|
248921
|
9.1 |
CRITICAL
Network
|
koji_project
|
koji
|
Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access control vulnerability resulting in arbitrary filesystem read/write access. This vulnerability has been fixed in versions 1.12.1, 1.1…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-1002150
|
2024-11-21 12:40 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248922
|
6.5 |
MEDIUM
Network
|
jenkins
|
jenkins
|
A path traversal vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java that allows attackers with Job/Configure permiss…
|
CWE-22
Path Traversal
|
CVE-2018-1000406
|
2024-11-21 12:39 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248923
|
8.4 |
HIGH
Adjacent
|
microsoft
|
windows_server_2016 windows_10
|
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote…
|
CWE-20
Improper Input Validation
|
CVE-2018-0965
|
2024-11-21 12:39 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248924
|
9.8 |
CRITICAL
Network
|
cobblerd
|
cobbler
|
Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrect Access Control vul…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-1000226
|
2024-11-21 12:39 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248925
|
6.1 |
MEDIUM
Network
|
cobblerd
|
cobbler
|
Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Cross Site Scripting (XSS) v…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000225
|
2024-11-21 12:39 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248926
|
7.5 |
HIGH
Network
|
godotengine
|
godot
|
Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing padding initialization v…
|
CWE-190 CWE-131 CWE-681 CWE-908 CWE-909
Integer Overflow or Wraparound Incorrect Calculation of Buffer Size Incorrect Conversion between Numeric Types Use of Uninitialized Resource Missing Initialization of Resource
|
CVE-2018-1000224
|
2024-11-21 12:39 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248927
|
8.8 |
HIGH
Network
|
surina
|
soundtouch
|
soundtouch version up to and including 2.0.0 contains a Buffer Overflow vulnerability in SoundStretch/WavFile.cpp:WavInFile::readHeaderBlock() that can result in arbitrary code execution. This attack…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-1000223
|
2024-11-21 12:39 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248928
|
8.8 |
HIGH
Network
|
libgd canonical debian
|
libgd ubuntu_linux debian_linux
|
Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This attack appear to be exploitable via Specially Crafted …
|
CWE-415
Double Free
|
CVE-2018-1000222
|
2024-11-21 12:39 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248929
|
9.8 |
CRITICAL
Network
|
pkgconf
|
pkgconf
|
pkgconf version 1.5.0 to 1.5.2 contains a Buffer Overflow vulnerability in dequote() that can result in dequote() function returns 1-byte allocation if initial length is 0, leading to buffer overflow…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-1000221
|
2024-11-21 12:39 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248930
|
5.4 |
MEDIUM
Network
|
open-emr
|
openemr
|
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'scan' parameter in line #41 of interface/fax/fax_view.php that can result in The vulnerability could allow remote …
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000219
|
2024-11-21 12:39 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|