|
246251
|
6.6 |
MEDIUM
Physics
|
opensc_project
|
opensc
|
Several buffer overflows when handling responses from a Cryptoflex card in read_public_key in tools/cryptoflex-tool.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted sma…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-16419
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246252
|
6.6 |
MEDIUM
Physics
|
opensc_project
|
opensc
|
A buffer overflow when handling string concatenation in util_acl_to_str in tools/util.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of s…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-16418
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246253
|
8.8 |
HIGH
Network
|
thedaylightstudio
|
fuel_cms
|
Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administrator's password.
|
CWE-352
Origin Validation Error
|
CVE-2018-16416
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246254
|
8.8 |
HIGH
Network
|
imagemagick
|
imagemagick
|
ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the MagickCore/quantum-private.h PushShortPixel function when called from the coders/psd.c ParseImageResourceBlocks function.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-16413
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246255
|
8.8 |
HIGH
Network
|
imagemagick opensuse
|
imagemagick leap
|
ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the coders/psd.c ParseImageResourceBlocks function.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-16412
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246256
|
6.5 |
MEDIUM
Network
|
vanillaforums
|
vanilla
|
Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/class.invitationmodel.php and applications/dashboard/control…
|
CWE-89
SQL Injection
|
CVE-2018-16410
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246257
|
8.6 |
HIGH
Network
|
gogs
|
gogs
|
In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-16409
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246258
|
7.2 |
HIGH
Network
|
d-link
|
dir-846_firmware
|
D-Link DIR-846 devices with firmware 100.26 allow remote attackers to execute arbitrary code as root via a SetNetworkTomographySettings request by leveraging admin access.
|
CWE-78
OS Command
|
CVE-2018-16408
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246259
|
6.1 |
MEDIUM
Network
|
mayan-edms
|
mayan_edms
|
An issue was discovered in Mayan EDMS before 3.0.3. The Tags app has XSS because tag label values are mishandled.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16407
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246260
|
6.1 |
MEDIUM
Network
|
mayan-edms
|
mayan_edms
|
An issue was discovered in Mayan EDMS before 3.0.2. The Cabinets app has XSS via a crafted cabinet label.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16406
|
2024-11-21 12:52 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|