|
248031
|
9.8 |
CRITICAL
Network
|
cobblerd
|
cobbler
|
Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vul…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-1000226
|
2024-11-21 12:39 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248032
|
6.1 |
MEDIUM
Network
|
cobblerd
|
cobbler
|
Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Cross Site Scripting (XSS) v…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000225
|
2024-11-21 12:39 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248033
|
7.5 |
HIGH
Network
|
godotengine
|
godot
|
Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing padding initialization v…
|
CWE-190 CWE-131 CWE-681 CWE-908 CWE-909
Integer Overflow or Wraparound Incorrect Calculation of Buffer Size Incorrect Conversion between Numeric Types Use of Uninitialized Resource Missing Initialization of Resource
|
CVE-2018-1000224
|
2024-11-21 12:39 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248034
|
8.8 |
HIGH
Network
|
surina
|
soundtouch
|
soundtouch version up to and including 2.0.0 contains a Buffer Overflow vulnerability in SoundStretch/WavFile.cpp:WavInFile::readHeaderBlock() that can result in arbitrary code execution. This attack…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-1000223
|
2024-11-21 12:39 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248035
|
8.8 |
HIGH
Network
|
libgd canonical debian
|
libgd ubuntu_linux debian_linux
|
Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This attack appear to be exploitable via Specially Crafted …
|
CWE-415
Double Free
|
CVE-2018-1000222
|
2024-11-21 12:39 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248036
|
9.8 |
CRITICAL
Network
|
pkgconf
|
pkgconf
|
pkgconf version 1.5.0 to 1.5.2 contains a Buffer Overflow vulnerability in dequote() that can result in dequote() function returns 1-byte allocation if initial length is 0, leading to buffer overflow…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-1000221
|
2024-11-21 12:39 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248037
|
5.4 |
MEDIUM
Network
|
open-emr
|
openemr
|
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'scan' parameter in line #41 of interface/fax/fax_view.php that can result in The vulnerability could allow remote …
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000219
|
2024-11-21 12:39 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248038
|
5.4 |
MEDIUM
Network
|
open-emr
|
openemr
|
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'file' parameter in line #43 of interface/fax/fax_view.php that can result in The vulnerability could allow remote …
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000218
|
2024-11-21 12:39 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248039
|
9.8 |
CRITICAL
Network
|
cjson_project
|
cjson
|
Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corruption of data or even RCE. This attack appear to …
|
CWE-416
Use After Free
|
CVE-2018-1000217
|
2024-11-21 12:39 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248040
|
8.8 |
HIGH
Network
|
cjson_project
|
cjson
|
Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploitable via Attacker …
|
CWE-415
Double Free
|
CVE-2018-1000216
|
2024-11-21 12:39 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|