|
245981
|
7.5 |
HIGH
Network
|
hutool
|
hutool
|
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive.
|
CWE-22
Path Traversal
|
CVE-2018-17297
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245982
|
6.5 |
MEDIUM
Network
|
liblouis canonical opensuse
|
liblouis ubuntu_linux leap
|
The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's length, allowing attackers to cause a denial of service (application crash via o…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-17294
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245983
|
8.8 |
HIGH
Network
|
webassembly_virtual_machine_project
|
webassembly_virtual_machine
|
An issue was discovered in WAVM before 2018-09-16. The run function in Programs/wavm/wavm.cpp does not check whether there is Emscripten memory to store the command-line arguments passed by the input…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-17293
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245984
|
6.5 |
MEDIUM
Network
|
webassembly_virtual_machine_project
|
webassembly_virtual_machine
|
An issue was discovered in WAVM before 2018-09-16. The loadModule function in Include/Inline/CLI.h lacks checking of the file length before a file magic comparison, allowing attackers to cause a Deni…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-17292
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245985
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_opmanager
|
Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged …
|
CWE-89
SQL Injection
|
CVE-2018-17283
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245986
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-17282
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245987
|
9.8 |
CRITICAL
Network
|
arkextensions
|
jck_editor
|
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17254
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245988
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_opmanager
|
Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2018-17243
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245989
|
6.5 |
MEDIUM
Network
|
hdfgroup
|
hdf5
|
A SIGFPE signal is raised in the function H5D__chunk_set_info_real() of H5Dchunk.c in the HDF HDF5 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection agai…
|
CWE-369
Divide By Zero
|
CVE-2018-17237
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245990
|
6.5 |
MEDIUM
Network
|
mp4v2_project
|
mp4v2
|
The function MP4Free() in mp4property.cpp in libmp4v2 2.1.0 internally calls free() on a invalid pointer, raising a SIGABRT signal.
|
CWE-416
Use After Free
|
CVE-2018-17236
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|