|
246731
|
5.4 |
MEDIUM
Network
|
domainmod
|
domainmod
|
DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_first_name parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11558
|
2024-11-21 12:43 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246732
|
6.1 |
MEDIUM
Network
|
yiban
|
easy_class_education_platform
|
YIBAN Easy class education platform 2.0 has XSS via the articlelist.php k parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11557
|
2024-11-21 12:43 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246733
|
7.8 |
HIGH
Local
|
littlecms
|
little_cms
|
tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11556
|
2024-11-21 12:43 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246734
|
7.8 |
HIGH
Local
|
littlecms
|
little_cms
|
tificc in Little CMS 2.9 has an out-of-bounds write in the PrecalculatedXFORM function in cmsxform.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerabilit…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11555
|
2024-11-21 12:43 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246735
|
5.4 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a f…
|
CWE-79
Cross-site Scripting
|
CVE-2018-11549
|
2024-11-21 12:43 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246736
|
7.5 |
HIGH
Network
|
block
|
eos
|
An issue was discovered in EOS.IO DAWN 4.2. plugins/net_plugin/net_plugin.cpp does not limit the number of P2P connections from the same source IP address.
|
CWE-20
Improper Input Validation
|
CVE-2018-11548
|
2024-11-21 12:43 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246737
|
9.8 |
CRITICAL
Network
|
md4c_project
|
md4c
|
md_is_link_reference_definition_helper in md4c 0.2.5 has a heap-based buffer over-read because md_is_link_label mishandles loop termination.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11547
|
2024-11-21 12:43 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246738
|
9.8 |
CRITICAL
Network
|
md4c_project
|
md4c
|
md4c 0.2.5 has a heap-based buffer over-read because md_is_named_entity_contents has an off-by-one error.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11546
|
2024-11-21 12:43 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246739
|
9.8 |
CRITICAL
Network
|
md4c_project
|
md4c
|
md4c 0.2.5 has a heap-based buffer overflow in md_merge_lines because md_is_link_label mishandles the case of a link label composed solely of backslash escapes.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11545
|
2024-11-21 12:43 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246740
|
9.8 |
CRITICAL
Network
|
theolivetree
|
ftp_server
|
The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-11544
|
2024-11-21 12:43 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|