|
249531
|
9.8 |
CRITICAL
Network
|
sam2p_project
|
sam2p
|
There is a heap-based buffer overflow in bmp_compress1_row in appliers.cpp in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12578
|
2024-11-21 12:45 |
2018-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249532
|
8.8 |
HIGH
Network
|
linaro debian
|
lava debian_linux
|
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote code execution can occur.
|
CWE-20
Improper Input Validation
|
CVE-2018-12565
|
2024-11-21 12:45 |
2018-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249533
|
6.5 |
MEDIUM
Network
|
linaro debian
|
lava debian_linux
|
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on…
|
CWE-20
Improper Input Validation
|
CVE-2018-12564
|
2024-11-21 12:45 |
2018-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249534
|
6.5 |
MEDIUM
Network
|
linaro
|
lava
|
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to download any file from the filesystem if it's readable by lavas…
|
CWE-20
Improper Input Validation
|
CVE-2018-12563
|
2024-11-21 12:45 |
2018-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249535
|
9.8 |
CRITICAL
Network
|
cantata_project
|
cantata
|
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The wrapper script 'mount.cifs.wrapper' uses the shell to forward the arguments to the actual mount.cifs binary.…
|
CWE-20
Improper Input Validation
|
CVE-2018-12562
|
2024-11-21 12:45 |
2018-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249536
|
8.8 |
HIGH
Network
|
cantata_project
|
cantata
|
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. A regular user can inject additional mount options such as file_mode= by manipulating (for example) the domain p…
|
CWE-20
Improper Input Validation
|
CVE-2018-12561
|
2024-11-21 12:45 |
2018-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249537
|
6.5 |
MEDIUM
Network
|
cantata_project
|
cantata
|
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. Arbitrary unmounts can be performed by regular users via directory traversal sequences such as a home/../sys/ker…
|
CWE-22
Path Traversal
|
CVE-2018-12560
|
2024-11-21 12:45 |
2018-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249538
|
8.8 |
HIGH
Network
|
cantata_project
|
cantata
|
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The mount target path check in mounter.cpp `mpOk()` is insufficient. A regular user can consequently mount a CIF…
|
CWE-22
Path Traversal
|
CVE-2018-12559
|
2024-11-21 12:45 |
2018-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249539
|
9.8 |
CRITICAL
Network
|
zuul-ci
|
zuul
|
An issue was discovered in Zuul 3.x before 3.1.0. If nodes become offline during the build, the no_log attribute of a task is ignored. If the unreachable error occurred in a task used with a loop var…
|
CWE-200
Information Exposure
|
CVE-2018-12557
|
2024-11-21 12:45 |
2018-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249540
|
9.8 |
CRITICAL
Network
|
quick_chat_project
|
quick_chat
|
A SQL injection issue was discovered in the Quick Chat plugin before 4.00 for WordPress.
|
CWE-89
SQL Injection
|
CVE-2018-12534
|
2024-11-21 12:45 |
2018-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|