|
248721
|
9.8 |
CRITICAL
Network
|
md4c_project
|
md4c
|
md_is_link_reference_definition_helper in md4c 0.2.5 has a heap-based buffer over-read because md_is_link_label mishandles loop termination.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11547
|
2024-11-21 12:43 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248722
|
9.8 |
CRITICAL
Network
|
md4c_project
|
md4c
|
md4c 0.2.5 has a heap-based buffer over-read because md_is_named_entity_contents has an off-by-one error.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11546
|
2024-11-21 12:43 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248723
|
9.8 |
CRITICAL
Network
|
md4c_project
|
md4c
|
md4c 0.2.5 has a heap-based buffer overflow in md_merge_lines because md_is_link_label mishandles the case of a link label composed solely of backslash escapes.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11545
|
2024-11-21 12:43 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248724
|
9.8 |
CRITICAL
Network
|
theolivetree
|
ftp_server
|
The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-11544
|
2024-11-21 12:43 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248725
|
8.8 |
HIGH
Network
|
jigowatt
|
php_login_\&_user_management
|
An arbitrary file upload vulnerability in /classes/profile.class.php in Jigowatt "PHP Login & User Management" before 4.1.1, as distributed in the Envato Market, allows any remote authenticated user …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-11392
|
2024-11-21 12:43 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248726
|
9.8 |
CRITICAL
Network
|
md4c_project
|
md4c
|
md4c before 0.2.5 has a heap-based buffer overflow because md_split_simple_pairing_mark mishandles splits.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11536
|
2024-11-21 12:43 |
2018-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248727
|
9.8 |
CRITICAL
Network
|
sitemakin
|
slac
|
An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.php is exploitable using SQL injection.
|
CWE-89
SQL Injection
|
CVE-2018-11535
|
2024-11-21 12:43 |
2018-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248728
|
6.1 |
MEDIUM
Network
|
changuondyu_advanced_statistics_project
|
changuondyu_advanced_statistics
|
An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11532
|
2024-11-21 12:43 |
2018-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248729
|
9.8 |
CRITICAL
Network
|
exiv2 debian canonical
|
exiv2 debian_linux ubuntu_linux
|
Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11531
|
2024-11-21 12:43 |
2018-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248730
|
9.8 |
CRITICAL
Network
|
wuzhicms
|
wuzhi_cms
|
WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI.
|
CWE-89
SQL Injection
|
CVE-2018-11528
|
2024-11-21 12:43 |
2018-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|