CVE-2018-20000 to CVE-2018-20999
222 CVEs with public proof-of-concept exploits.
- CVE-2018-200011 PoCIn Libav 12.3, there is a floating point exception in the range_decode_culshift function (called from range_decode_bits) in…
- CVE-2018-200021 PoCThe _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU…
- CVE-2018-200093 PoCsDomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.
- CVE-2018-200103 PoCsDomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.
- CVE-2018-200113 PoCsDomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.
- CVE-2018-200151 PoCYzmCMS v5.2 has admin/role/add.html CSRF.
- CVE-2018-200171 PoCSEMCMS 3.5 has XSS via the first text box to the SEMCMS_Main.php URI.
- CVE-2018-200181 PoCS-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI.
- CVE-2018-200271 PoCThe yaml_parse.load method in Pylearn2 allows code injection.
- CVE-2018-200501 PoCMishandling of an empty string on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of…
- CVE-2018-200626 PoCsKEVAn issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted…
- CVE-2018-200641 PoCdoorGets 7.0 allows remote attackers to write to arbitrary files via directory traversal, as demonstrated by a…
- CVE-2018-200951 PoCAn issue was discovered in EnsureCapacity in Core/Ap4Array.h in Bento4 1.5.1-627. Crafted MP4 input triggers an attempt at excessive…
- CVE-2018-200962 PoCsThere is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead…
- CVE-2018-200972 PoCsThere is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead…
- CVE-2018-200981 PoCThere is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to…
- CVE-2018-200991 PoCThere is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote…
- CVE-2018-201291 PoCAn issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to upload and execute…
- CVE-2018-201331 PoCymlref allows code injection.
- CVE-2018-201381 PoCPHP Scripts Mall Entrepreneur B2B Script 3.0.6 allows Stored XSS via Account Settings fields such as FirstName and LastName, a similar…
- CVE-2018-201401 PoCZenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters.
- CVE-2018-201441 PoCGitLab Community and Enterprise Edition 11.x before 11.3.13, 11.4.x before 11.4.11, and 11.5.x before 11.5.4 has Incorrect Access Control.
- CVE-2018-201471 PoCIn WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files.
- CVE-2018-201483 PoCsIn WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a…
- CVE-2018-201491 PoCIn WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass…
- CVE-2018-201501 PoCIn WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.
- CVE-2018-201511 PoCIn WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual…
- CVE-2018-201521 PoCIn WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.
- CVE-2018-201531 PoCIn WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly…
- CVE-2018-201592 PoCsi-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allows an authenticated…
- CVE-2018-201611 PoCA design flaw in the BlinkForHome (aka Blink For Home) Sync Module 2.10.4 and earlier allows attackers to disable cameras via Wi-Fi,…
- CVE-2018-201623 PoCsDigi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access…
- CVE-2018-201642 PoCsAn issue was discovered in regex.yaml (aka regexes.yaml) in UA-Parser UAP-Core before 0.6.0. A Regular Expression Denial of Service…
- CVE-2018-201662 PoCsA file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image,…
- CVE-2018-201671 PoCTerminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe "cat README.md" command…
- CVE-2018-201721 PoCAn issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not…
- CVE-2018-201741 PoCrdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function ui_clip_handle_data() that results in an…
- CVE-2018-201751 PoCrdesktop versions up to and including v1.8.3 contains several Integer Signedness errors that lead to Out-Of-Bounds Reads in the file mcs.c…
- CVE-2018-201761 PoCrdesktop versions up to and including v1.8.3 contain several Out-Of- Bounds Reads in the file secure.c that result in a Denial of Service…
- CVE-2018-201771 PoCrdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in the function…
- CVE-2018-201781 PoCrdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function process_demand_active() that results in a…
- CVE-2018-201791 PoCrdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function…
- CVE-2018-201801 PoCrdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function…
- CVE-2018-201811 PoCrdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function…
- CVE-2018-201821 PoCrdesktop versions up to and including v1.8.3 contain a Buffer Overflow over the global variables in the function seamless_process_line()…
- CVE-2018-201861 PoCAn issue was discovered in Bento4 1.5.1-627. AP4_Sample::ReadData in Core/Ap4Sample.cpp allows attackers to trigger an attempted excessive…
- CVE-2018-201881 PoCFUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.
- CVE-2018-201892 PoCsIn GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib…
- CVE-2018-201931 PoCCertain Secure Access SA Series SSL VPN products (originally developed by Juniper Networks but now sold and supported by Pulse Secure,…
- CVE-2018-201941 PoCThere is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced…
- CVE-2018-201951 PoCA NULL pointer dereference was discovered in ic_predict of libfaad/ic_predict.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The…
- CVE-2018-201961 PoCThere is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced…
- CVE-2018-201971 PoCThere is a stack-based buffer underflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced…
- CVE-2018-201981 PoCA NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The…
- CVE-2018-201991 PoCA NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The…
- CVE-2018-202001 PoCCertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing…
- CVE-2018-202011 PoCThere is a stack-based buffer over-read in the jsfNameFromString function of jsflash.c in Espruino 2V00, leading to a denial of service or…
- CVE-2018-202112 PoCsExifTool 8.32 allows local users to gain privileges by creating a %TEMP%\par-%username%\cache-exiftool-8.32 folder with a victim's…
- CVE-2018-202182 PoCsAn issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell…
- CVE-2018-202191 PoCAn issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an…
- CVE-2018-202201 PoCAn issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it…
- CVE-2018-202212 PoCsSecure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted…
- CVE-2018-202281 PoCSubsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF.
- CVE-2018-202301 PoCAn issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function read_bytes_internal in…
- CVE-2018-202311 PoCCross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote attackers to disable…
- CVE-2018-2025028 PoCsKEVIn WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format…
- CVE-2018-202511 PoCIn WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format.…
- CVE-2018-202521 PoCIn WinRAR versions prior to and including 5.60, there is an out-of-bounds write vulnerability during parsing of crafted ACE and RAR…
- CVE-2018-202531 PoCIn WinRAR versions prior to and including 5.60, There is an out-of-bounds write vulnerability during parsing of a crafted LHA / LZH…
- CVE-2018-203051 PoCD-Link DIR-816 A2 1.10 B05 devices allow arbitrary remote code execution without authentication via the newpass parameter. In the…
- CVE-2018-203233 PoCswww/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitrary OS commands.
- CVE-2018-203251 PoCThere is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python. It can execute…
- CVE-2018-203263 PoCsChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage=html/index.html…
- CVE-2018-203311 PoCLocal attackers can trigger a Kernel Pool Buffer Overflow in Antiy AVL ATool v1.0.0.22. An attacker must first obtain the ability to…
- CVE-2018-203371 PoCThere is a stack-based buffer overflow in the parse_makernote function of dcraw_common.cpp in LibRaw 0.19.1. Crafted input will lead to a…
- CVE-2018-203431 PoCMultiple buffer overflow vulnerabilities have been found in Ken Silverman Build Engine 1. An attacker could craft a special map file to…
- CVE-2018-203462 PoCsSQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries…
- CVE-2018-203481 PoClibpff_item_tree_create_node in libpff_item_tree.c in libpff before experimental-20180714 allows attackers to cause a denial of service…
- CVE-2018-203491 PoCThe igraph_i_strdiff function in igraph_trie.c in igraph through 0.7.1 has an NULL pointer dereference that allows attackers to cause a…
- CVE-2018-203571 PoCA NULL pointer dereference was discovered in sbr_process_channel of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8.…
- CVE-2018-203581 PoCAn invalid memory address dereference was discovered in the lt_prediction function of libfaad/lt_predict.c in Freeware Advanced Audio…
- CVE-2018-203591 PoCAn invalid memory address dereference was discovered in the sbrDecodeSingleFramePS function of libfaad/sbr_dec.c in Freeware Advanced…
- CVE-2018-203601 PoCAn invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/sbr_dec.c in Freeware Advanced Audio…
- CVE-2018-203611 PoCAn invalid memory address dereference was discovered in the hf_assembly function of libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder…
- CVE-2018-203621 PoCA NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The…
- CVE-2018-203631 PoCLibRaw::raw2image in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.
- CVE-2018-203641 PoCLibRaw::copy_bayer in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.
- CVE-2018-203651 PoCLibRaw::raw2image() in libraw_cxx.cpp has a heap-based buffer overflow.
- CVE-2018-203671 PoCThe "mall some commodity details: commodity consultation" component in WSTMart 2.0.8_181212 has stored XSS via the consultContent…
- CVE-2018-203681 PoCThe Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings…
- CVE-2018-203691 PoCBarracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the…
- CVE-2018-203711 PoCPhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass…
- CVE-2018-203722 PoCsTP-Link TD-W8961ND devices allow XSS via the hostname of a DHCP client.
- CVE-2018-203732 PoCsTenda ADSL modem routers 1.0.1 allow XSS via the hostname of a DHCP client.
- CVE-2018-203771 PoCOrange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi credentials via /get_getnetworkconf.cgi on port 8080, leading…
- CVE-2018-204061 PoCModules/_pickle.c in Python before 3.7.1 has an integer overflow via a large LONG_BINPUT value that is mishandled during a "resize to…
- CVE-2018-204071 PoCAn issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in…
- CVE-2018-204081 PoCAn issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4_StdcFileByteStream::Create in…
- CVE-2018-204091 PoCAn issue was discovered in Bento4 1.5.1-627. There is a heap-based buffer over-read in AP4_AvccAtom::Create in Core/Ap4AvccAtom.cpp, as…
- CVE-2018-204101 PoCWellinTech KingSCADA before 3.7.0.0.1 contains a stack-based buffer overflow. The vulnerability is triggered when sending a specially…
- CVE-2018-204182 PoCsindex.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
- CVE-2018-204191 PoCDouCo DouPHP 1.5 has upload/admin/manager.php?rec=insert CSRF to add an administrator account.
- CVE-2018-204251 PoClibming 0.4.8 has a NULL pointer dereference in the pushdup function of the decompile.c file.
- CVE-2018-204261 PoClibming 0.4.8 has a NULL pointer dereference in the newVar3 function of the decompile.c file, a different vulnerability than CVE-2018-7866.
- CVE-2018-204271 PoClibming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file, a different vulnerability than CVE-2018-9132.
- CVE-2018-204281 PoClibming 0.4.8 has a NULL pointer dereference in the strlenext function of the decompile.c file, a different vulnerability than…
- CVE-2018-204291 PoClibming 0.4.8 has a NULL pointer dereference in the getName function of the decompile.c file, a different vulnerability than CVE-2018-7872…
- CVE-2018-204321 PoCD-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated…
- CVE-2018-204346 PoCsLibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to…
- CVE-2018-204482 PoCsFrog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI.
- CVE-2018-204501 PoCThe read_MSAT function in ole.c in libxls 1.4.0 has a double free that allows attackers to cause a denial of service (application crash)…
- CVE-2018-204511 PoCThe process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a…
- CVE-2018-204521 PoCThe read_MSAT_body function in ole.c in libxls 1.4.0 has an invalid free that allows attackers to cause a denial of service (application…
- CVE-2018-204531 PoCThe getlong function in numutils.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial…
- CVE-2018-204541 PoCAn issue was discovered in 74cms v4.2.111. upload/index.php?c=resume&a=resume_list has XSS via the key parameter.
- CVE-2018-204622 PoCsAn issue was discovered in the JSmol2WP plugin 1.07 for WordPress. A cross-site scripting (XSS) vulnerability allows remote attackers to…
- CVE-2018-204633 PoCsAn issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory…
- CVE-2018-204681 PoCAn issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" that are vulnerable…
- CVE-2018-204693 PoCsAn issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to h2 SQL injection.…
- CVE-2018-204704 PoCsAn issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerability exists in…
- CVE-2018-204723 PoCsAn issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS.
- CVE-2018-204841 PoCZoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.
- CVE-2018-204851 PoCZoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
- CVE-2018-204861 PoCMetInfo 6.x through 6.1.3 has XSS via the /admin/login/login_check.php url_array[] parameter.
- CVE-2018-204871 PoCAn issue was discovered in the firewall3 component in Inteno IOPSYS 1.0 through 3.16. The attacker must make a JSON-RPC method call to add…
- CVE-2018-205021 PoCAn issue was discovered in Bento4 1.5.1-627. There is an attempt at excessive memory allocation in the AP4_DataBuffer class when called…
- CVE-2018-205033 PoCsAllied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter.
- CVE-2018-205121 PoCEPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.
- CVE-2018-205233 PoCsXiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In…
- CVE-2018-205241 PoCThe Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of <<a> in a message, because a danmuWrapper DIV element in…
- CVE-2018-205253 PoCsRoxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
- CVE-2018-205262 PoCsRoxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
- CVE-2018-205351 PoCThere is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service…
- CVE-2018-205381 PoCThere is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service…
- CVE-2018-205411 PoCThere is a heap-based buffer overflow in libxsmm_sparse_csc_reader at generator_spgemm_csc_reader.c in LIBXSMM 1.10, a different…
- CVE-2018-205422 PoCsThere is a heap-based buffer-overflow at generator_spgemm_csc_reader.c (function libxsmm_sparse_csc_reader) in LIBXSMM 1.10, a different…
- CVE-2018-205431 PoCThere is an attempted excessive memory allocation at libxsmm_sparse_csc_reader in generator_spgemm_csc_reader.c in LIBXSMM 1.10 that will…
- CVE-2018-205521 PoCTcpreplay before 4.3.1 has a heap-based buffer over-read in packet2tree in tree.c.
- CVE-2018-205531 PoCTcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c.
- CVE-2018-205551 PoCThe Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token,…
- CVE-2018-205562 PoCsSQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via…
- CVE-2018-205701 PoCjp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
- CVE-2018-205721 PoCWUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords…
- CVE-2018-205731 PoCThe Scanner::EnsureTokensInQueue function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack…
- CVE-2018-205741 PoCThe SingleDocParser::HandleFlowMap function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service…
- CVE-2018-205751 PoCOrange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update. This is related to Firmware…
- CVE-2018-205761 PoCOrange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone…
- CVE-2018-205771 PoCOrange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe,…
- CVE-2018-205802 PoCsThe WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted…
- CVE-2018-205841 PoCJasPer 2.0.14 allows remote attackers to cause a denial of service (application hang) via an attempted conversion to the jp2 format.
- CVE-2018-205881 PoClib/support/unicodeconv/unicodeconv.c in libotfcc.a in otfcc v0.10.3-alpha has a buffer over-read.
- CVE-2018-205911 PoCA heap-based buffer over-read was discovered in decompileJUMP function in util/decompile.c of libming v0.4.8. A crafted input can cause…
- CVE-2018-206081 PoCimcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI.
- CVE-2018-206161 PoCok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_wav_decode_ms_adpcm_data function in ok_wav.c.
- CVE-2018-206171 PoCok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_csv_decode2 function in ok_csv.c.
- CVE-2018-206181 PoCok-file-formats through 2018-10-16 has a heap-based buffer over-read in the ok_mo_decode2 function in ok_mo.c.
- CVE-2018-206211 PoCAn issue was discovered in Microvirt MEmu 6.0.6. The MemuService.exe service binary is vulnerable to local privilege escalation through…
- CVE-2018-206261 PoCPHP Scripts Mall Consumer Reviews Script 4.0.3 has directory traversal via a direct request for a listing of an uploads directory such as…
- CVE-2018-206271 PoCPHP Scripts Mall Consumer Reviews Script 4.0.3 has HTML injection via the search box.
- CVE-2018-206281 PoCPHP Scripts Mall Charity Foundation Script 1 through 3 allows directory traversal via a direct request for a listing of an uploads…
- CVE-2018-206291 PoCPHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal via a direct request for a listing of an uploads…
- CVE-2018-206301 PoCPHP Scripts Mall Advance Crowdfunding Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory such…
- CVE-2018-206311 PoCPHP Scripts Mall Website Seller Script 2.0.5 allows full Path Disclosure via a request for an arbitrary image URL such as a .png file.
- CVE-2018-206321 PoCPHP Scripts Mall Advance B2B Script 2.1.4 has stored Cross-Site Scripting (XSS) via the FIRST NAME or LAST NAME field.
- CVE-2018-206331 PoCPHP Scripts Mall Advance B2B Script 2.1.4 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
- CVE-2018-206341 PoCPHP Scripts Mall Advance B2B Script 2.1.4 allows remote attackers to cause a denial of service (changed Page structure) via JavaScript…
- CVE-2018-206351 PoCPHP Scripts Mall Advance B2B Script 2.1.4 has directory traversal via a direct request for a listing of an image directory such as an…
- CVE-2018-206361 PoCPHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field.
- CVE-2018-206371 PoCPHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 allows remote attackers to cause a denial of service (unrecoverable blank…
- CVE-2018-206381 PoCPHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has directory traversal via a direct request for a listing of an image…
- CVE-2018-206391 PoCPHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has HTML injection via the Search Bar.
- CVE-2018-206401 PoCPHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has stored Cross-Site Scripting (XSS) via the Full Name field.
- CVE-2018-206411 PoCPHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
- CVE-2018-206421 PoCPHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 allows remote attackers to cause a denial of service (outage of profile editing) via…
- CVE-2018-206431 PoCPHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has directory traversal via a direct request for a listing of an image directory…
- CVE-2018-206441 PoCPHP Scripts Mall Basic B2B Script 2.0.9 has Cross-Site Request Forgery (CSRF) via the Edit profile feature.
- CVE-2018-206451 PoCPHP Scripts Mall Basic B2B Script 2.0.9 has HTML injection via the First Name or Last Name field.
- CVE-2018-206461 PoCPHP Scripts Mall Basic B2B Script 2.0.9 has has directory traversal via a direct request for a listing of an image directory such as an…
- CVE-2018-206481 PoCPHP Scripts Mall Car Rental Script 2.0.8 has Cross-Site Request Forgery (CSRF) via accountedit.php.
- CVE-2018-206511 PoCA NULL pointer dereference was discovered in elf_link_add_object_symbols in elflink.c in the Binary File Descriptor (BFD) library (aka…
- CVE-2018-206521 PoCAn attempted excessive memory allocation was discovered in the function tinyexr::AllocateImage in tinyexr.h in tinyexr v0.9.5. Remote…
- CVE-2018-206571 PoCThe demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted…
- CVE-2018-206581 PoCThe server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted…
- CVE-2018-206591 PoCAn issue was discovered in Bento4 1.5.1-627. The AP4_StcoAtom class in Core/Ap4StcoAtom.cpp has an attempted excessive memory allocation…
- CVE-2018-206731 PoCThe demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow…
- CVE-2018-206761 PoCIn Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.
- CVE-2018-206771 PoCIn Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.
- CVE-2018-206811 PoCmate-screensaver before 1.20.2 in MATE Desktop Environment allows physically proximate attackers to view screen content and possibly…
- CVE-2018-207122 PoCsA heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils…
- CVE-2018-207161 PoCCubeCart before 6.1.13 has SQL Injection via the validate[] parameter of the "I forgot my Password!" feature.
- CVE-2018-207171 PoCIn the orders section of PrestaShop before 1.7.2.5, an attack is possible after gaining access to a target store with a user role with the…
- CVE-2018-207181 PoCIn Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to…
- CVE-2018-207353 PoCsAn issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement…
- CVE-2018-207512 PoCsAn issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document,…
- CVE-2018-207531 PoCKEVKaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute…
- CVE-2018-207631 PoCIn GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of…
- CVE-2018-207791 PoCTraq 3.7.1 allows SQL Injection via a tickets?search= URI.
- CVE-2018-207801 PoCTraq 3.7.1 allows admin/users/new CSRF to create an admin account (aka group_id=1).
- CVE-2018-207811 PoCIn pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM…
- CVE-2018-207821 PoCThe GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages.
- CVE-2018-207891 PoCtecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a paths[0] path…
- CVE-2018-207901 PoCtecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0] path traversal…
- CVE-2018-207911 PoCtecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mishandling of the…
- CVE-2018-207921 PoCtecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path parameter, through…
- CVE-2018-207931 PoCtecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path traversal…
- CVE-2018-207941 PoCtecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via path traversal with…
- CVE-2018-207951 PoCtecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path parameter, through…
- CVE-2018-208012 PoCsIn js/parts/SvgRenderer.js in Highcharts JS before 6.1.0, the use of backtracking regular expressions permitted an attacker to conduct a…
- CVE-2018-208061 PoCPhamm (aka PHP LDAP Virtual Hosting Manager) 0.6.8 allows XSS via the login page (the /public/main.php action parameter).
- CVE-2018-208191 PoCio/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based…
- CVE-2018-208201 PoCread_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an…
- CVE-2018-208231 PoCThe gyroscope on Xiaomi Mi 5s devices allows attackers to cause a denial of service (resonance and false data) via a 20.4 kHz audio…
- CVE-2018-208241 PoCThe WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross…
- CVE-2018-208341 PoCA vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when…
- CVE-2018-208351 PoCA vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a…
- CVE-2018-208401 PoCAn unhandled exception vulnerability exists during Google Sign-In with Google API C++ Client before 2019-04-10. It potentially causes an…
- CVE-2018-208412 PoCsHooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell…
- CVE-2018-208481 PoCAdvisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in…
- CVE-2018-208491 PoCArastta eCommerce 1.6.2 is vulnerable to XSS via the PATH_INFO to the login/ URI.
- CVE-2018-209661 PoCThe woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.
- CVE-2018-209691 PoCdo_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for…
- CVE-2018-209851 PoCThe wp-payeezy-pay plugin before 2.98 for WordPress has local file inclusion in pay.php, donate.php, donate-rec, and pay-rec.