|
247101
|
7.5 |
HIGH
Network
|
tinyexr_project
|
tinyexr
|
tinyexr 0.9.5 has a memory leak in ParseEXRHeaderFromMemory in tinyexr.h.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-12093
|
2024-11-21 12:44 |
2018-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247102
|
9.8 |
CRITICAL
Network
|
tinyexr_project
|
tinyexr
|
tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-12092
|
2024-11-21 12:44 |
2018-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247103
|
6.1 |
MEDIUM
Network
|
lamsfoundation
|
lams
|
There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introduce arbitrary JavaScript via manipulation of an unsanitized GET parameter durin…
|
CWE-79
Cross-site Scripting
|
CVE-2018-12090
|
2024-11-21 12:44 |
2018-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247104
|
7.5 |
HIGH
Network
|
octopus
|
octopus_server
|
In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cluster, when the Service Fabric Cluster target is configured in Azure Active Dir…
|
CWE-200
Information Exposure
|
CVE-2018-12089
|
2024-11-21 12:44 |
2018-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247105
|
7.5 |
HIGH
Network
|
futurxe
|
futurxe
|
The transferFrom function of a smart contract implementation for FuturXE (FXE), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized transfer of digital assets because of a logic e…
|
CWE-20 CWE-191
Improper Input Validation Integer Underflow (Wrap or Wraparound)
|
CVE-2018-12025
|
2024-11-21 12:44 |
2018-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247106
|
7.5 |
HIGH
Network
|
s3ql_project
|
s3ql
|
S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versions of the filesystem metadata database as up-to-da…
|
CWE-20
Improper Input Validation
|
CVE-2018-12088
|
2024-11-21 12:44 |
2018-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247107
|
8.8 |
HIGH
Network
|
liblouis canonical opensuse
|
liblouis ubuntu_linux leap
|
Liblouis 3.6.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12085
|
2024-11-21 12:44 |
2018-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247108
|
7.5 |
HIGH
Network
|
redhat canonical debian gnupg
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_server_tus enterprise_linux_server_aus ubuntu_linux deb…
|
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 t…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2018-12020
|
2024-11-21 12:44 |
2018-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247109
|
5.5 |
MEDIUM
Local
|
bird_project
|
bird
|
BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon crash) via BGP mask expressions in birdc.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-12066
|
2024-11-21 12:44 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247110
|
9.8 |
CRITICAL
Network
|
creatiwity
|
witycms
|
A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP files (execute PHP code) or read non-PHP files by replacing …
|
CWE-20
Improper Input Validation
|
CVE-2018-12065
|
2024-11-21 12:44 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|