|
246651
|
9.8 |
CRITICAL
Network
|
furuno
|
felcom_250_firmware felcom_500_firmware
|
FURUNO FELCOM 250 and 500 devices use only client-side JavaScript in login.js for authentication.
|
CWE-287
Improper Authentication
|
CVE-2018-16590
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246652
|
6.5 |
MEDIUM
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
There is an excessive memory allocation issue in the functions ReadBMPImage of coders/bmp.c and ReadDIBImage of coders/dib.c in ImageMagick 7.0.8-11, which allows remote attackers to cause a denial o…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2018-16645
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246653
|
6.5 |
MEDIUM
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
There is a missing check for length in the functions ReadDCMImage of coders/dcm.c and ReadPICTImage of coders/pict.c in ImageMagick 7.0.8-11, which allows remote attackers to cause a denial of servic…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-16644
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246654
|
6.5 |
MEDIUM
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
The functions ReadDCMImage in coders/dcm.c, ReadPWPImage in coders/pwp.c, ReadCALSImage in coders/cals.c, and ReadPICTImage in coders/pict.c in ImageMagick 7.0.8-4 do not check the return value of th…
|
CWE-252
Unchecked Return Value
|
CVE-2018-16643
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246655
|
6.5 |
MEDIUM
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
The function InsertRow in coders/cut.c in ImageMagick 7.0.7-37 allows remote attackers to cause a denial of service via a crafted image file due to an out-of-bounds write.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-16642
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246656
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
ImageMagick 7.0.8-6 has a memory leak vulnerability in the TIFFWritePhotoshopLayers function in coders/tiff.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-16641
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246657
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.8-5 has a memory leak vulnerability in the function ReadOneJNGImage in coders/png.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-16640
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246658
|
5.4 |
MEDIUM
Network
|
html-js
|
doracms
|
Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) discription or (2) comments fiel…
|
CWE-79
Cross-site Scripting
|
CVE-2018-16622
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246659
|
6.5 |
MEDIUM
Network
|
proconf
|
proconf
|
In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted papers (Title and Abstract) and their authors' personal information (Name, Email, Or…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2018-16606
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246660
|
7.2 |
HIGH
Network
|
nibbleblog
|
nibbleblog
|
An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the username because the username is surrounded by double q…
|
CWE-94
Code Injection
|
CVE-2018-16604
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|