|
246381
|
6.1 |
MEDIUM
Network
|
rejucms_project
|
rejucms
|
rejucms 2.1 has XSS via the ucenter/cms_user_add.php u_name parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16653
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246382
|
7.2 |
HIGH
Network
|
phpmyfaq
|
phpmyfaq
|
The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2018-16651
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246383
|
8.8 |
HIGH
Network
|
phpmyfaq
|
phpmyfaq
|
phpMyFAQ before 2.9.11 allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2018-16650
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246384
|
5.5 |
MEDIUM
Local
|
artifex
|
mupdf
|
In Artifex MuPDF 1.13.0, the fz_append_byte function in fitz/buffer.c allows remote attackers to cause a denial of service (segmentation fault) via a crafted pdf file. This is caused by a pdf/pdf-dev…
|
CWE-129
Improper Validation of Array Index
|
CVE-2018-16648
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246385
|
5.5 |
MEDIUM
Local
|
artifex
|
mupdf
|
In Artifex MuPDF 1.13.0, the pdf_get_xref_entry function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation fault in fz_write_data in fitz/output.c) via a crafted pd…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-16647
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246386
|
6.5 |
MEDIUM
Network
|
freedesktop debian canonical
|
poppler debian_linux ubuntu_linux
|
In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-16646
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246387
|
9.8 |
CRITICAL
Network
|
furuno
|
felcom_250_firmware felcom_500_firmware
|
FURUNO FELCOM 250 and 500 devices use only client-side JavaScript in login.js for authentication.
|
CWE-287
Improper Authentication
|
CVE-2018-16590
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246388
|
6.5 |
MEDIUM
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
There is an excessive memory allocation issue in the functions ReadBMPImage of coders/bmp.c and ReadDIBImage of coders/dib.c in ImageMagick 7.0.8-11, which allows remote attackers to cause a denial o…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2018-16645
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246389
|
6.5 |
MEDIUM
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
There is a missing check for length in the functions ReadDCMImage of coders/dcm.c and ReadPICTImage of coders/pict.c in ImageMagick 7.0.8-11, which allows remote attackers to cause a denial of servic…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-16644
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246390
|
6.5 |
MEDIUM
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
The functions ReadDCMImage in coders/dcm.c, ReadPWPImage in coders/pwp.c, ReadCALSImage in coders/cals.c, and ReadPICTImage in coders/pict.c in ImageMagick 7.0.8-4 do not check the return value of th…
|
CWE-252
Unchecked Return Value
|
CVE-2018-16643
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|