|
250541
|
5.5 |
MEDIUM
Local
|
linux canonical debian
|
linux_kernel ubuntu_linux debian_linux
|
The xfs_bmap_extents_to_btree function in fs/xfs/libxfs/xfs_bmap.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_bmapi_write NULL pointer dereference) via a …
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-10323
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250542
|
5.5 |
MEDIUM
Local
|
linux redhat
|
linux_kernel enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server virtualization_host
|
The xfs_dinode_verify function in fs/xfs/libxfs/xfs_inode_buf.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_ilock_attr_map_shared invalid pointer dereferen…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-10322
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250543
|
4.8 |
MEDIUM
Network
|
frogcms_project
|
frogcms
|
Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10321
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250544
|
4.8 |
MEDIUM
Network
|
frogcms_project
|
frogcms
|
Frog CMS 0.9.5 has XSS via the admin/?/layout/edit layout[name] parameter, aka Edit Layout.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10320
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250545
|
4.8 |
MEDIUM
Network
|
frogcms_project
|
frogcms
|
Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit snippet[name] parameter, aka Edit Snippet.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10319
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250546
|
4.8 |
MEDIUM
Network
|
frogcms_project
|
frogcms
|
Frog CMS 0.9.5 has XSS via the admin/?/page/edit page[keywords] parameter, aka Edit Page Metadata.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10318
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250547
|
5.5 |
MEDIUM
Local
|
nasm
|
netwide_assembler
|
Netwide Assembler (NASM) 2.14rc0 has an endless while loop in the assemble_file function of asm/nasm.c because of a globallineno integer overflow.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-10316
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250548
|
5.4 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10313
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250549
|
8.8 |
HIGH
Network
|
wuzhicms
|
wuzhi_cms
|
index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.
|
CWE-352
Origin Validation Error
|
CVE-2018-10312
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250550
|
6.1 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10311
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|