|
248601
|
8.8 |
HIGH
ネットワーク
|
mitmproxy
|
mitmproxy
|
mitmweb in mitmproxy v4.0.3 allows DNS Rebinding attacks, related to tools/web/app.py.
|
CWE-20
不適切な入力確認
|
CVE-2018-14505
|
2024-11-21 12:49 |
2018-07-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248602
|
9.8 |
CRITICAL
ネットワーク
|
joyplus_project
|
joyplus-cms
|
manager/admin_ajax.php in joyplus-cms 1.6.0 has SQL Injection, as demonstrated by crafted POST data beginning with an "m_id=1 AND SLEEP(5)" substring.
|
CWE-89
SQLインジェクション
|
CVE-2018-14501
|
2024-11-21 12:49 |
2018-07-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248603
|
6.1 |
MEDIUM
ネットワーク
|
joyplus-cms_project
|
joyplus-cms
|
joyplus-cms 1.6.0 has XSS via the manager/collect/collect_vod_zhuiju.php keyword parameter.
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2018-14500
|
2024-11-21 12:49 |
2018-07-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248604
|
7.5 |
HIGH
ネットワーク
|
tendacn
|
ac7_firmware ac9_firmware ac10_firmware ac15_firmware ac18_firmware
|
Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_CN devices have a Stack-based Buffer Overflow via a long limitSpeed or limitSpeedup parameter to an…
|
CWE-787
境界外書き込み
|
CVE-2018-14492
|
2024-11-21 12:49 |
2018-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248605
|
6.1 |
MEDIUM
ネットワーク
|
goodoldweb
|
orange_forum
|
views/auth.go in Orange Forum 1.4.0 allows Open Redirection via the next parameter to /login or /signup.
|
CWE-601
オープンリダイレクト
|
CVE-2018-14474
|
2024-11-21 12:49 |
2018-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248606
|
7.2 |
HIGH
ネットワーク
|
wuzhicms
|
wuzhicms
|
An issue was discovered in WUZHI CMS 4.1.0. The vulnerable file is coreframe/app/order/admin/goods.php. The $keywords parameter is taken directly into execution without any filtering, leading to SQL …
|
CWE-89
SQLインジェクション
|
CVE-2018-14472
|
2024-11-21 12:49 |
2018-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248607
|
6.5 |
MEDIUM
ネットワーク
|
gnu
|
libredwg
|
dwg_obj_block_control_get_block_headers in dwg_api.c in GNU LibreDWG 0.5.1048 allows remote attackers to cause a denial of service (NULL pointer dereference and SEGV) via a crafted dwg file.
|
CWE-476
NULL ポインタデリファレンス
|
CVE-2018-14471
|
2024-11-21 12:49 |
2018-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248608
|
8.8 |
HIGH
ネットワーク
|
hdfgroup
|
hdf5
|
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_sdspace_decode in H5Osdspace.c.
|
CWE-125
境界外読み取り
|
CVE-2018-14460
|
2024-11-21 12:49 |
2018-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248609
|
8.8 |
HIGH
ネットワーク
|
linuxsampler
|
libgig
|
An issue was discovered in libgig 4.1.0. There is an out-of-bounds write in pData[0] access in the function store16 in helper.h.
|
CWE-787
境界外書き込み
|
CVE-2018-14459
|
2024-11-21 12:49 |
2018-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248610
|
8.8 |
HIGH
ネットワーク
|
linuxsampler
|
libgig
|
An issue was discovered in libgig 4.1.0. There is a heap-based buffer overflow in pData[1] access in the function store32 in helper.h.
|
CWE-787
境界外書き込み
|
CVE-2018-14458
|
2024-11-21 12:49 |
2018-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248611
|
8.8 |
HIGH
ネットワーク
|
linuxsampler
|
libgig
|
An issue was discovered in libgig 4.1.0. There is an out-of-bounds write in the function DLS::Info::UpdateChunks in DLS.cpp.
|
CWE-787
境界外書き込み
|
CVE-2018-14457
|
2024-11-21 12:49 |
2018-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248612
|
8.8 |
HIGH
ネットワーク
|
linuxsampler
|
libgig
|
An issue was discovered in libgig 4.1.0. There is an out-of-bounds write in the function DLS::Info::SaveString in DLS.cpp.
|
CWE-787
境界外書き込み
|
CVE-2018-14456
|
2024-11-21 12:49 |
2018-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248613
|
8.8 |
HIGH
ネットワーク
|
linuxsampler
|
libgig
|
An issue was discovered in libgig 4.1.0. There is an out-of-bounds write in pData[0] access in the function store32 in helper.h.
|
CWE-787
境界外書き込み
|
CVE-2018-14455
|
2024-11-21 12:49 |
2018-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248614
|
8.8 |
HIGH
ネットワーク
|
linuxsampler
|
libgig
|
An issue was discovered in libgig 4.1.0. There is an out-of-bounds read in the function RIFF::Chunk::Read in RIFF.cpp.
|
CWE-125
境界外読み取り
|
CVE-2018-14454
|
2024-11-21 12:49 |
2018-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248615
|
8.8 |
HIGH
ネットワーク
|
linuxsampler
|
libgig
|
An issue was discovered in libgig 4.1.0. There is a heap-based buffer overflow in pData[1] access in the function store16 in helper.h.
|
CWE-787
境界外書き込み
|
CVE-2018-14453
|
2024-11-21 12:49 |
2018-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248616
|
8.8 |
HIGH
ネットワーク
|
linuxsampler
|
libgig
|
An issue was discovered in libgig 4.1.0. There is an out-of-bounds read in the "always assign the sample of the first dimension region of this region" feature of the function gig::Region::UpdateChunk…
|
CWE-125
境界外読み取り
|
CVE-2018-14452
|
2024-11-21 12:49 |
2018-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248617
|
8.8 |
HIGH
ネットワーク
|
linuxsampler
|
libgig
|
An issue was discovered in libgig 4.1.0. There is a heap-based buffer overflow in the function RIFF::Chunk::Read in RIFF.cpp.
|
CWE-787
境界外書き込み
|
CVE-2018-14451
|
2024-11-21 12:49 |
2018-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248618
|
8.8 |
HIGH
ネットワーク
|
linuxsampler
|
libgig
|
An issue was discovered in libgig 4.1.0. There is an out-of-bounds read in the "update dimension region's chunks" feature of the function gig::Region::UpdateChunks in gig.cpp.
|
CWE-125
境界外読み取り
|
CVE-2018-14450
|
2024-11-21 12:49 |
2018-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248619
|
8.8 |
HIGH
ネットワーク
|
linuxsampler
|
libgig
|
An issue was discovered in libgig 4.1.0. There is an out of bounds read in gig::File::UpdateChunks in gig.cpp.
|
CWE-125
境界外読み取り
|
CVE-2018-14449
|
2024-11-21 12:49 |
2018-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248620
|
6.5 |
MEDIUM
ネットワーク
|
untrunc_project
|
untrunc
|
Codec::parse in track.cpp in Untrunc through 2018-06-07 has a NULL pointer dereference via a crafted MP4 file because of improper interaction with libav.
|
CWE-476
NULL ポインタデリファレンス
|
CVE-2018-14448
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248621
|
8.8 |
HIGH
ネットワーク
|
libconfuse_project debian
|
libconfuse debian_linux
|
trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read.
|
CWE-125
境界外読み取り
|
CVE-2018-14447
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248622
|
8.8 |
HIGH
ネットワーク
|
techsmith
|
mp4v2
|
MP4Integer32Property::Read in atom_avcC.cpp in MP4v2 2.1.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other i…
|
CWE-787
境界外書き込み
|
CVE-2018-14446
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248623
|
6.5 |
MEDIUM
ネットワーク
|
axiosys
|
bento4
|
In Bento4 v1.5.1-624, AP4_File::ParseStream in Ap4File.cpp allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 file.
|
CWE-835
無限ループ
|
CVE-2018-14445
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248624
|
7.5 |
HIGH
ネットワーク
|
libdxfrw_project
|
libdxfrw
|
libdxfrw 0.6.3 has an Integer Overflow in dwgCompressor::decompress18 in dwgutil.cpp, leading to an out-of-bounds read and application crash.
|
CWE-125 CWE-190
境界外読み取り 整数オーバーフローまたはラップアラウンド
|
CVE-2018-14444
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248625
|
6.5 |
MEDIUM
ネットワーク
|
gnu
|
libredwg
|
get_first_owned_object in dwg.c in GNU LibreDWG 0.5.1036 allows remote attackers to cause a denial of service (SEGV).
|
CWE-119
バッファエラー
|
CVE-2018-14443
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248626
|
9.8 |
CRITICAL
ネットワーク
|
foxitsoftware
|
phantompdf foxit_reader
|
Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.
|
CWE-416
解放済みメモリの使用
|
CVE-2018-14442
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248627
|
6.1 |
MEDIUM
ネットワーク
|
sanscms
|
sanscms
|
blog/index.php in SansCMS 0.7 has XSS via the q parameter.
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2018-14422
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248628
|
8.8 |
HIGH
ネットワーク
|
seacms
|
seacms
|
SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admin_video.php). The code is executed by visiting /de…
|
CWE-352 CWE-94
同一生成元ポリシー違反 コード・インジェクション
|
CVE-2018-14421
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248629
|
8.8 |
HIGH
ネットワーク
|
metinfo
|
metinfo
|
MetInfo 6.0.0 allows a CSRF attack to add a user account via a doaddsave action to admin/index.php, as demonstrated by an admin/index.php?anyid=47&n=admin&c=admin_admin&a=doaddsave URI.
|
CWE-352
同一生成元ポリシー違反
|
CVE-2018-14420
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248630
|
4.8 |
MEDIUM
ネットワーク
|
metinfo
|
metinfo
|
MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2018-14419
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248631
|
9.8 |
CRITICAL
ネットワーク
|
msvod
|
msvod_cms
|
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
|
CWE-89
SQLインジェクション
|
CVE-2018-14418
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248632
|
6.1 |
MEDIUM
ネットワーク
|
icmsdev
|
icms
|
An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen.
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2018-14415
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248633
|
9.8 |
CRITICAL
ネットワーク
|
ssh_companywebsite_project
|
ssh_companywebsite
|
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upload, as demonstrated by a .jsp file with the image…
|
CWE-434
危険なタイプのファイルの無制限アップロード
|
CVE-2018-14441
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248634
|
9.8 |
CRITICAL
ネットワーク
|
ssh_companywebsite_project
|
ssh_companywebsite
|
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. SQL injection exists via the admin/noticeManageAction_queryNotice.action noticeInfo parameter.
|
CWE-89
SQLインジェクション
|
CVE-2018-14440
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248635
|
7.5 |
HIGH
ネットワーク
|
eblock
|
eos4j
|
espritblock eos4j, an unofficial SDK for EOS, through 2018-07-12 mishandles floating-point numbers with more than four digits after the decimal point, which might allow attackers to trigger currency …
|
CWE-682
計算の誤り
|
CVE-2018-14439
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248636
|
7.5 |
HIGH
ネットワーク
|
wireshark
|
wireshark
|
In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which allows attackers to modify the access control arbitra…
|
CWE-20
不適切な入力確認
|
CVE-2018-14438
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248637
|
6.5 |
MEDIUM
ネットワーク
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.8-4 has a memory leak in parse8BIM in coders/meta.c.
|
CWE-772
有効なライフタイム後のリソースの解放の欠如
|
CVE-2018-14437
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248638
|
6.5 |
MEDIUM
ネットワーク
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.8-4 has a memory leak in ReadMIFFImage in coders/miff.c.
|
CWE-772
有効なライフタイム後のリソースの解放の欠如
|
CVE-2018-14436
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248639
|
6.5 |
MEDIUM
ネットワーク
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.8-4 has a memory leak in DecodeImage in coders/pcd.c.
|
CWE-772
有効なライフタイム後のリソースの解放の欠如
|
CVE-2018-14435
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248640
|
6.5 |
MEDIUM
ネットワーク
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c.
|
CWE-772
有効なライフタイム後のリソースの解放の欠如
|
CVE-2018-14434
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248641
|
7.5 |
HIGH
ネットワーク
|
uclouvain debian
|
openjpeg debian_linux
|
Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (appl…
|
CWE-369
ゼロ除算
|
CVE-2018-14423
|
2024-11-21 12:49 |
2018-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248642
|
7.5 |
HIGH
ネットワーク
|
canonical debian xmlsoft
|
ubuntu_linux debian_linux libxml2
|
A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case.…
|
CWE-476
NULL ポインタデリファレンス
|
CVE-2018-14404
|
2024-11-21 12:49 |
2018-07-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248643
|
9.8 |
CRITICAL
ネットワーク
|
techsmith
|
mp4v2
|
MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for associated atoms. The resulting type confusion can cause out-of…
|
CWE-704
不正な型変換またはキャスト
|
CVE-2018-14403
|
2024-11-21 12:49 |
2018-07-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248644
|
9.8 |
CRITICAL
ネットワーク
|
greenpacket
|
dv-360_firmware
|
Green Packet WiMax DV-360 2.10.14-g1.0.6.1 devices allow Command Injection, with unauthenticated remote command execution, via a crafted payload to the HTTPS port, because lighttpd listens on all net…
|
CWE-77
コマンドインジェクション
|
CVE-2018-14067
|
2024-11-21 12:48 |
2020-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248645
|
8.1 |
HIGH
ネットワーク
|
qualcomm
|
apq8053_firmware mdm9205_firmware mdm9206_firmware msm8909w_firmware msm8917_firmware msm8920_firmware msm8937_firmware msm8940_firmware msm8953_firmware sdm450_firmware
|
u'Error in UE due to race condition in EPCO handling' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, M…
|
CWE-362 CWE-476
競合状態 NULL ポインタデリファレンス
|
CVE-2018-13903
|
2024-11-21 12:48 |
2020-09-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248646
|
4.8 |
MEDIUM
ネットワーク
|
seopanel
|
seo_panel
|
The Website Manager module in SEO Panel 3.13.0 and earlier is affected by a stored Cross-Site Scripting (XSS) vulnerability, allowing remote authenticated attackers to inject arbitrary web script or …
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2018-14384
|
2024-11-21 12:48 |
2020-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248647
|
7.8 |
HIGH
ローカル
|
qualcomm
|
apq8009_firmware apq8017_firmware apq8053_firmware apq8096_firmware apq8096au_firmware apq8098_firmware ipq8074_firmware mdm9150_firmware mdm9206_firmware mdm9607_firmware<…
|
Out-of-bounds memory access in Qurt kernel function when using the identifier to access Qurt kernel buffer to retrieve thread data. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sn…
|
CWE-120
古典的バッファオーバーフロー
|
CVE-2018-13916
|
2024-11-21 12:48 |
2019-11-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248648
|
9.1 |
CRITICAL
ネットワーク
|
cospas-sarsat
|
cospas-sarsat_system
|
The COSPAS-SARSAT protocol allows remote attackers to forge messages, replay encrypted messages, conduct denial of service attacks, and send private messages (unrelated to distress alerts) via a craf…
|
CWE-310
暗号の問題
|
CVE-2018-14062
|
2024-11-21 12:48 |
2019-08-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248649
|
6.5 |
MEDIUM
隣接
|
arista
|
eos
|
Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.
|
CWE-287
不適切な認証
|
CVE-2018-14008
|
2024-11-21 12:48 |
2019-08-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248650
|
7.5 |
HIGH
ネットワーク
|
ttpsc
|
the_scheduler
|
The Transition Technologies "The Scheduler" app 5.1.3 for Jira allows XXE due to a weakly configured/parameterized XML parser. It was fixed in the versions 5.2.1 and 3.3.7
|
CWE-611
XML 外部エンティティ参照の不適切な制限
|
CVE-2018-14383
|
2024-11-21 12:48 |
2019-08-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|