|
247811
|
8.8 |
HIGH
Network
|
libarchive debian canonical redhat opensuse fedoraproject
|
libarchive debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server leap fedora
|
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_f…
|
CWE-416
Use After Free
|
CVE-2018-1000878
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247812
|
8.8 |
HIGH
Network
|
libarchive debian canonical redhat fedoraproject
|
libarchive debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server fedora
|
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_form…
|
CWE-415
Double Free
|
CVE-2018-1000877
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247813
|
7.8 |
HIGH
Local
|
gnu canonical redhat
|
binutils ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger he…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2018-1000876
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247814
|
9.8 |
CRITICAL
Network
|
berkeley
|
berkeley_open_infrastructure_for_network_computing
|
Berkeley Open Infrastructure for Network Computing BOINC Server and Website Code version 0.9-1.0.2 contains a CWE-302: Authentication Bypass by Assumed-Immutable Data vulnerability in Website Terms o…
|
CWE-287
Improper Authentication
|
CVE-2018-1000875
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247815
|
6.5 |
MEDIUM
Network
|
pykmip_project
|
pykmip
|
OpenKMIP PyKMIP version All versions before 0.8.0 contains a CWE 399: Resource Management Errors (similar issue to CVE-2015-5262) vulnerability in PyKMIP server that can result in DOS: the server can…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-1000872
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247816
|
9.8 |
CRITICAL
Network
|
digitaldruid
|
hoteldruid
|
HotelDruid HotelDruid 2.3.0 version 2.3.0 and earlier contains a SQL Injection vulnerability in "id_utente_mod" parameter in gestione_utenti.php file that can result in An attacker can dump all the d…
|
CWE-89
SQL Injection
|
CVE-2018-1000871
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247817
|
6.1 |
MEDIUM
Network
|
cebe
|
markdown
|
PHP cebe markdown parser version 1.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in all distributed parsers allowing a malicious crafted script to be executed that can result in…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000874
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247818
|
6.5 |
MEDIUM
Network
|
fasterxml oracle netapp
|
jackson-modules-java8 database_server clusterware global_lifecycle_management_opatch nosql_database active_iq_unified_manager
|
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to b…
|
CWE-20
Improper Input Validation
|
CVE-2018-1000873
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247819
|
5.4 |
MEDIUM
Network
|
phpipam
|
phpipam
|
PHPipam version 1.3.2 and earlier contains a CWE-79 vulnerability in /app/admin/users/print-user.php that can result in Execute code in the victims browser. This attack appear to be exploitable via A…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000870
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247820
|
9.8 |
CRITICAL
Network
|
phpipam
|
phpipam
|
phpIPAM version 1.3.2 contains a CWE-89 vulnerability in /app/admin/nat/item-add-submit.php that can result in SQL Injection.. This attack appear to be exploitable via Rough user, exploiting the vuln…
|
CWE-89
SQL Injection
|
CVE-2018-1000869
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|