|
247101
|
6.1 |
MEDIUM
Network
|
sir
|
gnuboard
|
Cross-Site Scripting (XSS) vulnerability in adm/contentformupdate.php in gnuboard5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15580
|
2024-11-21 12:51 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247102
|
8.8 |
HIGH
Network
|
odoo
|
odoo
|
Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges via a crafted request.
|
CWE-863
Incorrect Authorization
|
CVE-2018-15640
|
2024-11-21 12:51 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247103
|
6.1 |
MEDIUM
Network
|
odoo
|
odoo
|
Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote attackers to inject arbitrary web script in the browser of…
|
CWE-79
Cross-site Scripting
|
CVE-2018-15635
|
2024-11-21 12:51 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247104
|
6.5 |
MEDIUM
Network
|
odoo
|
odoo
|
Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to e-mail themselves arbitrary files from the…
|
NVD-CWE-noinfo
|
CVE-2018-15631
|
2024-11-21 12:51 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247105
|
7.5 |
HIGH
Network
|
tp-link
|
tl-wr840n_firmware
|
TP-Link TL-WR840N devices allow remote attackers to cause a denial of service (networking outage) via fragmented packets, as demonstrated by an "nmap -f" command.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15840
|
2024-11-21 12:51 |
2019-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247106
|
6.1 |
MEDIUM
Network
|
sir
|
gnuboard
|
Cross-Site Scripting (XSS) vulnerability in newwinform.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML via the popup title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15585
|
2024-11-21 12:51 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247107
|
5.5 |
MEDIUM
Local
|
faststone
|
image_viewer
|
FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d63 via a crafted image file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15817
|
2024-11-21 12:51 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247108
|
5.5 |
MEDIUM
Local
|
faststone
|
image_viewer
|
FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d7d via a crafted image file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15816
|
2024-11-21 12:51 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247109
|
5.5 |
MEDIUM
Local
|
faststone
|
image_viewer
|
FastStone Image Viewer 6.5 has an Exception Handler Chain Corrupted issue starting at image00400000+0x00000000003ef68a via a crafted image file.
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2018-15815
|
2024-11-21 12:51 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247110
|
5.5 |
MEDIUM
Local
|
faststone
|
image_viewer
|
FastStone Image Viewer 6.5 has a User Mode Write AV starting at image00400000+0x00000000001cb509 via a crafted image file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15814
|
2024-11-21 12:51 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|