|
247611
|
7.5 |
HIGH
Network
|
mi
|
mi_a2_lite_firmware redmi_6_firmware
|
The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices through 2018-08-27 has a NULL pointer dereference in kf…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-19939
|
2024-11-21 12:58 |
2018-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247612
|
7.5 |
HIGH
Network
|
php debian
|
php debian_linux
|
ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty string in the message argument t…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-19935
|
2024-11-21 12:58 |
2018-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247613
|
5.5 |
MEDIUM
Local
|
gnu netapp
|
binutils vasa_provider
|
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINE…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-19932
|
2024-11-21 12:58 |
2018-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247614
|
7.8 |
HIGH
Local
|
gnu netapp canonical
|
binutils vasa_provider ubuntu_linux
|
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfco…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-19931
|
2024-11-21 12:58 |
2018-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247615
|
4.8 |
MEDIUM
Network
|
zenitel
|
ip-stationweb_firmware
|
Zenitel Norway IP-StationWeb before 4.2.3.9 allows stored XSS via the Display Name for Station Status or Account Settings, related to the goform/zForm_save_changes sip_nick parameter. The password of…
|
CWE-79
Cross-site Scripting
|
CVE-2018-19927
|
2024-11-21 12:58 |
2018-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247616
|
6.1 |
MEDIUM
Network
|
zenitel
|
ip-stationweb_firmware
|
Zenitel Norway IP-StationWeb before 4.2.3.9 allows reflected XSS via the goform/ PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2018-19926
|
2024-11-21 12:58 |
2018-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247617
|
9.8 |
CRITICAL
Network
|
sales_\&_company_management_system_project
|
sales_\&_company_management_system
|
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. It has SQL injection via the member/member_order.php type parameter, related to the O_state parameter.
|
CWE-89
SQL Injection
|
CVE-2018-19925
|
2024-11-21 12:58 |
2018-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247618
|
6.1 |
MEDIUM
Network
|
sales_\&_company_management_system_project
|
sales_\&_company_management_system
|
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. An email address can be modified in between the request for a validation code and the entry of the validation c…
|
CWE-79
Cross-site Scripting
|
CVE-2018-19924
|
2024-11-21 12:58 |
2018-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247619
|
8.8 |
HIGH
Network
|
sales_\&_company_management_system_project
|
sales_\&_company_management_system
|
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is member/member_email.php?action=edit CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2018-19923
|
2024-11-21 12:58 |
2018-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247620
|
5.7 |
MEDIUM
Adjacent
|
qemu opensuse
|
qemu leap
|
The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-19665
|
2024-11-21 12:58 |
2018-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|