|
246871
|
4.8 |
MEDIUM
Network
|
creatiwity
|
witycms
|
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbit…
|
CWE-79
Cross-site Scripting
|
CVE-2018-11512
|
2024-11-21 12:43 |
2018-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246872
|
5.5 |
MEDIUM
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.
|
CWE-200
Information Exposure
|
CVE-2018-11508
|
2024-11-21 12:43 |
2018-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246873
|
6.5 |
MEDIUM
Network
|
flif
|
flif
|
An issue was discovered in Free Lossless Image Format (FLIF) 0.3. An attacker can trigger a long loop in image_load_pnm in image/image-pnm.cpp.
|
CWE-834
Excessive Iteration
|
CVE-2018-11507
|
2024-11-21 12:43 |
2018-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246874
|
7.8 |
HIGH
Local
|
linux canonical debian
|
linux_kernel ubuntu_linux debian_linux
|
The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified othe…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11506
|
2024-11-21 12:43 |
2018-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246875
|
7.5 |
HIGH
Network
|
werewolf_online_project
|
werewolf_online
|
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.
|
CWE-200
Information Exposure
|
CVE-2018-11505
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246876
|
5.5 |
MEDIUM
Local
|
discount_project debian
|
discount debian_linux
|
The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2htm…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11504
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246877
|
5.5 |
MEDIUM
Local
|
discount_project debian
|
discount debian_linux
|
The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11503
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246878
|
8.8 |
HIGH
Network
|
website_seller_script_project
|
website_seller_script
|
PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS.
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2018-11501
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246879
|
8.8 |
HIGH
Network
|
publiccms
|
publiccms
|
An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUser/list" that can add an admin account.
|
CWE-352
Origin Validation Error
|
CVE-2018-11500
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246880
|
9.8 |
CRITICAL
Network
|
sass-lang
|
libsass
|
A use-after-free vulnerability exists in handle_error() in sass_context.cpp in LibSass 3.4.x and 3.5.x through 3.5.4 that could be leveraged to cause a denial of service (application crash) or possib…
|
CWE-416
Use After Free
|
CVE-2018-11499
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|