|
246331
|
9.8 |
CRITICAL
Network
|
furuno
|
felcom_250_firmware felcom_500_firmware
|
FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the system's usernames and passwords. This includes the Admin and Service user accounts…
|
CWE-200
Information Exposure
|
CVE-2018-16705
|
2024-11-21 12:53 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246332
|
9.8 |
CRITICAL
Network
|
furuno
|
felcom_250_firmware felcom_500_firmware
|
FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_cha…
|
CWE-862
Missing Authorization
|
CVE-2018-16591
|
2024-11-21 12:53 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246333
|
7.8 |
HIGH
Local
|
artifex debian canonical redhat
|
ghostscript debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_eus ent…
|
An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply…
|
NVD-CWE-noinfo
|
CVE-2018-16802
|
2024-11-21 12:53 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246334
|
7.8 |
HIGH
Local
|
kakaocorp
|
potplayer
|
A heap-based buffer overflow in PotPlayerMini.exe in PotPlayer 1.7.8556 allows remote attackers to execute arbitrary code via a .wav file with large BytesPerSec and SamplesPerSec values, and a small …
|
CWE-787
Out-of-bounds Write
|
CVE-2018-16797
|
2024-11-21 12:53 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246335
|
8.8 |
HIGH
Network
|
monstra
|
monstra
|
In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&action=edit&user_id=1, Insecure Direct Object Reference (IDOR).
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2018-16608
|
2024-11-21 12:53 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246336
|
8.1 |
HIGH
Network
|
mongodb
|
libbson
|
_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read via a crafted bson buffer.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-16790
|
2024-11-21 12:53 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246337
|
8.8 |
HIGH
Network
|
entropymine
|
imageworsener
|
libimageworsener.a in ImageWorsener 1.3.2 has a buffer overflow in the bmpr_read_rle_internal function in imagew-bmp.c.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-16782
|
2024-11-21 12:53 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246338
|
6.5 |
MEDIUM
Network
|
rockcarry
|
ffjpeg
|
ffjpeg.dll in ffjpeg before 2018-08-22 allows remote attackers to cause a denial of service (FPE signal) via a progressive JPEG file that lacks an AC Huffman table.
|
CWE-682 CWE-755
Incorrect Calculation Improper Handling of Exceptional Conditions
|
CVE-2018-16781
|
2024-11-21 12:53 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246339
|
5.4 |
MEDIUM
Network
|
complete_responsive_cms_blog_project
|
complete_responsive_cms_blog
|
Complete Responsive CMS Blog through 2018-05-20 has XSS via a comment.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16780
|
2024-11-21 12:53 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246340
|
6.1 |
MEDIUM
Network
|
blogcms_project
|
blogcms
|
BlogCMS through 2016-10-25 has XSS via a comment.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16779
|
2024-11-21 12:53 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|