|
247451
|
6.5 |
MEDIUM
Network
|
exiv2 debian canonical
|
exiv2 debian_linux ubuntu_linux
|
Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, a different vulnerability than CVE…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-16336
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247452
|
8.8 |
HIGH
Network
|
libtiff debian
|
libtiff debian_linux
|
newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possi…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-16335
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247453
|
8.8 |
HIGH
Network
|
tendacn
|
ac10_firmware ac9_firmware
|
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN and AC10 V15.03.06.23_CN devices. The mac parameter in a POST request is used directly in a doSystemCmd call, causing OS command injection.
|
CWE-78
OS Command
|
CVE-2018-16334
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247454
|
7.5 |
HIGH
Network
|
tendacn
|
ac18_firmware ac15_firmware ac10_firmware ac9_firmware ac7_firmware
|
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnera…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-16333
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247455
|
8.8 |
HIGH
Network
|
idreamsoft
|
icms
|
An issue was discovered in iCMS 7.0.9. There is an admincp.php?app=article&do=update CSRF vulnerability.
|
CWE-352
Origin Validation Error
|
CVE-2018-16332
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247456
|
8.8 |
HIGH
Network
|
damicms
|
damicms
|
admin.php?s=/Admin/doedit in DamiCMS v6.0.0 allows CSRF to change the administrator account's password.
|
CWE-352
Origin Validation Error
|
CVE-2018-16331
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247457
|
6.1 |
MEDIUM
Network
|
ipandao
|
editor.md
|
Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16330
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247458
|
9.8 |
CRITICAL
Network
|
imagemagick
|
imagemagick
|
In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the GetMagickProperty function in MagickCore/property.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-16329
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247459
|
9.8 |
CRITICAL
Network
|
imagemagick
|
imagemagick
|
In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-16328
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247460
|
4.8 |
MEDIUM
Network
|
intelliants
|
subrion
|
There is Stored XSS in Subrion 4.2.1 via the admin panel URL configuration.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16327
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|