|
245911
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Incorrect object lifetime calculations in GPU code in Google Chrome prior to 70.0.3538.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2018-17479
|
2024-11-21 12:54 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245912
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Incorrect array position calculations in V8 in Google Chrome prior to 70.0.3538.102 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.
|
CWE-129
Improper Validation of Array Index
|
CVE-2018-17478
|
2024-11-21 12:54 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245913
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient data validation in filesystem URIs in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
|
CWE-20
Improper Input Validation
|
CVE-2018-17460
|
2024-11-21 12:54 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245914
|
9.8 |
CRITICAL
Network
|
ranksol
|
twilio_web_to_fax_machine_system
|
SQL Injection exists in Twilio WEB To Fax Machine System 1.0 via the email or password parameter to login_check.php, or the id parameter to add_email.php or edit_content.php.
|
CWE-89
SQL Injection
|
CVE-2018-17388
|
2024-11-21 12:54 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245915
|
8.8 |
HIGH
Network
|
ranksol
|
nimble_professional
|
CSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account.
|
CWE-352
Origin Validation Error
|
CVE-2018-17387
|
2024-11-21 12:54 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245916
|
9.8 |
CRITICAL
Network
|
thephpfactory
|
micro_deal_factory
|
SQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.
|
CWE-89
SQL Injection
|
CVE-2018-17386
|
2024-11-21 12:54 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245917
|
9.8 |
CRITICAL
Network
|
thephpfactory
|
dutch_auction_factory
|
SQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17381
|
2024-11-21 12:54 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245918
|
9.8 |
CRITICAL
Network
|
thephpfactory
|
auction_factory
|
SQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17374
|
2024-11-21 12:54 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245919
|
4.8 |
MEDIUM
Network
|
e107
|
e107
|
An issue was discovered in e107 v2.1.9. There is a XSS attack on e107_admin/comment.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17423
|
2024-11-21 12:54 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245920
|
9.8 |
CRITICAL
Network
|
jimtawl_project
|
jimtawl
|
SQL Injection exists in the Jimtawl 2.2.7 component for Joomla! via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17399
|
2024-11-21 12:54 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|