|
250871
|
8.8 |
HIGH
Network
|
sam2p_project giflib_project debian canonical
|
sam2p giflib debian_linux ubuntu_linux
|
The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode …
|
CWE-787 CWE-129
Out-of-bounds Write Improper Validation of Array Index
|
CVE-2018-11490
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250872
|
8.8 |
HIGH
Network
|
sam2p_project giflib_project
|
sam2p giflib
|
The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain CrntCode array index i…
|
CWE-787 CWE-129
Out-of-bounds Write Improper Validation of Array Index
|
CVE-2018-11489
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250873
|
6.1 |
MEDIUM
Network
|
phpmywind
|
phpmywind
|
PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11487
|
2024-11-21 12:43 |
2018-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250874
|
8.0 |
HIGH
Network
|
monstra
|
monstra
|
Monstra CMS 3.0.4 has a Session Management Issue in the Users tab. A password change at users/1/edit does not invalidate a session that is open in a different browser.
|
CWE-384
Session Fixation
|
CVE-2018-11475
|
2024-11-21 12:43 |
2018-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250875
|
8.0 |
HIGH
Network
|
monstra
|
monstra
|
Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab. A password change at admin/index.php?id=users&action=edit&user_id=1 does not invalidate a session that is open in a differ…
|
CWE-384
Session Fixation
|
CVE-2018-11474
|
2024-11-21 12:43 |
2018-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250876
|
7.8 |
HIGH
Local
|
windscribe
|
windscribe
|
The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that establishes a \\.\pipe\WindscribeService named pipe endpoint…
|
CWE-20
Improper Input Validation
|
CVE-2018-11479
|
2024-11-21 12:43 |
2018-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250877
|
6.1 |
MEDIUM
Network
|
monstra
|
monstra
|
Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).
|
CWE-79
Cross-site Scripting
|
CVE-2018-11473
|
2024-11-21 12:43 |
2018-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250878
|
6.1 |
MEDIUM
Network
|
monstra
|
monstra
|
Monstra CMS 3.0.4 has Reflected XSS during Login (i.e., the login parameter to admin/index.php).
|
CWE-79
Cross-site Scripting
|
CVE-2018-11472
|
2024-11-21 12:43 |
2018-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250879
|
5.4 |
MEDIUM
Network
|
getcockpit
|
cockpit
|
Cockpit 0.5.5 has XSS via a collection, form, or region.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11471
|
2024-11-21 12:43 |
2018-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250880
|
8.8 |
HIGH
Network
|
iscripts
|
eswap
|
iScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel.
|
CWE-89
SQL Injection
|
CVE-2018-11470
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|