|
246391
|
6.5 |
MEDIUM
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
The function InsertRow in coders/cut.c in ImageMagick 7.0.7-37 allows remote attackers to cause a denial of service via a crafted image file due to an out-of-bounds write.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-16642
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246392
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
ImageMagick 7.0.8-6 has a memory leak vulnerability in the TIFFWritePhotoshopLayers function in coders/tiff.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-16641
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246393
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.8-5 has a memory leak vulnerability in the function ReadOneJNGImage in coders/png.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-16640
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246394
|
5.4 |
MEDIUM
Network
|
html-js
|
doracms
|
Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) discription or (2) comments fiel…
|
CWE-79
Cross-site Scripting
|
CVE-2018-16622
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246395
|
6.5 |
MEDIUM
Network
|
proconf
|
proconf
|
In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted papers (Title and Abstract) and their authors' personal information (Name, Email, Or…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2018-16606
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246396
|
7.2 |
HIGH
Network
|
nibbleblog
|
nibbleblog
|
An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the username because the username is surrounded by double q…
|
CWE-94
Code Injection
|
CVE-2018-16604
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246397
|
7.5 |
HIGH
Network
|
apereo
|
opencast
|
An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitrary external services in some situations.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-16153
|
2024-11-21 12:52 |
2023-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246398
|
6.5 |
MEDIUM
Network
|
opera
|
opera_mini
|
The Opera Mini application 47.1.2249.129326 for Android allows remote attackers to spoof the Location Permission dialog via a crafted web site.
|
NVD-CWE-noinfo
|
CVE-2018-16135
|
2024-11-21 12:52 |
2022-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246399
|
6.1 |
MEDIUM
Network
|
mitsubishielectric
|
smartrtu_firmware
|
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16061
|
2024-11-21 12:52 |
2021-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246400
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
smartrtu_firmware
|
Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2018-16060
|
2024-11-21 12:52 |
2021-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|