|
245771
|
6.5 |
MEDIUM
Network
|
libav
|
libav
|
There exists a NULL pointer dereference in ff_vc1_parse_frame_header_adv in vc1.c in Libav 12.3, which allows attackers to cause a denial-of-service through a crafted aac file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-18829
|
2024-11-21 12:56 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245772
|
6.5 |
MEDIUM
Network
|
libav
|
libav
|
There exists a heap-based buffer overflow in vc1_decode_i_block_adv in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-18828
|
2024-11-21 12:56 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245773
|
6.5 |
MEDIUM
Network
|
libav
|
libav
|
There exists a heap-based buffer over-read in ff_vc1_pred_dc in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-18827
|
2024-11-21 12:56 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245774
|
6.5 |
MEDIUM
Network
|
libav
|
libav
|
There exists a heap-based buffer overflow in vc1_decode_p_mb_intfi in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-18826
|
2024-11-21 12:56 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245775
|
6.1 |
MEDIUM
Network
|
pagoda_linux_project
|
pagoda_linux
|
Pagoda Linux panel V6.0 has XSS via the verification code associated with an invalid account login. A crafted code is mishandled during rendering of the login log.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18825
|
2024-11-21 12:56 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245776
|
9.8 |
CRITICAL
Network
|
grapixel
|
new_media
|
Grapixel New Media v2.0 allows SQL Injection via the pages.aspx pageref parameter.
|
CWE-89
SQL Injection
|
CVE-2018-18822
|
2024-11-21 12:56 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245777
|
7.5 |
HIGH
Network
|
leostream
|
connection_broker agent
|
The Leostream Agent before Build 7.0.1.0 when used with Leostream Connection Broker 8.2.72 or earlier allows remote attackers to modify registry keys via the Leostream Agent API.
|
NVD-CWE-noinfo
|
CVE-2018-18817
|
2024-11-21 12:56 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245778
|
9.8 |
CRITICAL
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie.
|
CWE-89
SQL Injection
|
CVE-2018-18792
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245779
|
9.8 |
CRITICAL
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie.
|
CWE-89
SQL Injection
|
CVE-2018-18791
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245780
|
7.2 |
HIGH
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 8.3. SQL Injection exists in admin/special_add.php via a zxbigclassid cookie. (This needs an admin user login.)
|
CWE-89
SQL Injection
|
CVE-2018-18790
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|