|
246251
|
5.9 |
MEDIUM
Network
|
mercedes-benz
|
comand
|
An issue was discovered in Daimler Mercedes-Benz COMAND 17/13.0 50.12 on Mercedes-Benz C-Class 2018 vehicles. Defining or receiving a specific navigation route might cause the system to freeze and re…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-18070
|
2024-11-21 12:55 |
2018-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246252
|
6.1 |
MEDIUM
Network
|
wpml
|
wpml
|
process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_name_en) in an authenticated theme-local…
|
CWE-79
Cross-site Scripting
|
CVE-2018-18069
|
2024-11-21 12:55 |
2018-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246253
|
7.5 |
HIGH
Network
|
net-snmp netapp
|
net-snmp e-series_santricity_os_controller data_ontap storagegrid_webscale solidfire_element_os hyper_converged_infrastructure cloud_backup
|
snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UD…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-18066
|
2024-11-21 12:55 |
2018-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246254
|
6.5 |
MEDIUM
Network
|
net-snmp debian canonical netapp paloaltonetworks
|
net-snmp debian_linux ubuntu_linux e-series_santricity_os_controller data_ontap storagegrid_webscale solidfire_element_os hyper_converged_infrastructure cloud_backup pan-os
|
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-18065
|
2024-11-21 12:55 |
2018-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246255
|
6.5 |
MEDIUM
Network
|
cairographics
|
cairo
|
cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-18064
|
2024-11-21 12:55 |
2018-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246256
|
4.4 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumpt…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-17977
|
2024-11-21 12:55 |
2018-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246257
|
5.3 |
MEDIUM
Network
|
we-con
|
pi_studio pi_studio_hmi
|
In WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior when parsing project files, the XMLParser that ships with Wecon PIStudio is vulnerable to …
|
CWE-611
XXE
|
CVE-2018-17889
|
2024-11-21 12:55 |
2018-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246258
|
6.5 |
MEDIUM
Network
|
imagemagick debian
|
imagemagick debian_linux
|
In ImageMagick 7.0.8-13 Q16, there is a heap-based buffer over-read in the EncodeImage function of coders/pict.c, which allows attackers to cause a denial of service via a crafted SVG image file.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-18025
|
2024-11-21 12:55 |
2018-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246259
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.8-13 Q16, there is an infinite loop in the ReadBMPImage function of the coders/bmp.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a cra…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-18024
|
2024-11-21 12:55 |
2018-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246260
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.8-13 Q16, there is a heap-based buffer over-read in the SVGStripString function of coders/svg.c, which allows attackers to cause a denial of service via a crafted SVG image file.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-18023
|
2024-11-21 12:55 |
2018-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|