|
246791
|
7.5 |
HIGH
Network
|
zclassic
|
z-nomp
|
Z-NOMP before 2018-04-05 has an incorrect Equihash solution verifier that allows attackers to spoof mining shares, as demonstrated by providing a solution with {x1=1,x2=1,x3=1,...,x512=1} to bypass t…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2018-10831
|
2024-11-21 12:42 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246792
|
7.5 |
HIGH
Network
|
litecart
|
litecart
|
LiteCart before 2.1.2 allows remote attackers to cause a denial of service (memory consumption) via URIs that do not exist, because public_html/logs/not_found.log grows without bound, and is loaded i…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-10827
|
2024-11-21 12:42 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246793
|
6.1 |
MEDIUM
Network
|
severalnines
|
clustercontrol
|
Severalnines ClusterControl before 1.6.0-4699 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10817
|
2024-11-21 12:42 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246794
|
4.1 |
MEDIUM
Local
|
bitpie
|
bitcoin_wallet
|
The Bitpie application through 3.2.4 for Android and iOS uses cleartext storage for digital currency initial keys, which allows local users to steal currency by leveraging root access to read /com.bi…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2018-10812
|
2024-11-21 12:42 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246795
|
7.8 |
HIGH
Local
|
2345_security_guard_project
|
2345_security_guard
|
In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input valu…
|
CWE-20
Improper Input Validation
|
CVE-2018-10809
|
2024-11-21 12:42 |
2018-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246796
|
5.4 |
MEDIUM
Network
|
frogcms_project
|
frogcms
|
An issue was discovered in Frog CMS 0.9.5. There is a reflected Cross Site Scripting Vulnerability via the file[current_name] parameter to the admin/?/plugin/file_manager/rename URI. This can be used…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2018-10806
|
2024-11-21 12:42 |
2018-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246797
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-10805
|
2024-11-21 12:42 |
2018-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246798
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick version 7.0.7-28 contains a memory leak in WriteTIFFImage in coders/tiff.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-10804
|
2024-11-21 12:42 |
2018-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246799
|
6.5 |
MEDIUM
Network
|
libtiff
|
libtiff
|
TIFFClientOpen in tif_unix.c in LibTIFF 3.8.2 has memory leaks, as demonstrated by bmp2tiff.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-10801
|
2024-11-21 12:42 |
2018-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246800
|
6.5 |
MEDIUM
Network
|
brave
|
brave
|
A hang issue was discovered in Brave before 0.14.0 (on, for example, Linux). This vulnerability is caused by the mishandling of a long URL formed by window.location+='?\u202a\uFEFF\u202b'; concatenat…
|
CWE-20
Improper Input Validation
|
CVE-2018-10799
|
2024-11-21 12:42 |
2018-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|