|
246731
|
6.5 |
MEDIUM
Network
|
nagios
|
nagios_xi
|
An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginning with index.php?xiwindow=./ and config/?xiwindo…
|
CWE-22
Path Traversal
|
CVE-2018-10553
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246732
|
8.8 |
HIGH
Network
|
php canonical debian netapp
|
php ubuntu_linux debian_linux storage_automation_store
|
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. exif_read_data in ext/exif/exif.c has an out-of-bounds read for crafted JPEG data becau…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-10549
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246733
|
7.5 |
HIGH
Network
|
php canonical debian netapp
|
php ubuntu_linux debian_linux storage_automation_store
|
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. ext/ldap/ldap.c allows remote LDAP servers to cause a denial of service (NULL pointer d…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-10548
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246734
|
6.1 |
MEDIUM
Network
|
php canonical debian netapp
|
php ubuntu_linux debian_linux storage_automation_store
|
An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. There is Reflected XSS on the PHAR 403 and 404 error pages vi…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10547
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246735
|
7.5 |
HIGH
Network
|
php canonical debian netapp
|
php ubuntu_linux debian_linux storage_automation_store
|
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/iconv.c because the iconv stream filter does not r…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-10546
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246736
|
4.7 |
MEDIUM
Local
|
php canonical debian netapp
|
php ubuntu_linux debian_linux storage_automation_store
|
An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c…
|
CWE-200
Information Exposure
|
CVE-2018-10545
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246737
|
5.5 |
MEDIUM
Local
|
wavpack debian
|
wavpack debian_linux
|
An issue was discovered in WavPack 5.1.0 and earlier for W64 input. Out-of-bounds writes can occur because ParseWave64HeaderConfig in wave64.c does not validate the sizes of unknown chunks before att…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-10540
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246738
|
5.5 |
MEDIUM
Local
|
wavpack debian
|
wavpack debian_linux
|
An issue was discovered in WavPack 5.1.0 and earlier for DSDiff input. Out-of-bounds writes can occur because ParseDsdiffHeaderConfig in dsdiff.c does not validate the sizes of unknown chunks before …
|
CWE-787
Out-of-bounds Write
|
CVE-2018-10539
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246739
|
5.5 |
MEDIUM
Local
|
wavpack debian
|
wavpack debian_linux
|
An issue was discovered in WavPack 5.1.0 and earlier for WAV input. Out-of-bounds writes can occur because ParseRiffHeaderConfig in riff.c does not validate the sizes of unknown chunks before attempt…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-10538
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246740
|
7.8 |
HIGH
Local
|
wavpack debian
|
wavpack debian_linux
|
An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerability that allows writing to memory because ParseWave64HeaderConfig in wave64.c does not reject multi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10537
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|