|
246311
|
5.5 |
MEDIUM
Local
|
freebsd
|
freebsd
|
In FreeBSD before 11.2-STABLE(r338987), 11.2-RELEASE-p4, and 11.1-RELEASE-p15, due to insufficient memory checking in the freebsd4_getfsstat system call, a NULL pointer dereference can occur. Unprivi…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-17154
|
2024-11-21 12:53 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246312
|
6.1 |
MEDIUM
Network
|
progress
|
sitefinity_cms
|
Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17056
|
2024-11-21 12:53 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246313
|
7.5 |
HIGH
Network
|
progress
|
sitefinity
|
An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-17055
|
2024-11-21 12:53 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246314
|
9.8 |
CRITICAL
Network
|
rausoft
|
id.prove
|
An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST parameter. Hypothetically, an attacker can utilize …
|
CWE-89
SQL Injection
|
CVE-2018-16659
|
2024-11-21 12:53 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246315
|
6.5 |
MEDIUM
Network
|
otrs debian
|
open_ticket_request_system debian_linux
|
In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions op…
|
CWE-20
Improper Input Validation
|
CVE-2018-16587
|
2024-11-21 12:53 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246316
|
6.5 |
MEDIUM
Network
|
iobit
|
advanced_systemcare
|
IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402084) with a buffer containing u…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-16713
|
2024-11-21 12:53 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246317
|
6.5 |
MEDIUM
Network
|
iobit
|
advanced_systemcare
|
IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send a specially crafted IOCTL 0x9C406104 to read phy…
|
CWE-200
Information Exposure
|
CVE-2018-16712
|
2024-11-21 12:53 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246318
|
8.8 |
HIGH
Network
|
iobit
|
advanced_systemcare
|
IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402088) with a buffer containing u…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-16711
|
2024-11-21 12:53 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246319
|
7.8 |
HIGH
Local
|
suse
|
shadow
|
Privilege escalation can occur in the SUSE useradd.c code in useradd, as distributed in the SUSE shadow package through 4.2.1-27.9.1 for SUSE Linux Enterprise 12 (SLE-12) and through 4.5-5.39 for SUS…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-16588
|
2024-11-21 12:53 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246320
|
4.3 |
MEDIUM
Network
|
e107
|
e107
|
e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbitrary page.
|
CWE-352
Origin Validation Error
|
CVE-2018-17081
|
2024-11-21 12:53 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|