in Apple Safari – CVE-2018-4392
oval:org.secpod.oval:def:48597 CVE-2018-4416 Memory corruption vulnerability in WebKit in Apple Safari – CVE-2018-4416
oval:org.secpod.oval:def:48598 CVE-2018-4378 Memory corruption vulnerability in WebKit in Apple Safari – CVE-2018-4378
oval:org.secpod.oval:def:48599 CVE-2018-4409 Denial of service vulnerability in WebKit in Apple Safari – CVE-2018-4409
oval:org.secpod.oval:def:48600 CVE-2016-1034 Remote code execution vulnerability in Adobe Creative Cloud
oval:org.secpod.oval:def:48602 CVE-2016-4157 Untrusted search path vulnerability in Adobe Creative Cloud via a trojan horse resource in an unspecified directory
oval:org.secpod.oval:def:48603 CVE-2016-4158 Windows search path vulnerability in Adobe Creative Cloud via a trojan horse executable file in the %systemdrive% directory
oval:org.secpod.oval:def:48604 CVE-2016-6935 Unquoted windows search path vulnerability in Adobe Creative Cloud via a trojan horse executable file in the %systemdrive% directory
oval:org.secpod.oval:def:48605 CVE-2018-4873 Unquoted search path vulnerability in Adobe Creative Cloud
oval:org.secpod.oval:def:48606 CVE-2018-4991 Improper certificate validation vulnerability in Adobe Creative Cloud
oval:org.secpod.oval:def:48607 CVE-2018-4992 Improper input validation vulnerability in Adobe Creative Cloud
oval:org.secpod.oval:def:48609 CVE-2016-7866 Memory corruption vulnerability in Adobe Animate – CVE-2016-7866
oval:org.secpod.oval:def:704368 CVE-2018-3136
CVE-2018-3139
CVE-2018-3149
CVE-2018-3150
CVE-2018-3169
CVE-2018-3180
CVE-2018-3183
USN-3804-1
USN-3804-1 — openjdk vulnerabilities
oval:org.secpod.oval:def:704369 CVE-2018-17961
CVE-2018-18073
CVE-2018-18284
USN-3803-1
USN-3803-1 — ghostscript vulnerabilities

Featured Posts

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026

Open TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

CVE Research

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

A chronological look at how a long-running China-nexus espionage cluster evolved from server-side exploitation to a chained Chrome/Windows zero-day kit — and what that shift signals.

Sep 24, 2026