|
246061
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
phantompdf reader
|
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This rel…
|
CWE-416
Use After Free
|
CVE-2018-17607
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246062
|
7.5 |
HIGH
Network
|
asset_pipeline_project
|
asset-pipeline
|
An issue was discovered in the Asset Pipeline plugin before 3.0.4 for Grails. An attacker can perform directory traversal via a crafted request when a servlet-based application is executed in Jetty, …
|
CWE-22
Path Traversal
|
CVE-2018-17605
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246063
|
7.1 |
HIGH
Local
|
broadcom
|
tcpreplay
|
Tcpreplay v4.3.0 beta1 contains a heap-based buffer over-read. The get_next_packet() function in the send_packets.c file uses the memcpy() function unsafely to copy sequences from the source buffer p…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-17582
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246064
|
6.5 |
MEDIUM
Network
|
exiv2 debian canonical redhat
|
exiv2 debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-17581
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246065
|
7.1 |
HIGH
Local
|
broadcom
|
tcpreplay
|
A heap-based buffer over-read exists in the function fast_edit_packet() in the file send_packets.c of Tcpreplay v4.3.0 beta1. This can lead to Denial of Service (DoS) and potentially Information Expo…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-17580
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246066
|
9.8 |
CRITICAL
Network
|
swa
|
swa.jacad
|
SWA SWA.JACAD 3.1.37 Build 024 has SQL Injection via the /academico/aluno/esqueci-minha-senha/ studentId parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17575
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246067
|
5.4 |
MEDIUM
Network
|
ymfe
|
yapi
|
An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17574
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246068
|
9.8 |
CRITICAL
Network
|
smartlogix
|
wp-insert
|
The Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configuration of FCKeditor under fckeditor/editor/filemanager/browser/default/browser.…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-17573
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246069
|
6.1 |
MEDIUM
Network
|
vanillaforums
|
vanilla
|
Vanilla before 2.6.1 allows XSS via the email field of a profile.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17571
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246070
|
7.5 |
HIGH
Network
|
jekyllrb
|
jekyll
|
Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specifying a symlink in the "include" key in the "_config.yml" file.
|
CWE-59
Link Following
|
CVE-2018-17567
|
2024-11-21 12:54 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|