|
247841
|
7.8 |
HIGH
Local
|
xkbcommon canonical
|
xkbcommon libxkbcommon ubuntu_linux
|
An invalid free in ExprAppendMultiKeysymList in xkbcomp/ast-build.c in xkbcommon before 0.8.1 could be used by local attackers to crash xkbcommon keymap parsers or possibly have unspecified other imp…
|
CWE-416
Use After Free
|
CVE-2018-15857
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247842
|
5.5 |
MEDIUM
Local
|
xkbcommon canonical
|
xkbcommon ubuntu_linux
|
An infinite loop when reaching EOL unexpectedly in compose/parser.c (aka the keymap parser) in xkbcommon before 0.8.1 could be used by local attackers to cause a denial of service during parsing of c…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-15856
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247843
|
5.5 |
MEDIUM
Local
|
xkbcommon_project canonical
|
xkbcommon ubuntu_linux
|
Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because the XkbFil…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-15855
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247844
|
5.5 |
MEDIUM
Local
|
xkbcommon_project canonical
|
xkbcommon ubuntu_linux
|
Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because geometry t…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-15854
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247845
|
5.5 |
MEDIUM
Local
|
xkbcommon canonical
|
xkbcommon libxkbcommon ubuntu_linux
|
Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-15853
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247846
|
6.5 |
MEDIUM
Adjacent
|
technicolor
|
tc7200.20_firmware
|
Technicolor TC7200.20 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof. NOTE: Technicolor denies that the …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-15852
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247847
|
8.8 |
HIGH
Network
|
flexocms_project
|
flexo_cms
|
An issue was discovered in Flexo CMS v0.1.6. There is a CSRF vulnerability that can add an administrator via /admin/user/add.
|
CWE-352
Origin Validation Error
|
CVE-2018-15851
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247848
|
8.8 |
HIGH
Network
|
redaxo
|
redaxo_cms
|
An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via index.php?page=user.
|
CWE-352
Origin Validation Error
|
CVE-2018-15850
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247849
|
4.3 |
MEDIUM
Network
|
portfoliocms_project
|
portfoliocms
|
An issue was discovered in portfolioCMS 1.0.5. There is CSRF to update the website settings via admin/aboutus.php.
|
CWE-352
Origin Validation Error
|
CVE-2018-15849
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247850
|
8.8 |
HIGH
Network
|
portfoliocms_project
|
portfoliocms
|
An issue was discovered in portfolioCMS 1.0.5. There is CSRF to create new pages via admin/portfolio.php?newpage=true.
|
CWE-352
Origin Validation Error
|
CVE-2018-15848
|
2024-11-21 12:51 |
2018-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|