|
246301
|
8.8 |
HIGH
Network
|
libconfuse_project debian
|
libconfuse debian_linux
|
trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-14447
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246302
|
8.8 |
HIGH
Network
|
techsmith
|
mp4v2
|
MP4Integer32Property::Read in atom_avcC.cpp in MP4v2 2.1.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other i…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-14446
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246303
|
6.5 |
MEDIUM
Network
|
axiosys
|
bento4
|
In Bento4 v1.5.1-624, AP4_File::ParseStream in Ap4File.cpp allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 file.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-14445
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246304
|
7.5 |
HIGH
Network
|
libdxfrw_project
|
libdxfrw
|
libdxfrw 0.6.3 has an Integer Overflow in dwgCompressor::decompress18 in dwgutil.cpp, leading to an out-of-bounds read and application crash.
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2018-14444
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246305
|
6.5 |
MEDIUM
Network
|
gnu
|
libredwg
|
get_first_owned_object in dwg.c in GNU LibreDWG 0.5.1036 allows remote attackers to cause a denial of service (SEGV).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14443
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246306
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
phantompdf foxit_reader
|
Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.
|
CWE-416
Use After Free
|
CVE-2018-14442
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246307
|
6.1 |
MEDIUM
Network
|
sanscms
|
sanscms
|
blog/index.php in SansCMS 0.7 has XSS via the q parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14422
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246308
|
8.8 |
HIGH
Network
|
seacms
|
seacms
|
SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admin_video.php). The code is executed by visiting /de…
|
CWE-352 CWE-94
Origin Validation Error Code Injection
|
CVE-2018-14421
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246309
|
8.8 |
HIGH
Network
|
metinfo
|
metinfo
|
MetInfo 6.0.0 allows a CSRF attack to add a user account via a doaddsave action to admin/index.php, as demonstrated by an admin/index.php?anyid=47&n=admin&c=admin_admin&a=doaddsave URI.
|
CWE-352
Origin Validation Error
|
CVE-2018-14420
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246310
|
4.8 |
MEDIUM
Network
|
metinfo
|
metinfo
|
MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14419
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|