|
245581
|
9.8 |
CRITICAL
Network
|
mozilla
|
thunderbird
|
A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediately freed, although the sound is still being played asynchrono…
|
CWE-416
Use After Free
|
CVE-2018-18512
|
2024-11-21 12:56 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245582
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaff…
|
CWE-200
Information Exposure
|
CVE-2018-18511
|
2024-11-21 12:56 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245583
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the loaded page or the browser for test purposes. This issue allows for a non-persist…
|
NVD-CWE-noinfo
|
CVE-2018-18510
|
2024-11-21 12:56 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245584
|
5.3 |
MEDIUM
Network
|
mozilla
|
thunderbird
|
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signatur…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2018-18509
|
2024-11-21 12:56 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245585
|
6.1 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18643
|
2024-11-21 12:56 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245586
|
4.8 |
MEDIUM
Network
|
wolfcms
|
wolf_cms
|
WolfCMS v0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18824
|
2024-11-21 12:56 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245587
|
4.8 |
MEDIUM
Network
|
wolfcms
|
wolf_cms
|
WolfCMS 0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18823
|
2024-11-21 12:56 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245588
|
4.9 |
MEDIUM
Network
|
tp-link
|
wr840n_firmware
|
The ping feature in the Diagnostic functionality on TP-LINK WR840N v2 Firmware 3.16.9 Build 150701 Rel.51516n devices allows remote attackers to cause a denial of service (HTTP service termination) b…
|
NVD-CWE-noinfo
|
CVE-2018-18489
|
2024-11-21 12:56 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245589
|
9.8 |
CRITICAL
Network
|
provisio
|
sitekiosk
|
An elevation of privilege vulnerability exists in the Call Dispatcher in Provisio SiteKiosk before 9.7.4905.
|
NVD-CWE-noinfo
|
CVE-2018-18766
|
2024-11-21 12:56 |
2019-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245590
|
7.8 |
HIGH
Local
|
opera
|
opera_browser
|
Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a malicious DLL to the target. Once the do…
|
CWE-426
Untrusted Search Path
|
CVE-2018-18913
|
2024-11-21 12:56 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|