|
246671
|
9.8 |
CRITICAL
Network
|
nmealib_project
|
nmealib
|
A stack-based buffer overflow was discovered in the xtimor NMEA library (aka nmealib) 0.5.3. nmea_parse() in parser.c allows an attacker to trigger denial of service (even arbitrary code execution in…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17174
|
2024-11-21 12:54 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246672
|
9.8 |
CRITICAL
Network
|
lg
|
supersign_cms
|
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
|
CWE-94
Code Injection
|
CVE-2018-17173
|
2024-11-21 12:54 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246673
|
5.4 |
MEDIUM
Network
|
espocrm
|
espocrm
|
Stored XSS exists in views/fields/wysiwyg.js in EspoCRM 5.3.6 via a /#Email/view saved draft message.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17302
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246674
|
5.4 |
MEDIUM
Network
|
espocrm
|
espocrm
|
Reflected XSS exists in client/res/templates/global-search/name-field.tpl in EspoCRM 5.3.6 via /#Account in the search panel.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17301
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246675
|
4.8 |
MEDIUM
Network
|
cuppacms
|
cuppacms
|
Stored XSS exists in CuppaCMS through 2018-09-03 via an administrator/#/component/table_manager/view/cu_menus section name.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17300
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246676
|
9.8 |
CRITICAL
Network
|
enalean
|
tuleap
|
An issue was discovered in Enalean Tuleap before 10.5. Reset password links are not invalidated after a user changes its password.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2018-17298
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246677
|
7.5 |
HIGH
Network
|
hutool
|
hutool
|
The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive.
|
CWE-22
Path Traversal
|
CVE-2018-17297
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246678
|
6.5 |
MEDIUM
Network
|
liblouis canonical opensuse
|
liblouis ubuntu_linux leap
|
The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's length, allowing attackers to cause a denial of service (application crash via o…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-17294
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246679
|
8.8 |
HIGH
Network
|
webassembly_virtual_machine_project
|
webassembly_virtual_machine
|
An issue was discovered in WAVM before 2018-09-16. The run function in Programs/wavm/wavm.cpp does not check whether there is Emscripten memory to store the command-line arguments passed by the input…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-17293
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246680
|
6.5 |
MEDIUM
Network
|
webassembly_virtual_machine_project
|
webassembly_virtual_machine
|
An issue was discovered in WAVM before 2018-09-16. The loadModule function in Include/Inline/CLI.h lacks checking of the file length before a file magic comparison, allowing attackers to cause a Deni…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-17292
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|