|
249001
|
6.1 |
MEDIUM
Network
|
atlassian
|
jira jira_server
|
The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9…
|
CWE-79
Cross-site Scripting
|
CVE-2018-13387
|
2024-11-21 12:47 |
2018-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249002
|
5.5 |
MEDIUM
Local
|
nagios
|
nagios_core
|
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the …
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-13458
|
2024-11-21 12:47 |
2018-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249003
|
5.5 |
MEDIUM
Local
|
nagios
|
nagios_core
|
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the …
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-13457
|
2024-11-21 12:47 |
2018-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249004
|
5.5 |
MEDIUM
Local
|
nagios
|
nagios
|
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload …
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-13441
|
2024-11-21 12:47 |
2018-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249005
|
4.7 |
MEDIUM
Network
|
atlassian
|
confluence
|
The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of applic…
|
CWE-20
Improper Input Validation
|
CVE-2018-13389
|
2024-11-21 12:47 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249006
|
5.4 |
MEDIUM
Network
|
atlassian
|
fisheye crucible
|
The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in …
|
CWE-79
Cross-site Scripting
|
CVE-2018-13388
|
2024-11-21 12:47 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249007
|
6.7 |
MEDIUM
Local
|
supermicro
|
x11ssz_firmware x11ssv_firmware x11ssql_firmware x11ssq_firmware x11ssn_firmware x11srm_firmware x11sra_firmware x11sba_firmware x11sat_firmware x11sae_m_firmware x11sae…
|
Certain Supermicro X11S, X10, X9, X8SI, K1SP, C9X299, C7, B1, A2, and A1 products have a misconfigured Descriptor Region, allowing OS programs to modify firmware.
|
NVD-CWE-noinfo
|
CVE-2018-13787
|
2024-11-21 12:47 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249008
|
6.5 |
MEDIUM
Network
|
libpng canonical oracle redhat
|
libpng ubuntu_linux jdk jre enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG fil…
|
CWE-369 CWE-190
Divide By Zero Integer Overflow or Wraparound
|
CVE-2018-13785
|
2024-11-21 12:47 |
2018-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249009
|
9.1 |
CRITICAL
Network
|
prestashop
|
prestashop
|
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php.
|
NVD-CWE-noinfo
|
CVE-2018-13784
|
2024-11-21 12:47 |
2018-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249010
|
7.5 |
HIGH
Network
|
jiucaitoken_project
|
jiucaitoken
|
The mintToken function of a smart contract implementation for JiucaiToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-13783
|
2024-11-21 12:47 |
2018-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|