|
249751
|
9.8 |
CRITICAL
Network
|
liulishuo
|
filedownloader
|
util/FileDownloadUtils.java in FileDownloader 1.7.3 does not check an attachment's name. If an attacker places "../" in the file name, the file can be stored in an unintended directory because of Dir…
|
CWE-22
Path Traversal
|
CVE-2018-11248
|
2024-11-21 12:42 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249752
|
6.1 |
MEDIUM
Network
|
misp-project
|
misp
|
app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11245
|
2024-11-21 12:42 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249753
|
5.3 |
MEDIUM
Network
|
dopewp
|
bbe_theme
|
The BBE theme before 1.53 for WordPress allows a direct launch of an HTML editor.
|
NVD-CWE-noinfo
|
CVE-2018-11244
|
2024-11-21 12:42 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249754
|
7.8 |
HIGH
Local
|
upx_project
|
upx
|
PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability of a malware scanner to operate on the entire original data, o…
|
CWE-415
Double Free
|
CVE-2018-11243
|
2024-11-21 12:42 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249755
|
7.8 |
HIGH
Local
|
gnu redhat oracle netapp canonical
|
glibc enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server virtualization_host enterprise_communications_broker communications_session_border_controller …
|
An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempc…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11237
|
2024-11-21 12:42 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249756
|
9.8 |
CRITICAL
Network
|
gnu redhat oracle netapp
|
glibc enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server virtualization_host enterprise_communications_broker communications_session_border_controller …
|
stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit …
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2018-11236
|
2024-11-21 12:42 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249757
|
9.8 |
CRITICAL
Network
|
d-link
|
dir-550a_firmware dir-604m_firmware
|
On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can use a default TELNET account to get unauthorized access to vulnerable devices, aka a backdoor access vulnerability.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2018-10968
|
2024-11-21 12:42 |
2018-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249758
|
8.8 |
HIGH
Network
|
d-link
|
dir-550a_firmware dir-604m_firmware
|
On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be executed on the device with higher privileges, aka …
|
CWE-78
OS Command
|
CVE-2018-10967
|
2024-11-21 12:42 |
2018-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249759
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The etm_setup_aux function in drivers/hwtracing/coresight/coresight-etm-perf.c in the Linux kernel before 4.10.2 allows attackers to cause a denial of service (panic) because a parameter is incorrect…
|
CWE-20
Improper Input Validation
|
CVE-2018-11232
|
2024-11-21 12:42 |
2018-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249760
|
7.8 |
HIGH
Local
|
vcftools_project
|
vcftools
|
The header::add_FORMAT_descriptor function in header.cpp in VCFtools 0.1.15 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a craft…
|
CWE-416
Use After Free
|
CVE-2018-11130
|
2024-11-21 12:42 |
2018-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|