|
251281
|
9.8 |
CRITICAL
Network
|
haxx canonical
|
curl ubuntu_linux
|
Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that might be exploitable by an attacker who can control the data that curl transmits o…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-0500
|
2024-11-21 12:38 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251282
|
6.1 |
MEDIUM
Network
|
xapian canonical
|
xapian-core ubuntu_linux
|
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().
|
CWE-79
Cross-site Scripting
|
CVE-2018-0499
|
2024-11-21 12:38 |
2018-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251283
|
6.1 |
MEDIUM
Network
|
5000_trillion_yen_converter_project
|
5000_trillion_yen_converter
|
Cross-site scripting vulnerability in 5000 trillion yen converter v1.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2018-0612
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251284
|
7.4 |
HIGH
Network
|
ana
|
ana
|
The ANA App for iOS version 4.0.22 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a cr…
|
CWE-295
Improper Certificate Validation
|
CVE-2018-0611
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251285
|
7.2 |
HIGH
Network
|
zenphoto
|
zenphoto
|
Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code or obtain sensitive information.
|
CWE-269
Improper Privilege Management
|
CVE-2018-0610
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251286
|
7.8 |
HIGH
Local
|
linecorp
|
line
|
Untrusted search path vulnerability in LINE for Windows versions before 5.8.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2018-0609
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251287
|
9.8 |
CRITICAL
Network
|
dena
|
h2o
|
Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-0608
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251288
|
7.2 |
HIGH
Network
|
pixelpost
|
pixelpost
|
SQL injection vulnerability in the Pixelpost v1.7.3 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2018-0606
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251289
|
6.1 |
MEDIUM
Network
|
pixelpost
|
pixelpost
|
Cross-site scripting vulnerability in Pixelpost v1.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2018-0605
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251290
|
7.2 |
HIGH
Network
|
pixelpost
|
pixelpost
|
Pixelpost v1.7.3 and earlier allows remote code execution via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2018-0604
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|