|
248361
|
9.8 |
CRITICAL
Network
|
palemoon
|
pale_moon
|
A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.
|
CWE-416
Use After Free
|
CVE-2018-12292
|
2024-11-21 12:44 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248362
|
7.5 |
HIGH
Network
|
matrix
|
synapse
|
The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied …
|
NVD-CWE-noinfo
|
CVE-2018-12291
|
2024-11-21 12:44 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248363
|
6.1 |
MEDIUM
Network
|
yii2-statemachine
|
yii2-statemachine
|
The Yii2-StateMachine extension v2.x.x for Yii2 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12290
|
2024-11-21 12:44 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248364
|
6.1 |
MEDIUM
Network
|
ximdex
|
ximdex
|
The /edit URI in the DMS component in Ximdex 4.0 has XSS via the Ciudad or Nombre parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12273
|
2024-11-21 12:44 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248365
|
6.1 |
MEDIUM
Network
|
ximdex
|
ximdex
|
xowl/request.php in Ximdex 4.0 has XSS via the content parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12272
|
2024-11-21 12:44 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248366
|
9.8 |
CRITICAL
Network
|
acccheck_project
|
acccheck.pl
|
acccheck.pl in acccheck 0.2.1 allows Command Injection via shell metacharacters in a username or password file, as demonstrated by injection into an smbclient command line.
|
CWE-78
OS Command
|
CVE-2018-12268
|
2024-11-21 12:44 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248367
|
6.1 |
MEDIUM
Network
|
hongcms_project
|
hongcms
|
system\errors\404.php in HongCMS 3.0.0 has XSS via crafted input that triggers a 404 HTTP status code.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12266
|
2024-11-21 12:44 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248368
|
8.8 |
HIGH
Network
|
exiv2 debian canonical
|
exiv2 debian_linux ubuntu_linux
|
Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basicio.cpp.
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2018-12265
|
2024-11-21 12:44 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248369
|
8.8 |
HIGH
Network
|
exiv2 debian canonical
|
exiv2 debian_linux ubuntu_linux
|
Exiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea in value.hpp.
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2018-12264
|
2024-11-21 12:44 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248370
|
8.8 |
HIGH
Network
|
portfoliocms_project
|
portfoliocms
|
portfolioCMS 1.0.5 allows upload of arbitrary .php files via the admin/portfolio.php?newpage=true URI.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-12263
|
2024-11-21 12:44 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|