|
246351
|
8.8 |
HIGH
Network
|
webassembly_virtual_machine_project
|
webassembly_virtual_machine
|
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because Errors::unreacha…
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2018-16766
|
2024-11-21 12:53 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246352
|
8.8 |
HIGH
Network
|
webassembly_virtual_machine_project
|
webassembly_virtual_machine
|
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an unspecifie…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-16765
|
2024-11-21 12:53 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246353
|
8.8 |
HIGH
Network
|
webassembly_virtual_machine_project
|
webassembly_virtual_machine
|
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an IR::Functi…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-16764
|
2024-11-21 12:53 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246354
|
9.8 |
CRITICAL
Network
|
thedaylightstudio
|
fuel_cms
|
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
|
CWE-74
Injection
|
CVE-2018-16763
|
2024-11-21 12:53 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246355
|
9.8 |
CRITICAL
Network
|
thedaylightstudio
|
fuel_cms
|
FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items.
|
CWE-89
SQL Injection
|
CVE-2018-16762
|
2024-11-21 12:53 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246356
|
6.1 |
MEDIUM
Network
|
eventum_project
|
eventum
|
Eventum before 3.4.0 has an open redirect vulnerability.
|
CWE-601
Open Redirect
|
CVE-2018-16761
|
2024-11-21 12:53 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246357
|
6.1 |
MEDIUM
Network
|
easycms
|
easycms
|
The removeXSS function in App/Common/common.php (called from App/Modules/Index/Action/SearchAction.class.php) in EasyCMS v1.4 allows XSS via an onhashchange event.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16759
|
2024-11-21 12:53 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246358
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
In ImageMagick 7.0.7-29 and earlier, a memory leak in the formatIPTCfromBuffer function in coders/meta.c was found.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-16750
|
2024-11-21 12:53 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246359
|
6.5 |
MEDIUM
Network
|
imagemagick canonical debian
|
imagemagick ubuntu_linux debian_linux
|
In ImageMagick 7.0.7-29 and earlier, a missing NULL check in ReadOneJNGImage in coders/png.c allows an attacker to cause a denial of service (WriteBlob assertion failure and application exit) via a c…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-16749
|
2024-11-21 12:53 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246360
|
5.4 |
MEDIUM
Network
|
rcfilters_project
|
rcfilters
|
In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters section of the settings).
|
CWE-79
Cross-site Scripting
|
CVE-2018-16736
|
2024-11-21 12:53 |
2018-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|