|
246531
|
7.5 |
HIGH
Network
|
s3ql_project
|
s3ql
|
S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versions of the filesystem metadata database as up-to-da…
|
CWE-20
Improper Input Validation
|
CVE-2018-12088
|
2024-11-21 12:44 |
2018-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246532
|
8.8 |
HIGH
Network
|
liblouis canonical opensuse
|
liblouis ubuntu_linux leap
|
Liblouis 3.6.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12085
|
2024-11-21 12:44 |
2018-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246533
|
7.5 |
HIGH
Network
|
redhat canonical debian gnupg
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_server_tus enterprise_linux_server_aus ubuntu_linux deb…
|
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 t…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2018-12020
|
2024-11-21 12:44 |
2018-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246534
|
5.5 |
MEDIUM
Local
|
bird_project
|
bird
|
BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon crash) via BGP mask expressions in birdc.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-12066
|
2024-11-21 12:44 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246535
|
9.8 |
CRITICAL
Network
|
creatiwity
|
witycms
|
A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP files (execute PHP code) or read non-PHP files by replacing …
|
CWE-20
Improper Input Validation
|
CVE-2018-12065
|
2024-11-21 12:44 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246536
|
9.8 |
CRITICAL
Network
|
tinyexr_project
|
tinyexr
|
tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-12064
|
2024-11-21 12:44 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246537
|
9.8 |
CRITICAL
Network
|
schools_alert_management_script_project
|
schools_alert_management_script
|
Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.php, faq.php, about.php, photo_gallery.php, privacy.php, and so on.
|
CWE-89
SQL Injection
|
CVE-2018-12055
|
2024-11-21 12:44 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246538
|
7.5 |
HIGH
Network
|
schools_alert_management_script_project
|
schools_alert_management_script
|
Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absolute path traversal.
|
CWE-22
Path Traversal
|
CVE-2018-12054
|
2024-11-21 12:44 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246539
|
7.5 |
HIGH
Network
|
schools_alert_management_script_project
|
schools_alert_management_script
|
Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.php by using directory traversal.
|
CWE-22
Path Traversal
|
CVE-2018-12053
|
2024-11-21 12:44 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246540
|
9.8 |
CRITICAL
Network
|
schools_alert_management_script_project
|
schools_alert_management_script
|
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
|
CWE-89
SQL Injection
|
CVE-2018-12052
|
2024-11-21 12:44 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|