|
248391
|
5.5 |
MEDIUM
Local
|
clamav debian canonical
|
clamav debian_linux ubuntu_linux
|
ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit cha…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-1000085
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248392
|
5.4 |
MEDIUM
Network
|
wolfcms
|
wolf_cms
|
WOlfCMS WolfCMS version version 0.8.3.1 contains a Stored Cross-Site Scripting vulnerability in Layout Name (from Layout tab) that can result in low privilege user can steal the cookie of admin user …
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000084
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248393
|
5.3 |
MEDIUM
Network
|
ajenti
|
ajenti
|
Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via…
|
CWE-22
Path Traversal
|
CVE-2018-1000083
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248394
|
8.8 |
HIGH
Network
|
ajenti
|
ajenti
|
Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the serve…
|
CWE-352
Origin Validation Error
|
CVE-2018-1000082
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248395
|
7.5 |
HIGH
Network
|
ajenti
|
ajenti
|
Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can…
|
CWE-20
Improper Input Validation
|
CVE-2018-1000081
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248396
|
6.5 |
MEDIUM
Network
|
ajenti
|
ajenti
|
Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-1000080
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248397
|
5.5 |
MEDIUM
Local
|
rubygems
|
rubygems
|
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains…
|
CWE-22
Path Traversal
|
CVE-2018-1000079
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248398
|
6.1 |
MEDIUM
Network
|
rubygems debian
|
rubygems debian_linux
|
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000078
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248399
|
5.3 |
MEDIUM
Network
|
rubygems debian
|
rubygems debian_linux
|
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains…
|
CWE-20
Improper Input Validation
|
CVE-2018-1000077
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248400
|
9.8 |
CRITICAL
Network
|
rubygems debian
|
rubygems debian_linux
|
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2018-1000076
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|