|
247281
|
6.1 |
MEDIUM
Network
|
squirrelmail
|
squirrelmail
|
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14951
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247282
|
6.1 |
MEDIUM
Network
|
squirrelmail
|
squirrelmail
|
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14950
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247283
|
7.8 |
HIGH
Local
|
sound_project
|
sound
|
An issue has been found in dilawar sound through 2017-11-27. The end of openWavFile in wav-file.cc has Mismatched Memory Management Routines (operator new [] versus operator delete).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14948
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247284
|
8.8 |
HIGH
Network
|
flowpaper
|
pdf2json
|
An issue has been found in PDF2JSON 0.69. XmlFontAccu::CSStyle in XmlFonts.cc has Mismatched Memory Management Routines (operator new [] versus operator delete).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14947
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247285
|
8.8 |
HIGH
Network
|
flowpaper
|
pdf2json
|
An issue has been found in PDF2JSON 0.69. The HtmlString class in ImgOutputDev.cc has Mismatched Memory Management Routines (malloc versus operator delete).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14946
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247286
|
7.8 |
HIGH
Local
|
jpeg_encoder_project
|
jpeg_encoder
|
An issue has been found in jpeg_encoder through 2015-11-27. It is a heap-based buffer overflow in the function readFromBMP in jpeg_encoder.cpp.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-14945
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247287
|
7.8 |
HIGH
Local
|
jpeg_encoder_project
|
jpeg_encoder
|
An issue has been found in jpeg_encoder through 2015-11-27. It is a SEGV in the function readFromBMP in jpeg_encoder.cpp. The signal is caused by an out-of-bounds write.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-14944
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247288
|
9.8 |
CRITICAL
Network
|
harmonicinc
|
nsg_9000_firmware
|
Harmonic NSG 9000 devices have a default password of nsgadmin for the admin account, a default password of nsgguest for the guest account, and a default password of nsgconfig for the config account.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-14943
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247289
|
8.8 |
HIGH
Network
|
harmonicinc
|
nsg_9000_firmware
|
Harmonic NSG 9000 devices allow remote authenticated users to conduct directory traversal attacks, as demonstrated by "POST /PY/EMULATION_GET_FILE" or "POST /PY/EMULATION_EXPORT" with FileName=../../…
|
CWE-22
Path Traversal
|
CVE-2018-14942
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247290
|
6.5 |
MEDIUM
Network
|
harmonicinc
|
nsg_9000
|
Harmonic NSG 9000 devices allow remote authenticated users to read the webapp.py source code via a direct request for the /webapp.py URI.
|
CWE-200
Information Exposure
|
CVE-2018-14941
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|