|
247381
|
7.5 |
HIGH
Network
|
boodskap
|
growchain
|
The _sell function of a smart contract implementation for GROWCHAIN (GROW), an Ethereum token, has an integer overflow.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-13325
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247382
|
9.8 |
CRITICAL
Network
|
godoc
|
go_doc_dot_org
|
In Go Doc Dot Org (gddo) through 2018-06-27, an attacker could use specially crafted <go-import> tags in packages being fetched by gddo to cause a directory traversal and remote code execution.
|
CWE-22
Path Traversal
|
CVE-2018-12976
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247383
|
9.8 |
CRITICAL
Network
|
gnome canonical debian redhat opensuse
|
libsoup ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server openshift_container_platform ansible_tower leap
|
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-12910
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247384
|
8.1 |
HIGH
Network
|
ffmpeg
|
ffmpeg
|
In FFmpeg 4.0.1, due to a missing check for negative values of the mquant variable, the vc1_put_blocks_clamped function in libavcodec/vc1_block.c may trigger an out-of-array access while converting a…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-13305
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247385
|
6.5 |
MEDIUM
Network
|
ffmpeg
|
ffmpeg
|
In libavcodec in FFmpeg 4.0.1, improper maintenance of the consistency between the context profile field and studio_profile in libavcodec may trigger an assertion failure while converting a crafted A…
|
CWE-617
Reachable Assertion
|
CVE-2018-13304
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247386
|
6.5 |
MEDIUM
Network
|
ffmpeg
|
ffmpeg
|
In FFmpeg 4.0.1, a missing check for failure of a call to init_get_bits8() in the avpriv_ac3_parse_header function in libavcodec/ac3_parser.c may trigger a NULL pointer dereference while converting a…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-13303
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247387
|
8.8 |
HIGH
Network
|
ffmpeg debian
|
ffmpeg debian_linux
|
In FFmpeg 4.0.1, improper handling of frame types (other than EAC3_FRAME_TYPE_INDEPENDENT) that have multiple independent substreams in the handle_eac3 function in libavformat/movenc.c may trigger an…
|
CWE-129
Improper Validation of Array Index
|
CVE-2018-13302
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247388
|
6.5 |
MEDIUM
Network
|
ffmpeg
|
ffmpeg
|
In FFmpeg 4.0.1, due to a missing check of a profile value before setting it, the ff_mpeg4_decode_picture_header function in libavcodec/mpeg4videodec.c may trigger a NULL pointer dereference while co…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-13301
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247389
|
8.1 |
HIGH
Network
|
ffmpeg debian
|
ffmpeg debian_linux
|
In FFmpeg 3.2 and 4.0.1, an improper argument (AVCodecParameters) passed to the avpriv_request_sample function in the handle_eac3 function in libavformat/movenc.c may trigger an out-of-array read whi…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-13300
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247390
|
6.1 |
MEDIUM
Network
|
entrustdatacard
|
syntera_customization_suite
|
Entrust Datacard Syntera CS 5.x has XSS via the name field of "Domain or Computer Name" in the login page.
|
CWE-79
Cross-site Scripting
|
CVE-2018-13252
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|