|
246701
|
5.5 |
MEDIUM
Local
|
espruino
|
espruino
|
Espruino before 1.98 allows attackers to cause a denial of service (application crash) with a user crafted input file via a NULL pointer dereference during syntax parsing. This was addressed by addin…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-11591
|
2024-11-21 12:43 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246702
|
5.5 |
MEDIUM
Local
|
espruino
|
espruino
|
Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via an integer overflow during syntax parsing. This was addressed by fixing stack…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-11590
|
2024-11-21 12:43 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246703
|
6.1 |
MEDIUM
Network
|
seacms
|
seacms
|
SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11583
|
2024-11-21 12:43 |
2018-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246704
|
5.4 |
MEDIUM
Network
|
multidots
|
mass_pages\/posts_creator
|
An issue was discovered in mass-pages-posts-creator.php in the MULTIDOTS Mass Pages/Posts Creator plugin 1.2.2 for WordPress. Any logged in user can launch Mass Pages/Posts creation with custom conte…
|
CWE-79
Cross-site Scripting
|
CVE-2018-11580
|
2024-11-21 12:43 |
2018-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246705
|
5.3 |
MEDIUM
Network
|
multidots
|
woocommerce_category_banner_management
|
class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Change Vulnerability, related to certain wp_ajax_nop…
|
CWE-287
Improper Authentication
|
CVE-2018-11579
|
2024-11-21 12:43 |
2018-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246706
|
6.5 |
MEDIUM
Network
|
miniupnp_project
|
ngiflib
|
GifIndexToTrueColor in ngiflib.c in MiniUPnP ngiflib 0.4 has a Segmentation fault.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-11578
|
2024-11-21 12:43 |
2018-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246707
|
8.8 |
HIGH
Network
|
liblouis canonical opensuse
|
liblouis ubuntu_linux leap
|
Liblouis 3.5.0 has a Segmentation fault in lou_logPrint in logging.c.
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-11577
|
2024-11-21 12:43 |
2018-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246708
|
9.8 |
CRITICAL
Network
|
miniupnp_project
|
ngiflib
|
ngiflib.c in MiniUPnP ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11576
|
2024-11-21 12:43 |
2018-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246709
|
9.8 |
CRITICAL
Network
|
miniupnp_project
|
ngiflib
|
ngiflib.c in MiniUPnP ngiflib 0.4 has a stack-based buffer overflow in DecodeGifImg.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11575
|
2024-11-21 12:43 |
2018-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246710
|
5.4 |
MEDIUM
Network
|
clippercms
|
clippercms
|
ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11572
|
2024-11-21 12:43 |
2018-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|