|
246411
|
6.1 |
MEDIUM
Network
|
instantcms
|
instantcms
|
InstantCMS 2.10.1 has /redirect?url= XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14382
|
2024-11-21 12:48 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246412
|
6.1 |
MEDIUM
Network
|
pagekit
|
pagekit
|
Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.
|
CWE-601
Open Redirect
|
CVE-2018-14381
|
2024-11-21 12:48 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246413
|
6.1 |
MEDIUM
Network
|
graylog
|
graylog
|
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14380
|
2024-11-21 12:48 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246414
|
7.5 |
HIGH
Network
|
eclipse
|
mojarra
|
The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote attacker can download configuration files or Ja…
|
CWE-22
Path Traversal
|
CVE-2018-14371
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246415
|
8.8 |
HIGH
Network
|
techsmith
|
mp4v2
|
MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case where MP4DataAtom is required, which allows remote attackers to cause a denial of service (…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2018-14379
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246416
|
7.5 |
HIGH
Network
|
debian neomutt
|
debian_linux neomutt
|
An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.
|
CWE-22
Path Traversal
|
CVE-2018-14363
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246417
|
9.8 |
CRITICAL
Network
|
mutt neomutt canonical debian redhat
|
mutt neomutt ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_server_tus
|
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' c…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14362
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246418
|
9.8 |
CRITICAL
Network
|
debian neomutt
|
debian_linux neomutt
|
An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.
|
CWE-20
Improper Input Validation
|
CVE-2018-14361
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246419
|
9.8 |
CRITICAL
Network
|
debian neomutt
|
debian_linux neomutt
|
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-14360
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246420
|
9.8 |
CRITICAL
Network
|
mutt neomutt canonical debian
|
mutt neomutt ubuntu_linux debian_linux
|
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data.
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-14359
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|