|
246691
|
6.5 |
MEDIUM
Network
|
makemytrip
|
makemytrip
|
An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as de…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2018-11242
|
2024-11-21 12:42 |
2018-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246692
|
7.5 |
HIGH
Network
|
hexagontoken
|
hexagon
|
An integer overflow in the _transfer function of a smart contract implementation for Hexagon (HXG), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-11239
|
2024-11-21 12:42 |
2018-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246693
|
5.5 |
MEDIUM
Local
|
podofo_project
|
podofo
|
An issue was discovered in PoDoFo 0.9.5. The function PdfPage::GetPageNumber() in PdfPage.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and applic…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-11255
|
2024-11-21 12:42 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246694
|
5.5 |
MEDIUM
Local
|
podofo_project
|
podofo
|
An issue was discovered in PoDoFo 0.9.5. There is an Excessive Recursion in the PdfPagesTree::GetPageNode() function of PdfPagesTree.cpp. Remote attackers could leverage this vulnerability to cause a…
|
CWE-674
Uncontrolled Recursion
|
CVE-2018-11254
|
2024-11-21 12:42 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246695
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.7-23 Q16 x86_64 2018-01-24, there is a heap-based buffer over-read in ReadSUNImage in coders/sun.c, which allows attackers to cause a denial of service (application crash in SetGra…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11251
|
2024-11-21 12:42 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246696
|
9.8 |
CRITICAL
Network
|
liulishuo
|
filedownloader
|
util/FileDownloadUtils.java in FileDownloader 1.7.3 does not check an attachment's name. If an attacker places "../" in the file name, the file can be stored in an unintended directory because of Dir…
|
CWE-22
Path Traversal
|
CVE-2018-11248
|
2024-11-21 12:42 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246697
|
6.1 |
MEDIUM
Network
|
misp-project
|
misp
|
app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11245
|
2024-11-21 12:42 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246698
|
5.3 |
MEDIUM
Network
|
dopewp
|
bbe_theme
|
The BBE theme before 1.53 for WordPress allows a direct launch of an HTML editor.
|
NVD-CWE-noinfo
|
CVE-2018-11244
|
2024-11-21 12:42 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246699
|
7.8 |
HIGH
Local
|
upx_project
|
upx
|
PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability of a malware scanner to operate on the entire original data, o…
|
CWE-415
Double Free
|
CVE-2018-11243
|
2024-11-21 12:42 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246700
|
7.8 |
HIGH
Local
|
gnu redhat oracle netapp canonical
|
glibc enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server virtualization_host enterprise_communications_broker communications_session_border_controller …
|
An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempc…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11237
|
2024-11-21 12:42 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|