|
246771
|
7.8 |
HIGH
Local
|
2345.cc
|
security_guard
|
In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating …
|
CWE-20
Improper Input Validation
|
CVE-2018-10974
|
2024-11-21 12:42 |
2018-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246772
|
7.8 |
HIGH
Local
|
flif
|
free_lossless_image_format
|
An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The TransformPaletteC::process function in transform/palette_C.hpp allows remote attackers to cause a denial of service (heap-based b…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-10972
|
2024-11-21 12:42 |
2018-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246773
|
5.5 |
MEDIUM
Local
|
flif
|
flif
|
An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The Plane function in image/image.hpp allows remote attackers to cause a denial of service (attempted excessive memory allocation) vi…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2018-10971
|
2024-11-21 12:42 |
2018-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246774
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_netflow_analyzer
|
Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 123125) allows remote attackers to inject arbitrary we…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2018-10803
|
2024-11-21 12:42 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246775
|
9.8 |
CRITICAL
Network
|
attribute_wizard_project
|
attribute_wizard
|
modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-10942
|
2024-11-21 12:42 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246776
|
6.5 |
MEDIUM
Network
|
libtiff debian canonical
|
libtiff debian_linux ubuntu_linux
|
The TIFFWriteDirectorySec() function in tif_dirwrite.c in LibTIFF through 4.0.9 allows remote attackers to cause a denial of service (assertion failure and application crash) via a crafted file, a di…
|
CWE-617
Reachable Assertion
|
CVE-2018-10963
|
2024-11-21 12:42 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246777
|
5.5 |
MEDIUM
Local
|
2345_security_guard_project
|
2345_security_guard
|
An issue was discovered in Shanghai 2345 Security Guard 3.7.0. 2345MPCSafe.exe, 2345SafeTray.exe, and 2345Speedup.exe allow local users to bypass intended process protections, and consequently termin…
|
NVD-CWE-noinfo
|
CVE-2018-10962
|
2024-11-21 12:42 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246778
|
6.5 |
MEDIUM
Network
|
exiv2 debian canonical
|
exiv2 debian_linux ubuntu_linux
|
In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an attempt at memory allocation for an Exiv2::Internal::PngChunk::zlibUncompress call.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10958
|
2024-11-21 12:42 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246779
|
8.8 |
HIGH
Network
|
dlink
|
dir-868l_firmware
|
CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password. hedwig.cgi and pigwidgeon.cgi are two of the affected components.
|
CWE-352
Origin Validation Error
|
CVE-2018-10957
|
2024-11-21 12:42 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246780
|
7.8 |
HIGH
Local
|
2345_security_guard_project
|
2345_security_guard
|
In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating …
|
CWE-20
Improper Input Validation
|
CVE-2018-10955
|
2024-11-21 12:42 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|