|
247401
|
7.5 |
HIGH
Network
|
miniz_project
|
miniz
|
In Miniz 2.0.7, tinfl_decompress in miniz_tinfl.c has an infinite loop because sym2 and counter can both remain equal to zero.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-12913
|
2024-11-21 12:46 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247402
|
7.2 |
HIGH
Network
|
hongcms_project
|
hongcms
|
An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via an admin/index.php/database/operate?dbaction=emptytable&tablename= URI.
|
CWE-89
SQL Injection
|
CVE-2018-12912
|
2024-11-21 12:46 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247403
|
7.5 |
HIGH
Network
|
webgrind_project
|
webgrind
|
Webgrind 1.5 relies on user input to display a file, which lets anyone view files from the local filesystem (that the webserver user has access to) via an index.php?op=fileviewer&file= URI. NOTE: the…
|
CWE-22
Path Traversal
|
CVE-2018-12909
|
2024-11-21 12:46 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247404
|
9.8 |
CRITICAL
Network
|
brynamics
|
brynamics
|
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for the /dashboard/deposit URI, as demonstr…
|
CWE-200
Information Exposure
|
CVE-2018-12908
|
2024-11-21 12:46 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247405
|
7.5 |
HIGH
Network
|
rclone
|
rclone
|
In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of any URL's content to Google, because there is no val…
|
CWE-200
Information Exposure
|
CVE-2018-12907
|
2024-11-21 12:46 |
2018-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247406
|
6.1 |
MEDIUM
Network
|
joyplus-cms_project
|
joyplus-cms
|
joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12905
|
2024-11-21 12:46 |
2018-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247407
|
4.9 |
MEDIUM
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause L1 KVM guests to VMEXIT, potentially allowing privilege escalations and denial…
|
NVD-CWE-noinfo
|
CVE-2018-12904
|
2024-11-21 12:46 |
2018-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247408
|
5.4 |
MEDIUM
Network
|
cyberark
|
endpoint_privilege_manager
|
In CyberArk Endpoint Privilege Manager (formerly Viewfinity) 10.2.1.603, there is persistent XSS via an account name on the create token screen, the VfManager.asmx SelectAccounts->DisplayName screen,…
|
CWE-79
Cross-site Scripting
|
CVE-2018-12903
|
2024-11-21 12:46 |
2018-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247409
|
6.1 |
MEDIUM
Network
|
easymagazine_project
|
easymagazine
|
In Easy Magazine through 2012-10-26, there is XSS in the search bar of the web site.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12902
|
2024-11-21 12:46 |
2018-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247410
|
8.8 |
HIGH
Network
|
libtiff canonical
|
libtiff ubuntu_linux
|
Heap-based buffer overflow in the cpSeparateBufToContigBuf function in tiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0, 4.0.1, 4.0.2, 4…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12900
|
2024-11-21 12:46 |
2018-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|