|
246591
|
9.8 |
CRITICAL
Network
|
telegram
|
telegram_desktop
|
Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and application data in cleartext over the SOCKS5 protocol.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-17613
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246592
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
phantompdf reader
|
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This rel…
|
CWE-416
Use After Free
|
CVE-2018-17611
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246593
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
phantompdf reader
|
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This rel…
|
CWE-416
Use After Free
|
CVE-2018-17610
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246594
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
phantompdf reader
|
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This rel…
|
CWE-416
Use After Free
|
CVE-2018-17609
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246595
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
phantompdf reader
|
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This rel…
|
CWE-416
Use After Free
|
CVE-2018-17608
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246596
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
phantompdf reader
|
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This rel…
|
CWE-416
Use After Free
|
CVE-2018-17607
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246597
|
7.5 |
HIGH
Network
|
asset_pipeline_project
|
asset-pipeline
|
An issue was discovered in the Asset Pipeline plugin before 3.0.4 for Grails. An attacker can perform directory traversal via a crafted request when a servlet-based application is executed in Jetty, …
|
CWE-22
Path Traversal
|
CVE-2018-17605
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246598
|
7.1 |
HIGH
Local
|
broadcom
|
tcpreplay
|
Tcpreplay v4.3.0 beta1 contains a heap-based buffer over-read. The get_next_packet() function in the send_packets.c file uses the memcpy() function unsafely to copy sequences from the source buffer p…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-17582
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246599
|
6.5 |
MEDIUM
Network
|
exiv2 debian canonical redhat
|
exiv2 debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-17581
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246600
|
7.1 |
HIGH
Local
|
broadcom
|
tcpreplay
|
A heap-based buffer over-read exists in the function fast_edit_packet() in the file send_packets.c of Tcpreplay v4.3.0 beta1. This can lead to Denial of Service (DoS) and potentially Information Expo…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-17580
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|