|
248811
|
9.8 |
CRITICAL
Network
|
info-zip_project
|
zip
|
Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact becau…
|
CWE-416
Use After Free
|
CVE-2018-13410
|
2024-11-21 12:47 |
2018-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248812
|
6.1 |
MEDIUM
Network
|
jirafeau
|
jirafeau
|
An issue was discovered in Jirafeau before 3.4.1. The "search file by hash" form is affected by reflected XSS that could allow, by targeting an administrator, stealing a session and gaining administr…
|
CWE-79
Cross-site Scripting
|
CVE-2018-13409
|
2024-11-21 12:47 |
2018-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248813
|
6.1 |
MEDIUM
Network
|
jirafeau
|
jirafeau
|
An issue was discovered in Jirafeau before 3.4.1. The "search file by link" form is affected by reflected XSS that could allow, by targeting an administrator, stealing a session and gaining administr…
|
CWE-79
Cross-site Scripting
|
CVE-2018-13408
|
2024-11-21 12:47 |
2018-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248814
|
4.9 |
MEDIUM
Network
|
jirafeau
|
jirafeau
|
A CSRF issue was discovered in Jirafeau before 3.4.1. The "delete file" feature on the admin panel is not protected against automated requests and could be abused.
|
CWE-352
Origin Validation Error
|
CVE-2018-13407
|
2024-11-21 12:47 |
2018-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248815
|
7.8 |
HIGH
Local
|
linux canonical debian
|
linux_kernel ubuntu_linux debian_linux
|
An integer overflow in the uvesafb_setcmap function in drivers/video/fbdev/uvesafb.c in the Linux kernel before 4.17.4 could result in local attackers being able to crash the kernel or potentially el…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-13406
|
2024-11-21 12:47 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248816
|
7.8 |
HIGH
Local
|
linux debian canonical fedoraproject redhat f5
|
linux_kernel debian_linux ubuntu_linux fedora enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_se…
|
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certai…
|
CWE-269
Improper Privilege Management
|
CVE-2018-13405
|
2024-11-21 12:47 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248817
|
8.8 |
HIGH
Network
|
fortinet
|
fortios
|
An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via connecting to the ZebOS component.
|
CWE-20
Improper Input Validation
|
CVE-2018-13371
|
2024-11-21 12:46 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248818
|
7.5 |
HIGH
Network
|
easyappointments
|
easy\!appointments
|
Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.
|
CWE-862
Missing Authorization
|
CVE-2018-13063
|
2024-11-21 12:46 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248819
|
6.5 |
MEDIUM
Network
|
easyappointments
|
easy\!appointments
|
Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.
|
CWE-287
Improper Authentication
|
CVE-2018-13060
|
2024-11-21 12:46 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248820
|
6.5 |
MEDIUM
Network
|
totolink
|
a3002ru_firmware
|
In TOTOLINK A3002RU 1.0.8, the router provides a page that allows the user to change their account name and password. This page, password.htm, contains JavaScript which is used to confirm the user kn…
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2018-13313
|
2024-11-21 12:46 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|