|
250881
|
5.9 |
MEDIUM
Network
|
haproxy canonical
|
haproxy ubuntu_linux
|
Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticate…
|
CWE-200
Information Exposure
|
CVE-2018-11469
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250882
|
5.5 |
MEDIUM
Local
|
discount_project debian
|
discount debian_linux
|
The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by m…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11468
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250883
|
8.8 |
HIGH
Network
|
easyservice_billing_project
|
easyservice_billing
|
A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing 1.0. A User can be added with the Admin role.
|
CWE-352
Origin Validation Error
|
CVE-2018-11445
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250884
|
9.8 |
CRITICAL
Network
|
easyservice_billing_project
|
easyservice_billing
|
A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0.
|
CWE-89
SQL Injection
|
CVE-2018-11444
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250885
|
6.1 |
MEDIUM
Network
|
easyservice_billing_project
|
easyservice_billing
|
The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11443
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250886
|
8.8 |
HIGH
Network
|
easyservice_billing_project
|
easyservice_billing
|
A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= URI, as demonstrated by adding a new quotation.
|
CWE-352
Origin Validation Error
|
CVE-2018-11442
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250887
|
8.8 |
HIGH
Network
|
liblouis canonical opensuse
|
liblouis ubuntu_linux leap
|
Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11440
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250888
|
9.8 |
CRITICAL
Network
|
jerryscript
|
jerryscript
|
An issue was discovered in JerryScript 1.0. There is a heap-based buffer over-read in the lit_read_code_unit_from_hex function via a RegExp("[\\u0") payload, related to re_parse_char_class in parser/…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11419
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250889
|
9.8 |
CRITICAL
Network
|
jerryscript
|
jerryscript
|
An issue was discovered in JerryScript 1.0. There is a heap-based buffer over-read in the lit_read_code_unit_from_utf8 function via a RegExp("[\\u0020") payload, related to re_parse_char_class in par…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11418
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250890
|
8.8 |
HIGH
Network
|
jpegoptim_project
|
jpegoptim
|
jpegoptim.c in jpegoptim 1.4.5 (fixed in 1.4.6) has an invalid use of realloc() and free(), which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified…
|
CWE-415
Double Free
|
CVE-2018-11416
|
2024-11-21 12:43 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|