|
245991
|
6.5 |
MEDIUM
Network
|
mp4v2_project
|
mp4v2
|
The function mp4v2::impl::MP4Track::FinishSdtp() in mp4track.cpp in libmp4v2 2.1.0 mishandles compatibleBrand while processing a crafted mp4 file, which leads to a heap-based buffer over-read, causin…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-17235
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245992
|
6.5 |
MEDIUM
Network
|
hdfgroup
|
hdf5
|
Memory leak in the H5O__chunk_deserialize() function in H5Ocache.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-17234
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245993
|
6.5 |
MEDIUM
Network
|
hdfgroup
|
hdf5
|
A SIGFPE signal is raised in the function H5D__create_chunk_file_map_hyper() of H5Dchunk.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect…
|
CWE-369
Divide By Zero
|
CVE-2018-17233
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245994
|
9.8 |
CRITICAL
Network
|
slack_archivebot_project
|
slack_archivebot
|
SQL injection vulnerability in archivebot.py in docmarionum1 Slack ArchiveBot (aka slack-archive-bot) before 2018-09-19 allows remote attackers to execute arbitrary SQL commands via the text paramete…
|
CWE-89
SQL Injection
|
CVE-2018-17232
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245995
|
7.5 |
HIGH
Network
|
telegram
|
telegram_desktop
|
Telegram Desktop (aka tdesktop) 1.3.14 might allow attackers to cause a denial of service (assertion failure and application exit) via an "Edit color palette" search that triggers an "index out of ra…
|
CWE-617
Reachable Assertion
|
CVE-2018-17231
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245996
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
Exiv2::ul2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17230
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245997
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
Exiv2::d2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17229
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245998
|
9.8 |
CRITICAL
Network
|
nmap4j_project
|
nmap4j
|
nmap4j 1.1.0 allows attackers to execute arbitrary commands via shell metacharacters in an includeHosts call.
|
CWE-78
OS Command
|
CVE-2018-17228
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245999
|
8.8 |
HIGH
Network
|
linksys
|
velop_firmware
|
Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cgi-bin/zbtest2.cgi (scripts that can be discovered …
|
CWE-78
OS Command
|
CVE-2018-17208
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246000
|
9.8 |
CRITICAL
Network
|
snapcreek
|
duplicator
|
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php duri…
|
CWE-94
Code Injection
|
CVE-2018-17207
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|