|
246761
|
5.5 |
MEDIUM
Local
|
discount_project debian
|
discount debian_linux
|
The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2htm…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11504
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246762
|
5.5 |
MEDIUM
Local
|
discount_project debian
|
discount debian_linux
|
The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11503
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246763
|
8.8 |
HIGH
Network
|
website_seller_script_project
|
website_seller_script
|
PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS.
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2018-11501
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246764
|
8.8 |
HIGH
Network
|
publiccms
|
publiccms
|
An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUser/list" that can add an admin account.
|
CWE-352
Origin Validation Error
|
CVE-2018-11500
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246765
|
9.8 |
CRITICAL
Network
|
sass-lang
|
libsass
|
A use-after-free vulnerability exists in handle_error() in sass_context.cpp in LibSass 3.4.x and 3.5.x through 3.5.4 that could be leveraged to cause a denial of service (application crash) or possib…
|
CWE-416
Use After Free
|
CVE-2018-11499
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246766
|
7.8 |
HIGH
Local
|
lizard_project
|
lz5 lizard
|
In Lizard v1.0 and LZ5 v2.0 (the prior release, before the product was renamed), there is an unchecked buffer size during a memcpy in the Lizard_decompress_LIZv1 function (lib/lizard_decompress_liz.h…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-11498
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246767
|
6.5 |
MEDIUM
Network
|
long_range_zip_project debian
|
long_range_zip debian_linux
|
In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks certain size validation.
|
CWE-416
Use After Free
|
CVE-2018-11496
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246768
|
4.9 |
MEDIUM
Network
|
opencart
|
opencart
|
OpenCart through 3.0.2.0 allows directory traversal in the editDownload function in admin\model\catalog\download.php via admin/index.php?route=catalog/download/edit, related to the download_id. For e…
|
CWE-22
Path Traversal
|
CVE-2018-11495
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246769
|
8.0 |
HIGH
Network
|
opencart
|
opencart
|
The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move, xml, remove) that allows attackers to execute arbitrary code if the remove ste…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2018-11494
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246770
|
8.8 |
HIGH
Network
|
wuzhicms
|
wuzhi_cms
|
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m=link&f=index&v=add.
|
CWE-352
Origin Validation Error
|
CVE-2018-11493
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|