|
247091
|
8.8 |
HIGH
Network
|
weaselcms_project
|
weaselcms
|
An issue was discovered in WeaselCMS v0.3.5. CSRF can update the website settings (such as the theme, title, and description) via index.php.
|
CWE-352
Origin Validation Error
|
CVE-2018-14958
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247092
|
6.1 |
MEDIUM
Network
|
squirrelmail
|
squirrelmail
|
The mail message display page in SquirrelMail through 1.4.22 has XSS via SVG animations (animate to attribute).
|
CWE-79
Cross-site Scripting
|
CVE-2018-14955
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247093
|
6.1 |
MEDIUM
Network
|
squirrelmail
|
squirrelmail
|
The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14954
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247094
|
6.1 |
MEDIUM
Network
|
squirrelmail
|
squirrelmail
|
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14953
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247095
|
6.1 |
MEDIUM
Network
|
squirrelmail
|
squirrelmail
|
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math><maction xlink:href=" attack.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14952
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247096
|
6.1 |
MEDIUM
Network
|
squirrelmail
|
squirrelmail
|
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14951
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247097
|
6.1 |
MEDIUM
Network
|
squirrelmail
|
squirrelmail
|
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14950
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247098
|
7.8 |
HIGH
Local
|
sound_project
|
sound
|
An issue has been found in dilawar sound through 2017-11-27. The end of openWavFile in wav-file.cc has Mismatched Memory Management Routines (operator new [] versus operator delete).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14948
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247099
|
8.8 |
HIGH
Network
|
flowpaper
|
pdf2json
|
An issue has been found in PDF2JSON 0.69. XmlFontAccu::CSStyle in XmlFonts.cc has Mismatched Memory Management Routines (operator new [] versus operator delete).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14947
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247100
|
8.8 |
HIGH
Network
|
flowpaper
|
pdf2json
|
An issue has been found in PDF2JSON 0.69. The HtmlString class in ImgOutputDev.cc has Mismatched Memory Management Routines (malloc versus operator delete).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14946
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|