|
247161
|
7.8 |
HIGH
Local
|
artifex canonical debian redhat
|
ghostscript ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_server_aus ent…
|
The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remo…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10194
|
2024-11-21 12:40 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247162
|
5.3 |
MEDIUM
Network
|
iac
|
fromdoctopdf
|
The FromDocToPDF extension before 13.611.13.2303 for Chrome allows remote attackers to discover visited web sites via vectors involving a mostVisitedSites command.
|
CWE-200
Information Exposure
|
CVE-2018-10178
|
2024-11-21 12:40 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247163
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
In ImageMagick 7.0.7-28, there is an infinite loop in the ReadOneMNGImage function of the coders/png.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a craf…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-10177
|
2024-11-21 12:40 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247164
|
8.8 |
HIGH
Local
|
7-zip
|
7-zip
|
7-Zip through 18.01 on Windows implements the "Large memory pages" option by calling the LsaAddAccountRights function to add the SeLockMemoryPrivilege privilege to the user's account, which makes it …
|
CWE-269
Improper Privilege Management
|
CVE-2018-10172
|
2024-11-21 12:40 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247165
|
7.5 |
HIGH
Network
|
mikrotik
|
router_firmware
|
A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU and all available RAM by sending a crafted FTP request on port 21 that begins wi…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-10070
|
2024-11-21 12:40 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247166
|
6.1 |
MEDIUM
Network
|
catalooksupport
|
.netstore
|
The CATALooK.netStore module through 7.2.8 for DNN (formerly DotNetNuke) allows XSS via the /ViewEditGoogleMaps.aspx PortalID or CATSkin parameter, or the /ImageViewer.aspx link or desc parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10138
|
2024-11-21 12:40 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247167
|
8.8 |
HIGH
Network
|
iscripts
|
uberforx
|
iScripts UberforX 2.2 has CSRF in the "manage_settings" section of the Admin Panel via the /cms?section=manage_settings&action=edit URI.
|
CWE-352
Origin Validation Error
|
CVE-2018-10137
|
2024-11-21 12:40 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247168
|
6.1 |
MEDIUM
Network
|
iscripts
|
uberforx
|
iScripts UberforX 2.2 has Stored XSS in the "manage_settings" section of the Admin Panel via a value field to the /cms?section=manage_settings&action=edit URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10136
|
2024-11-21 12:40 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247169
|
6.1 |
MEDIUM
Network
|
iscripts
|
eswap
|
iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10135
|
2024-11-21 12:40 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247170
|
9.8 |
CRITICAL
Network
|
pbootcms
|
pbootcms
|
PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabel function in \apps\home\controller\ParserController.php.
|
CWE-94
Code Injection
|
CVE-2018-10133
|
2024-11-21 12:40 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|