|
246221
|
9.8 |
CRITICAL
Network
|
gxlcms
|
gxlcms
|
The add function in www/Lib/Lib/Action/Admin/TplAction.class.php in Gxlcms v1.1.4 allows remote attackers to read arbitrary files via a crafted index.php?s=Admin-Tpl-ADD-id request, related to Lib/Co…
|
CWE-200
Information Exposure
|
CVE-2018-14685
|
2024-11-21 12:49 |
2018-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246222
|
8.8 |
HIGH
Network
|
cabextract cabextract_project debian canonical redhat
|
libmspack cabextract debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server ansible_tower
|
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.
|
CWE-193
Off-by-one Error
|
CVE-2018-14682
|
2024-11-21 12:49 |
2018-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246223
|
8.8 |
HIGH
Network
|
cabextract cabextract_project debian canonical redhat
|
libmspack cabextract debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server ansible_tower
|
An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-14681
|
2024-11-21 12:49 |
2018-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246224
|
6.5 |
MEDIUM
Network
|
cabextract cabextract_project debian canonical redhat
|
libmspack cabextract debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server ansible_tower
|
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames.
|
CWE-20
Improper Input Validation
|
CVE-2018-14680
|
2024-11-21 12:49 |
2018-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246225
|
6.5 |
MEDIUM
Network
|
cabextract cabextract_project debian canonical redhat
|
libmspack cabextract debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server ansible_tower
|
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitial…
|
CWE-193
Off-by-one Error
|
CVE-2018-14679
|
2024-11-21 12:49 |
2018-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246226
|
7.8 |
HIGH
Local
|
linux xen debian canonical
|
linux_kernel xen debian_linux ubuntu_linux
|
An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S does not properly maintain RBX, which al…
|
CWE-665
Improper Initialization
|
CVE-2018-14678
|
2024-11-21 12:49 |
2018-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246227
|
5.5 |
MEDIUM
Local
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference and panic in hfsplus_lookup() in fs/hfsplus/dir.c when opening a file (that is purportedly a hard link…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-14617
|
2024-11-21 12:49 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246228
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference in fscrypt_do_page_crypto() in fs/crypto/crypto.c when operating on a file in a corrupted f2fs image.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-14616
|
2024-11-21 12:49 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246229
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
An issue was discovered in the Linux kernel through 4.17.10. There is a buffer overflow in truncate_inline_inode() in fs/f2fs/inline.c when umounting an f2fs image, because a length value may be nega…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14615
|
2024-11-21 12:49 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246230
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
An issue was discovered in the Linux kernel through 4.17.10. There is an out-of-bounds access in __remove_dirty_segment() in fs/f2fs/segment.c when mounting an f2fs image.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-14614
|
2024-11-21 12:49 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|