|
246611
|
5.5 |
MEDIUM
Local
|
libfsntfs_project
|
libfsntfs
|
The libfsntfs_security_descriptor_values_free function in libfsntfs_security_descriptor_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause a denial of service (double-free) via…
|
CWE-415
Double Free
|
CVE-2018-11730
|
2024-11-21 12:43 |
2018-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246612
|
5.5 |
MEDIUM
Local
|
libfsntfs_project
|
libfsntfs
|
The libfsntfs_mft_entry_read_header function in libfsntfs_mft_entry.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a cr…
|
CWE-200 CWE-125
Information Exposure Out-of-bounds Read
|
CVE-2018-11729
|
2024-11-21 12:43 |
2018-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246613
|
5.5 |
MEDIUM
Local
|
libfsntfs_project
|
libfsntfs
|
The libfsntfs_reparse_point_values_read_data function in libfsntfs_reparse_point_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer…
|
CWE-200 CWE-125
Information Exposure Out-of-bounds Read
|
CVE-2018-11728
|
2024-11-21 12:43 |
2018-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246614
|
5.5 |
MEDIUM
Local
|
libfsntfs_project
|
libfsntfs
|
The libfsntfs_attribute_read_from_mft function in libfsntfs_attribute.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a …
|
CWE-200 CWE-125
Information Exposure Out-of-bounds Read
|
CVE-2018-11727
|
2024-11-21 12:43 |
2018-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246615
|
8.8 |
HIGH
Network
|
libmobi_project
|
libmobi
|
The mobi_decode_font_resource function in util.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a craft…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11726
|
2024-11-21 12:43 |
2018-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246616
|
6.5 |
MEDIUM
Network
|
libmobi_project
|
libmobi
|
The mobi_parse_index_entry function in index.c in Libmobi 0.3 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted mobi file.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11725
|
2024-11-21 12:43 |
2018-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246617
|
8.8 |
HIGH
Network
|
libmobi_project
|
libmobi
|
The mobi_pk1_decrypt function in encryption.c in Libmobi 0.3 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted …
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11724
|
2024-11-21 12:43 |
2018-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246618
|
5.5 |
MEDIUM
Local
|
libpff_project
|
libpff
|
The libpff_name_to_id_map_entry_read function in libpff_name_to_id_map.c in libyal libpff through 2018-04-28 allows remote attackers to cause an information disclosure (heap-based buffer over-read) v…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11723
|
2024-11-21 12:43 |
2018-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246619
|
6.5 |
MEDIUM
Network
|
auth0
|
angular-jwt
|
Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypa…
|
CWE-20
Improper Input Validation
|
CVE-2018-11537
|
2024-11-21 12:43 |
2018-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246620
|
7.8 |
HIGH
Local
|
webtoffee
|
wordpress_comments_import_and_export
|
The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2018-11526
|
2024-11-21 12:43 |
2018-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|