|
247381
|
9.1 |
CRITICAL
Network
|
seacms
|
seacms
|
An issue was discovered in SeaCMS 6.61. adm1n/admin_reslib.php has SSRF via the url parameter.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-16444
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247382
|
8.8 |
HIGH
Network
|
hdfgroup
|
hdf5
|
An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in H5L_extern_query at H5Lexternal.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-16438
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247383
|
5.5 |
MEDIUM
Local
|
littlecms canonical redhat debian
|
little_cms_color_engine ubuntu_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux
|
Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafte…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2018-16435
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247384
|
9.8 |
CRITICAL
Network
|
bluecms_project
|
bluecms
|
BlueCMS 1.6 allows SQL Injection via the user_name parameter to uploads/user.php?act=index_login.
|
CWE-89
SQL Injection
|
CVE-2018-16432
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247385
|
8.8 |
HIGH
Network
|
yfcmf
|
yfcmf
|
admin/admin/adminsave.html in YFCMF v3.0 allows CSRF to add an administrator account.
|
CWE-352
Origin Validation Error
|
CVE-2018-16431
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247386
|
8.8 |
HIGH
Network
|
gnu debian
|
libextractor debian_linux
|
GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-16430
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247387
|
7.5 |
HIGH
Network
|
gnome canonical
|
glib ubuntu_linux
|
GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().
|
CWE-125
Out-of-bounds Read
|
CVE-2018-16429
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247388
|
9.8 |
CRITICAL
Network
|
gnome canonical
|
glib ubuntu_linux
|
In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-16428
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247389
|
4.3 |
MEDIUM
Physics
|
opensc_project
|
opensc
|
Various out of bounds reads when handling responses in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to potentially crash the opensc library using programs.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-16427
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247390
|
4.3 |
MEDIUM
Physics
|
opensc_project
|
opensc
|
Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcard…
|
CWE-674
Uncontrolled Recursion
|
CVE-2018-16426
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|