|
247541
|
5.5 |
MEDIUM
Local
|
faststone
|
image_viewer
|
FastStone Image Viewer 6.5 has an Exception Handler Chain Corrupted issue starting at image00400000+0x00000000003ef68a via a crafted image file.
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2018-15815
|
2024-11-21 12:51 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247542
|
5.5 |
MEDIUM
Local
|
faststone
|
image_viewer
|
FastStone Image Viewer 6.5 has a User Mode Write AV starting at image00400000+0x00000000001cb509 via a crafted image file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15814
|
2024-11-21 12:51 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247543
|
5.5 |
MEDIUM
Local
|
faststone
|
image_viewer
|
FastStone Image Viewer 6.5 has a User Mode Write AV starting at image00400000+0x00000000000e1237 via a crafted image file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15813
|
2024-11-21 12:51 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247544
|
6.1 |
MEDIUM
Network
|
sir
|
gnuboard
|
Cross-Site Scripting (XSS) vulnerability in point_list.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML via the popup title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15583
|
2024-11-21 12:51 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247545
|
7.2 |
HIGH
Network
|
solarwinds
|
serv-u_ftp_server
|
SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.
|
NVD-CWE-noinfo
|
CVE-2018-15906
|
2024-11-21 12:51 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247546
|
7.5 |
HIGH
Network
|
reputeinfosystems
|
repute_arforms
|
An issue was discovered in Repute ARForms 3.5.1 and prior. An attacker is able to delete any file on the server with web server privileges by sending a malicious request to admin-ajax.php.
|
CWE-20
Improper Input Validation
|
CVE-2018-15818
|
2024-11-21 12:51 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247547
|
3.8 |
LOW
Local
|
hp
|
synaptics_touchpad_driver
|
SynTP.sys in Synaptics Touchpad drivers before 2018-06-06 allows local users to obtain sensitive information about freed kernel addresses.
|
CWE-200
Information Exposure
|
CVE-2018-15532
|
2024-11-21 12:51 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247548
|
8.0 |
HIGH
Adjacent
|
dell
|
wyse_thinlinux
|
The Dell Wyse Password Encoder in ThinLinux2 versions prior to 2.1.0.01 contain a Hard-coded Cryptographic Key vulnerability. An unauthenticated remote attacker could reverse engineer the cryptograph…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-15781
|
2024-11-21 12:51 |
2019-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247549
|
7.5 |
HIGH
Network
|
freron
|
mailmate
|
MailMate before 1.11.3 mishandles a suspicious HTML/MIME structure in a signed/encrypted email.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2018-15588
|
2024-11-21 12:51 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247550
|
6.5 |
MEDIUM
Network
|
gnome debian
|
evolution debian_linux
|
GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated a…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2018-15587
|
2024-11-21 12:51 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|