|
246681
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_opmanager
|
Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged …
|
CWE-89
SQL Injection
|
CVE-2018-17283
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246682
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-17282
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246683
|
9.8 |
CRITICAL
Network
|
arkextensions
|
jck_editor
|
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17254
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246684
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_opmanager
|
Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2018-17243
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246685
|
6.5 |
MEDIUM
Network
|
hdfgroup
|
hdf5
|
A SIGFPE signal is raised in the function H5D__chunk_set_info_real() of H5Dchunk.c in the HDF HDF5 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection agai…
|
CWE-369
Divide By Zero
|
CVE-2018-17237
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246686
|
6.5 |
MEDIUM
Network
|
mp4v2_project
|
mp4v2
|
The function MP4Free() in mp4property.cpp in libmp4v2 2.1.0 internally calls free() on a invalid pointer, raising a SIGABRT signal.
|
CWE-416
Use After Free
|
CVE-2018-17236
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246687
|
6.5 |
MEDIUM
Network
|
mp4v2_project
|
mp4v2
|
The function mp4v2::impl::MP4Track::FinishSdtp() in mp4track.cpp in libmp4v2 2.1.0 mishandles compatibleBrand while processing a crafted mp4 file, which leads to a heap-based buffer over-read, causin…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-17235
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246688
|
6.5 |
MEDIUM
Network
|
hdfgroup
|
hdf5
|
Memory leak in the H5O__chunk_deserialize() function in H5Ocache.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-17234
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246689
|
6.5 |
MEDIUM
Network
|
hdfgroup
|
hdf5
|
A SIGFPE signal is raised in the function H5D__create_chunk_file_map_hyper() of H5Dchunk.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect…
|
CWE-369
Divide By Zero
|
CVE-2018-17233
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246690
|
9.8 |
CRITICAL
Network
|
slack_archivebot_project
|
slack_archivebot
|
SQL injection vulnerability in archivebot.py in docmarionum1 Slack ArchiveBot (aka slack-archive-bot) before 2018-09-19 allows remote attackers to execute arbitrary SQL commands via the text paramete…
|
CWE-89
SQL Injection
|
CVE-2018-17232
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|