|
247671
|
6.1 |
MEDIUM
Network
|
icmsdev
|
icms
|
An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14415
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247672
|
9.8 |
CRITICAL
Network
|
ssh_companywebsite_project
|
ssh_companywebsite
|
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upload, as demonstrated by a .jsp file with the image…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-14441
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247673
|
9.8 |
CRITICAL
Network
|
ssh_companywebsite_project
|
ssh_companywebsite
|
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. SQL injection exists via the admin/noticeManageAction_queryNotice.action noticeInfo parameter.
|
CWE-89
SQL Injection
|
CVE-2018-14440
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247674
|
7.5 |
HIGH
Network
|
eblock
|
eos4j
|
espritblock eos4j, an unofficial SDK for EOS, through 2018-07-12 mishandles floating-point numbers with more than four digits after the decimal point, which might allow attackers to trigger currency …
|
CWE-682
Incorrect Calculation
|
CVE-2018-14439
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247675
|
7.5 |
HIGH
Network
|
wireshark
|
wireshark
|
In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which allows attackers to modify the access control arbitra…
|
CWE-20
Improper Input Validation
|
CVE-2018-14438
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247676
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.8-4 has a memory leak in parse8BIM in coders/meta.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-14437
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247677
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.8-4 has a memory leak in ReadMIFFImage in coders/miff.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-14436
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247678
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.8-4 has a memory leak in DecodeImage in coders/pcd.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-14435
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247679
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-14434
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247680
|
7.5 |
HIGH
Network
|
uclouvain debian
|
openjpeg debian_linux
|
Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (appl…
|
CWE-369
Divide By Zero
|
CVE-2018-14423
|
2024-11-21 12:49 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|