|
246561
|
5.3 |
MEDIUM
Network
|
digium debian
|
asterisk certified_asterisk debian_linux
|
An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert before 13.18-cert4 and 13.21-cert before 13.21-cert2.…
|
CWE-200
Information Exposure
|
CVE-2018-12227
|
2024-11-21 12:44 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246562
|
7.8 |
HIGH
Local
|
md4c_project
|
md4c
|
md_build_attribute in md4c.c in md4c 0.2.6 allows remote attackers to cause a denial of service (Segmentation fault and application crash) or possibly have unspecified other impact via a crafted file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-12112
|
2024-11-21 12:44 |
2018-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246563
|
6.1 |
MEDIUM
Network
|
canon
|
efi_printme
|
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /wt3/mydocs.php URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12111
|
2024-11-21 12:44 |
2018-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246564
|
7.2 |
HIGH
Network
|
portfoliocms_project
|
portfoliocms
|
portfolioCMS 1.0.5 has SQL Injection via the admin/portfolio.php preview parameter.
|
CWE-89
SQL Injection
|
CVE-2018-12110
|
2024-11-21 12:44 |
2018-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246565
|
7.8 |
HIGH
Local
|
flif
|
flif
|
An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The TransformPaletteC<FileIO>::process function in transform/palette_C.hpp allows remote attackers to cause a denial of service (heap…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12109
|
2024-11-21 12:44 |
2018-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246566
|
5.5 |
MEDIUM
Local
|
dropbox
|
lepton
|
An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attackers to cause a denial of service (SIGFPE and application crash) via a malformed …
|
CWE-20
Improper Input Validation
|
CVE-2018-12108
|
2024-11-21 12:44 |
2018-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246567
|
5.5 |
MEDIUM
Local
|
md4c_project
|
md4c
|
md4c 0.2.6 has a NULL pointer dereference in the function md_process_line in md4c.c, related to ctx->current_block.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-12102
|
2024-11-21 12:44 |
2018-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246568
|
4.8 |
MEDIUM
Network
|
sonatype
|
nexus_repository_manager
|
Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12100
|
2024-11-21 12:44 |
2018-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246569
|
6.1 |
MEDIUM
Network
|
grafana netapp
|
grafana active_iq_performance_analytics_services storagegrid_webscale_nas_bridge
|
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12099
|
2024-11-21 12:44 |
2018-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246570
|
5.4 |
MEDIUM
Network
|
oecms_project
|
oecms
|
A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod parameter of info.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12095
|
2024-11-21 12:44 |
2018-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|