|
247471
|
6.1 |
MEDIUM
Network
|
instagram-clone_project
|
instagram-clone
|
edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequate XSS protection mechanism based on preg_replace.
|
CWE-79
Cross-site Scripting
|
CVE-2018-13849
|
2024-11-21 12:48 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247472
|
7.5 |
HIGH
Network
|
axiosys
|
bento4
|
An issue has been found in Bento4 1.5.1-624. It is a SEGV in AP4_StszAtom::GetSampleSize in Core/Ap4StszAtom.cpp.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-13848
|
2024-11-21 12:48 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247473
|
7.5 |
HIGH
Network
|
axiosys
|
bento4
|
An issue has been found in Bento4 1.5.1-624. It is a SEGV in AP4_StcoAtom::AdjustChunkOffsets in Core/Ap4StcoAtom.cpp.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-13847
|
2024-11-21 12:48 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247474
|
9.8 |
CRITICAL
Network
|
axiosys
|
bento4
|
An issue has been found in Bento4 1.5.1-624. AP4_Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp has a heap-based buffer over-read after a call from Mp42Ts.cpp, a related issue to CVE-20…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-13846
|
2024-11-21 12:48 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247475
|
9.8 |
CRITICAL
Network
|
htslib
|
htslib
|
An issue has been found in HTSlib 1.8. It is a buffer over-read in sam_parse1 in sam.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-13845
|
2024-11-21 12:48 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247476
|
7.5 |
HIGH
Network
|
htslib
|
htslib
|
An issue has been found in HTSlib 1.8. It is a memory leak in fai_read in faidx.c. NOTE: This has been disputed with the assertion that this vulnerability exists in the test harness and HTSlib users …
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2018-13844
|
2024-11-21 12:48 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247477
|
7.5 |
HIGH
Network
|
htslib
|
htslib
|
An issue has been found in HTSlib 1.8. It is a memory leak in bgzf_getline in bgzf.c. NOTE: the software maintainer's position is that the "failure to free memory" can be fixed in applications that u…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-13843
|
2024-11-21 12:48 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247478
|
7.8 |
HIGH
Local
|
cmft_project
|
cmft
|
An issue was discovered in cmft through 2017-09-24. The cmft::rwReadFile function in image.cpp allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash)…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-13833
|
2024-11-21 12:48 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247479
|
9.8 |
CRITICAL
Network
|
symfony
|
twig
|
Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is not a web application and states that it is the res…
|
CWE-94
Code Injection
|
CVE-2018-13818
|
2024-11-21 12:48 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247480
|
9.8 |
CRITICAL
Network
|
node-macaddress_project
|
node-macaddress
|
The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.
|
CWE-78
OS Command
|
CVE-2018-13797
|
2024-11-21 12:48 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|