|
246321
|
7.5 |
HIGH
Network
|
tencent
|
wechat_pay
|
WXPayUtil in WeChat Pay Java SDK allows XXE attacks involving a merchant notification URL.
|
CWE-611
XXE
|
CVE-2018-13439
|
2024-11-21 12:47 |
2018-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246322
|
6.1 |
MEDIUM
Network
|
boostnote
|
boostnote
|
Boostnote v0.11.7 allows XSS during highlighting of Markdown text, as demonstrated by an onerror attribute of an IMG element.
|
CWE-79
Cross-site Scripting
|
CVE-2018-13433
|
2024-11-21 12:47 |
2018-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246323
|
6.1 |
MEDIUM
Network
|
omeka
|
omeka
|
admin/themes/default/items/tag-form.php in Omeka before 2.6.1 allows XSS by adding or editing a tag.
|
CWE-79
Cross-site Scripting
|
CVE-2018-13423
|
2024-11-21 12:47 |
2018-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246324
|
6.1 |
MEDIUM
Network
|
tecnick
|
tcexam
|
TCExam before 14.1.2 has XSS via an ff_ or xl_ field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-13422
|
2024-11-21 12:47 |
2018-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246325
|
9.8 |
CRITICAL
Network
|
fast-cpp-csv-parser_project
|
fast-cpp-csv-parser
|
Fast C++ CSV Parser (aka fast-cpp-csv-parser) before 2018-07-06 has a heap-based buffer over-read in io::trim_chars in csv.h.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-13421
|
2024-11-21 12:47 |
2018-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246326
|
7.5 |
HIGH
Network
|
gperftools_project
|
gperftools
|
Google gperftools 2.7 has a memory leak in malloc_extension.cc, related to MallocExtension::Register and InitModule. NOTE: the software maintainer indicates that this is not a bug; it is only a false…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-13420
|
2024-11-21 12:47 |
2018-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246327
|
6.5 |
MEDIUM
Network
|
libsndfile_project
|
libsndfile
|
An issue has been found in libsndfile 1.0.28. There is a memory leak in psf_allocate in common.c, as demonstrated by sndfile-convert. NOTE: The maintainer and third parties were unable to reproduce a…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-13419
|
2024-11-21 12:47 |
2018-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246328
|
9.8 |
CRITICAL
Network
|
info-zip_project
|
zip
|
Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact becau…
|
CWE-416
Use After Free
|
CVE-2018-13410
|
2024-11-21 12:47 |
2018-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246329
|
6.1 |
MEDIUM
Network
|
jirafeau
|
jirafeau
|
An issue was discovered in Jirafeau before 3.4.1. The "search file by hash" form is affected by reflected XSS that could allow, by targeting an administrator, stealing a session and gaining administr…
|
CWE-79
Cross-site Scripting
|
CVE-2018-13409
|
2024-11-21 12:47 |
2018-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246330
|
6.1 |
MEDIUM
Network
|
jirafeau
|
jirafeau
|
An issue was discovered in Jirafeau before 3.4.1. The "search file by link" form is affected by reflected XSS that could allow, by targeting an administrator, stealing a session and gaining administr…
|
CWE-79
Cross-site Scripting
|
CVE-2018-13408
|
2024-11-21 12:47 |
2018-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|