|
246641
|
6.1 |
MEDIUM
Local
|
linux canonical debian
|
linux_kernel ubuntu_linux debian_linux
|
An issue was discovered in the Linux kernel before 4.18.6. An information leak in cdrom_ioctl_drive_status in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a ca…
|
CWE-200
Information Exposure
|
CVE-2018-16658
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246642
|
9.8 |
CRITICAL
Network
|
debian kamailio
|
debian_linux kamailio
|
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with an invalid Via header causes a segmentation fault and crashes Kamailio. The reason is missing input validation in the crcit…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-16657
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246643
|
6.1 |
MEDIUM
Network
|
gxlcms
|
gxlcms
|
Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16655
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246644
|
6.1 |
MEDIUM
Network
|
zurmo
|
zurmo_crm
|
Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16654
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246645
|
6.1 |
MEDIUM
Network
|
rejucms_project
|
rejucms
|
rejucms 2.1 has XSS via the ucenter/cms_user_add.php u_name parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16653
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246646
|
7.2 |
HIGH
Network
|
phpmyfaq
|
phpmyfaq
|
The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2018-16651
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246647
|
8.8 |
HIGH
Network
|
phpmyfaq
|
phpmyfaq
|
phpMyFAQ before 2.9.11 allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2018-16650
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246648
|
5.5 |
MEDIUM
Local
|
artifex
|
mupdf
|
In Artifex MuPDF 1.13.0, the fz_append_byte function in fitz/buffer.c allows remote attackers to cause a denial of service (segmentation fault) via a crafted pdf file. This is caused by a pdf/pdf-dev…
|
CWE-129
Improper Validation of Array Index
|
CVE-2018-16648
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246649
|
5.5 |
MEDIUM
Local
|
artifex
|
mupdf
|
In Artifex MuPDF 1.13.0, the pdf_get_xref_entry function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation fault in fz_write_data in fitz/output.c) via a crafted pd…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-16647
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246650
|
6.5 |
MEDIUM
Network
|
freedesktop debian canonical
|
poppler debian_linux ubuntu_linux
|
In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-16646
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|