|
248621
|
8.1 |
HIGH
Network
|
sleuthkit
|
the_sleuth_kit
|
An issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function tsk_UTF16toUTF8 in tsk/base/tsk…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11740
|
2024-11-21 12:43 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248622
|
8.1 |
HIGH
Network
|
sleuthkit
|
the_sleuth_kit
|
An issue was discovered in libtskimg.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function raw_read in tsk/img/raw.c which …
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11739
|
2024-11-21 12:43 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248623
|
8.1 |
HIGH
Network
|
sleuthkit
|
the_sleuth_kit
|
An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function ntfs_make_data_run in tsk/fs/ntfs…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11738
|
2024-11-21 12:43 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248624
|
8.1 |
HIGH
Network
|
sleuthkit
|
the_sleuth_kit
|
An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function ntfs_fix_idxrec in tsk/fs/ntfs_de…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11737
|
2024-11-21 12:43 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248625
|
9.8 |
CRITICAL
Network
|
monstra
|
monstra_cms
|
plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.
|
CWE-20
Improper Input Validation
|
CVE-2018-11678
|
2024-11-21 12:43 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248626
|
9.8 |
CRITICAL
Network
|
yzmcms
|
yzmcms
|
The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Discrepancy Information Exposure issue and an unexpectedly long lifetime for a ver…
|
CWE-200
Information Exposure
|
CVE-2018-11554
|
2024-11-21 12:43 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248627
|
9.8 |
CRITICAL
Network
|
pluck-cms
|
pluck
|
An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-11736
|
2024-11-21 12:43 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248628
|
6.1 |
MEDIUM
Network
|
ximdex
|
ximdex
|
index.php?action=createaccount in Ximdex 4.0 has XSS via the sname or fname parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11735
|
2024-11-21 12:43 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248629
|
5.4 |
MEDIUM
Network
|
recent_threads_project
|
recent_threads
|
The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11715
|
2024-11-21 12:43 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248630
|
9.8 |
CRITICAL
Network
|
tp-link
|
tl-wr840n_firmware tl-wr841n_firmware
|
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused…
|
CWE-384
Session Fixation
|
CVE-2018-11714
|
2024-11-21 12:43 |
2018-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|