|
246231
|
7.2 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomla…
|
NVD-CWE-noinfo
|
CVE-2018-17856
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246232
|
8.8 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in the registration process, he can activate himself.
|
CWE-269
Improper Privilege Management
|
CVE-2018-17855
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246233
|
9.8 |
CRITICAL
Network
|
linuxsampler
|
libgig
|
An issue was discovered in libgig 4.1.0. There is an operator new[] failure (due to a big pSampleLoops heap request) in DLS::Sampler::Sampler in DLS.cpp.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-18197
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246234
|
8.8 |
HIGH
Network
|
linuxsampler
|
libgig
|
An issue was discovered in libgig 4.1.0. There is a heap-based buffer over-read in RIFF::List::GetListTypeString in RIFF.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-18196
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246235
|
6.5 |
MEDIUM
Network
|
linuxsampler
|
libgig
|
An issue was discovered in libgig 4.1.0. There is an FPE (divide-by-zero error) in DLS::Sample::Sample in DLS.cpp.
|
CWE-369
Divide By Zero
|
CVE-2018-18195
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246236
|
8.8 |
HIGH
Network
|
linuxsampler
|
libgig
|
An issue was discovered in libgig 4.1.0. There is a heap-based buffer over-read in DLS::Region::GetSample() in DLS.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-18194
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246237
|
8.8 |
HIGH
Network
|
linuxsampler
|
libgig
|
An issue was discovered in libgig 4.1.0. There is operator new[] failure (due to a big pWavePoolTable heap request) in DLS::File::File in DLS.cpp.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-18193
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246238
|
6.5 |
MEDIUM
Network
|
linuxsampler
|
libgig
|
An issue was discovered in libgig 4.1.0. There is a NULL pointer dereference in the function DLS::File::GetFirstSample() in DLS.cpp.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-18192
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246239
|
8.8 |
HIGH
Network
|
finecms
|
finecms
|
Cross-site request forgery (CSRF) vulnerability in /admin.php?c=member&m=edit&uid=1 in dayrui FineCms 5.4 allows remote attackers to change the administrator's password.
|
CWE-352
Origin Validation Error
|
CVE-2018-18191
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246240
|
5.5 |
MEDIUM
Local
|
gopro
|
gpmf-parser
|
An issue was discovered in GoPro gpmf-parser before 1.2.1. There is a divide-by-zero error in GPMF_ScaledData in GPMF_parser.c.
|
CWE-369
Divide By Zero
|
CVE-2018-18190
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|