|
251901
|
7.5 |
HIGH
Network
|
palletsprojects netapp
|
flask ontap_select_deploy_utility hyper_converged_infrastructure active_iq
|
The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of servi…
|
CWE-20
Improper Input Validation
|
CVE-2018-1000656
|
2024-11-21 12:40 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251902
|
6.5 |
MEDIUM
Network
|
jsish
|
jsish
|
Jsish version 2.4.65 contains a CWE-476: NULL Pointer Dereference vulnerability in Function jsi_ValueCopyMove from jsiValue.c:240 that can result in Crash due to segmentation fault. This attack appea…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-1000655
|
2024-11-21 12:40 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251903
|
5.5 |
MEDIUM
Local
|
gnu
|
libtasn1
|
GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_obje…
|
NVD-CWE-noinfo
|
CVE-2018-1000654
|
2024-11-21 12:40 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251904
|
9.8 |
CRITICAL
Network
|
zzcms
|
zzcms
|
zzcms version 8.3 and earlier contains a SQL Injection vulnerability in zt/top.php line 5 that can result in could be attacked by sql injection in zzcms in nginx. This attack appear to be exploitable…
|
CWE-89
SQL Injection
|
CVE-2018-1000653
|
2024-11-21 12:40 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251905
|
10.0 |
CRITICAL
Network
|
jabref
|
jabref
|
JabRef version <=4.3.1 contains a XML External Entity (XXE) vulnerability in MsBibImporter XML Parser that can result in disclosure of confidential data, denial of service, server side request forger…
|
CWE-611
XXE
|
CVE-2018-1000652
|
2024-11-21 12:40 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251906
|
10.0 |
CRITICAL
Network
|
gchq
|
stroom
|
Stroom version <5.4.5 contains a XML External Entity (XXE) vulnerability in XML Parser that can result in disclosure of confidential data, denial of service, server side request forgery, port scannin…
|
CWE-611
XXE
|
CVE-2018-1000651
|
2024-11-21 12:40 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251907
|
8.8 |
HIGH
Network
|
librehealth
|
librehealth_ehr
|
LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions that can result in Ability to perform malicious database queries. This attack ap…
|
CWE-89
SQL Injection
|
CVE-2018-1000650
|
2024-11-21 12:40 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251908
|
8.8 |
HIGH
Network
|
librehealth
|
librehealth_ehr
|
LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write in letter.php (2) vulnerability in Patient file letter functions that can result in Write files with malicious …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-1000649
|
2024-11-21 12:40 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251909
|
8.8 |
HIGH
Network
|
librehealth
|
librehealth_ehr
|
LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write vulnerability in Patient file letter functions that can result in Write files with malicious content and may le…
|
CWE-269
Improper Privilege Management
|
CVE-2018-1000648
|
2024-11-21 12:40 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251910
|
7.1 |
HIGH
Network
|
librehealth
|
librehealth_ehr
|
LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial of service. This attack appear to be exploitable …
|
CWE-22 CWE-20
Path Traversal Improper Input Validation
|
CVE-2018-1000647
|
2024-11-21 12:40 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|