|
247501
|
7.8 |
HIGH
Local
|
vcftools_project
|
vcftools
|
The header::add_FORMAT_descriptor function in header.cpp in VCFtools 0.1.15 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a craft…
|
CWE-416
Use After Free
|
CVE-2018-11130
|
2024-11-21 12:42 |
2018-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247502
|
7.8 |
HIGH
Local
|
vcftools_project
|
vcftools
|
The header::add_INFO_descriptor function in header.cpp in VCFtools 0.1.15 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted…
|
CWE-416
Use After Free
|
CVE-2018-11129
|
2024-11-21 12:42 |
2018-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247503
|
7.8 |
HIGH
Local
|
pdfparser
|
pdfparser
|
The ObjReader::ReadObj() function in ObjReader.cpp in vincent0629 PDFParser allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly execute arbitrary code via a…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11128
|
2024-11-21 12:42 |
2018-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247504
|
6.1 |
MEDIUM
Network
|
signal
|
signal-desktop
|
Open Whisper Signal (aka Signal-Desktop) through 1.10.1 allows XSS via a resource location specified in an attribute of a SCRIPT, IFRAME, or IMG element, leading to JavaScript execution after a reply…
|
CWE-79
Cross-site Scripting
|
CVE-2018-11101
|
2024-11-21 12:42 |
2018-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247505
|
5.5 |
MEDIUM
Local
|
vcftools_project
|
vcftools
|
The header::add_INFO_descriptor function in header.cpp in VCFtools 0.1.15 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted vcf file.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11099
|
2024-11-21 12:42 |
2018-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247506
|
6.1 |
MEDIUM
Network
|
ilias
|
ilias
|
Services/COPage/classes/class.ilPCSourceCode.php in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11120
|
2024-11-21 12:42 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247507
|
6.1 |
MEDIUM
Network
|
ilias
|
ilias
|
ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 redirects a logged-in user to a third-party site via the return_to_url parameter.
|
CWE-601
Open Redirect
|
CVE-2018-11119
|
2024-11-21 12:42 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247508
|
6.1 |
MEDIUM
Network
|
ilias
|
ilias
|
The RSS subsystem in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS via a URI to Services/Feeds/classes/class.ilExternalFeedItem.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11118
|
2024-11-21 12:42 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247509
|
6.1 |
MEDIUM
Network
|
ilias
|
ilias
|
Services/Feeds/classes/class.ilExternalFeedItem.php in ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 has XSS via a link attribute.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11117
|
2024-11-21 12:42 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247510
|
8.8 |
HIGH
Network
|
jbig2enc_project
|
jbig2enc
|
jbig2_add_page in jbig2enc.cc in libjbig2enc.a in jbig2enc 0.29 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted file.
|
CWE-416
Use After Free
|
CVE-2018-11230
|
2024-11-21 12:42 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|