|
247511
|
8.8 |
HIGH
Network
|
libming
|
libming
|
The getString function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-11226
|
2024-11-21 12:42 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247512
|
8.8 |
HIGH
Network
|
libming
|
libming
|
The dcputs function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of se…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-11225
|
2024-11-21 12:42 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247513
|
6.5 |
MEDIUM
Network
|
libav
|
libav
|
An issue was discovered in Libav 12.3. A read access violation in the in_table_init16 function in libavcodec/aacsbr.c allows remote attackers to cause a denial of service (application crash), as demo…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-11224
|
2024-11-21 12:42 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247514
|
6.5 |
MEDIUM
Network
|
ijg debian canonical
|
libjpeg debian_linux ubuntu_linux
|
An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.
|
NVD-CWE-noinfo
|
CVE-2018-11214
|
2024-11-21 12:42 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247515
|
6.5 |
MEDIUM
Network
|
ijg debian canonical
|
libjpeg debian_linux ubuntu_linux
|
An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.
|
NVD-CWE-noinfo
|
CVE-2018-11213
|
2024-11-21 12:42 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247516
|
6.5 |
MEDIUM
Network
|
ijg debian canonical netapp oracle redhat opensuse
|
libjpeg debian_linux ubuntu_linux oncommand_unified_manager oncommand_workflow_automation snapmanager jdk jre enterprise_linux_desktop enterprise_linux_workstation enter…
|
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
|
CWE-369
Divide By Zero
|
CVE-2018-11212
|
2024-11-21 12:42 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247517
|
9.8 |
CRITICAL
Network
|
tinyxml2_project
|
tinyxml2
|
TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so. NOTE: The tinyxml2 developers have determined that the reported overflow is due to improper use …
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11210
|
2024-11-21 12:42 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247518
|
7.2 |
HIGH
Network
|
zblogcn
|
z-blogphp
|
An issue was discovered in Z-BlogPHP 2.0.0. zb_system/cmd.php?act=verify relies on MD5 for the password parameter, which might make it easier for attackers to bypass intended access restrictions via …
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2018-11209
|
2024-11-21 12:42 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247519
|
4.8 |
MEDIUM
Network
|
zblogcn
|
z-blogphp
|
An issue was discovered in Z-BlogPHP 2.0.0. There is a persistent XSS that allows remote attackers to inject arbitrary web script or HTML into background web site settings via the "copyright informat…
|
CWE-79
Cross-site Scripting
|
CVE-2018-11208
|
2024-11-21 12:42 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247520
|
6.5 |
MEDIUM
Network
|
hdfgroup
|
hdf5
|
A division by zero was discovered in H5D__chunk_init in H5Dchunk.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.
|
CWE-369
Divide By Zero
|
CVE-2018-11207
|
2024-11-21 12:42 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|