CVE-2018-8000 to CVE-2018-8999
172 CVEs with public proof-of-concept exploits.
- CVE-2018-80002 PoCsIn PoDoFo 0.9.5, there exists a heap-based buffer overflow vulnerability in PoDoFo::PdfTokenizer::GetNextToken() in PdfTokenizer.cpp, a…
- CVE-2018-80021 PoCIn PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may…
- CVE-2018-80041 PoCThere are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server…
- CVE-2018-80061 PoCAn instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp…
- CVE-2018-80071 PoCApache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of…
- CVE-2018-80111 PoCmod_md, DoS via Coredumps on specially crafted requests
- CVE-2018-80212 PoCsVersions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code…
- CVE-2018-80231 PoCApache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos…
- CVE-2018-80241 PoCIn Apache Spark 2.1.0 to 2.1.2, 2.2.0 to 2.2.1, and 2.3.0, it's possible for a malicious user to construct a URL pointing to a Spark…
- CVE-2018-80321 PoCApache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
- CVE-2018-80335 PoCsIn Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP…
- CVE-2018-80351 PoCThis vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<=…
- CVE-2018-80381 PoCVersions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity…
- CVE-2018-80391 PoCIt is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs",…
- CVE-2018-80411 PoCApache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
- CVE-2018-80451 PoCIn Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the…
- CVE-2018-80561 PoCPhysical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to…
- CVE-2018-80572 PoCsA SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a…
- CVE-2018-80581 PoCCMS Made Simple (CMSMS) 2.2.6 has XSS in admin/moduleinterface.php via the pagedata parameter.
- CVE-2018-80601 PoCHWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send an IOCTL to the device driver. If input and/or…
- CVE-2018-80611 PoCHWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send IOCTL 0x85FE2608 to the device driver with the…
- CVE-2018-80622 PoCsA cross-site scripting (XSS) vulnerability on Comtrend AR-5387un devices with A731-410JAZ-C04_R02.A2pD035g.d23i firmware allows remote…
- CVE-2018-80653 PoCsAn issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access violation on the…
- CVE-2018-80721 PoCAn issue was discovered on EDIMAX IC-3140W through 3.06, IC-5150W through 3.09, and IC-6220DC through 3.06 devices. The ipcam_cgi binary…
- CVE-2018-80901 PoCQuick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00…
- CVE-2018-80962 PoCsDatalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via…
- CVE-2018-80972 PoCsio/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where…
- CVE-2018-81081 PoCThe select component in bui through 2018-03-13 has XSS because it performs an escape operation on already-escaped text, as demonstrated by…
- CVE-2018-812015 PoCsKEVAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka…
- CVE-2018-81331 PoCA remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka…
- CVE-2018-81341 PoCAn elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of…
- CVE-2018-81391 PoCA remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka…
- CVE-2018-81451 PoCAn information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an…
- CVE-2018-81721 PoCA remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an…
- CVE-2018-817412 PoCsKEVA remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine…
- CVE-2018-82082 PoCsAn elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows…
- CVE-2018-82142 PoCsAn elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows…
- CVE-2018-82291 PoCA remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka…
- CVE-2018-82691 PoCA denial of service vulnerability exists when OData Library improperly handles web requests, aka "OData Denial of Service Vulnerability."…
- CVE-2018-82791 PoCA remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory…
- CVE-2018-82841 PoCA remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework…
- CVE-2018-82881 PoCA remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka…
- CVE-2018-82911 PoCA remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka…
- CVE-2018-82981 PoCKEVA remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting…
- CVE-2018-83532 PoCsA remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka…
- CVE-2018-83551 PoCA remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka…
- CVE-2018-83841 PoCA remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka…
- CVE-2018-83892 PoCsA remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka…
- CVE-2018-84102 PoCsAn elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory, aka "Windows…
- CVE-2018-84111 PoCAn elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This…
- CVE-2018-84131 PoCA remote code execution vulnerability exists when "Windows Theme API" does not properly decompress files, aka "Windows Theme API Remote…
- CVE-2018-84141 PoCKEVA remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code…
- CVE-2018-84201 PoCA remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote…
- CVE-2018-84232 PoCsA remote code execution vulnerability exists in the Microsoft JET Database Engine, aka "Microsoft JET Database Engine Remote Code…
- CVE-2018-84404 PoCsKEVAn elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows…
- CVE-2018-84491 PoCA security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass…
- CVE-2018-84536 PoCsKEVAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka…
- CVE-2018-84631 PoCAn elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in…
- CVE-2018-84661 PoCA remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka…
- CVE-2018-84671 PoCA remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka…
- CVE-2018-84681 PoCAn elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privilege…
- CVE-2018-84691 PoCAn elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in…
- CVE-2018-84742 PoCsA security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for…
- CVE-2018-84952 PoCsA remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka "Windows Shell Remote Code Execution…
- CVE-2018-85271 PoCAn information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file…
- CVE-2018-85321 PoCAn information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file…
- CVE-2018-85331 PoCAn information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content…
- CVE-2018-85441 PoCA remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine…
- CVE-2018-85501 PoCAn elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerability." This affects…
- CVE-2018-85521 PoCAn information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an…
- CVE-2018-85812 PoCsKEVAn elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege…
- CVE-2018-85841 PoCAn elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows…
- CVE-2018-85871 PoCA remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka…
- CVE-2018-86112 PoCsKEVAn elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel…
- CVE-2018-86173 PoCsA remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka…
- CVE-2018-86191 PoCA remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly restrict VBScript…
- CVE-2018-86251 PoCA remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine…
- CVE-2018-86311 PoCA remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory…
- CVE-2018-86392 PoCsKEVAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka…
- CVE-2018-87153 PoCsThe Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c.…
- CVE-2018-87163 PoCsWSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
- CVE-2018-87182 PoCsCross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send…
- CVE-2018-87192 PoCsAn issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/*…
- CVE-2018-87272 PoCsPath Traversal in Gateway in Mirasys DVMS Workstation 5.12.6 and earlier allows an attacker to traverse the file system to access files or…
- CVE-2018-87292 PoCsMultiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote attackers to inject…
- CVE-2018-87321 PoCCross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the…
- CVE-2018-87333 PoCsAuthentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated…
- CVE-2018-87343 PoCsSQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute…
- CVE-2018-87353 PoCsRemote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary…
- CVE-2018-87363 PoCsA privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability…
- CVE-2018-87371 PoCBookme Control Panel 2.0 Application is vulnerable to stored XSS within the Customers "Book Me" function. Within the Name and Note (aka…
- CVE-2018-87381 PoCAirties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS.
- CVE-2018-87631 PoCRoland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the…
- CVE-2018-87641 PoCRoland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it…
- CVE-2018-87651 PoCIn 2345 Security Guard 3.6, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-87691 PoCelfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_SHNDX is…
- CVE-2018-87704 PoCsPhysical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php,…
- CVE-2018-87721 PoCCoship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen.
- CVE-2018-87841 PoCFreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress_segment() that results in a memory…
- CVE-2018-87851 PoCFreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress() that results in a memory corruption…
- CVE-2018-87861 PoCFreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function…
- CVE-2018-87871 PoCFreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function…
- CVE-2018-87881 PoCFreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nsc_rle_decode() that results in a memory…
- CVE-2018-87891 PoCFreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results in a Denial of…
- CVE-2018-88051 PoCYxcms building system (compatible cell phone) v1.4.7 has XSS via the content parameter to…
- CVE-2018-88061 PoCIn libming 0.4.8, there is a use-after-free in the decompileArithmeticOp function of decompile.c. Remote attackers could use this…
- CVE-2018-88071 PoCIn libming 0.4.8, these is a use-after-free in the function decompileCALLFUNCTION of decompile.c. Remote attackers could leverage this…
- CVE-2018-88081 PoCIn radare2 2.4.0, there is a heap-based buffer over-read in the r_asm_disassemble function of asm.c. Remote attackers could leverage this…
- CVE-2018-88091 PoCIn radare2 2.4.0, there is a heap-based buffer over-read in the dalvik_op function of anal_dalvik.c. Remote attackers could leverage this…
- CVE-2018-88101 PoCIn radare2 2.4.0, there is a heap-based buffer over-read in the get_ivar_list_t function of mach0_classes.c. Remote attackers could…
- CVE-2018-88111 PoCCross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allows remote attackers…
- CVE-2018-88131 PoCOpen redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect…
- CVE-2018-88141 PoCCross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for…
- CVE-2018-88151 PoCCross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to inject arbitrary web…
- CVE-2018-88171 PoCWampserver before 3.1.3 has CSRF in add_vhost.php.
- CVE-2018-88202 PoCsAn issue was discovered in Square 9 GlobalForms 6.2.x. A Time Based SQL injection vulnerability in the "match" parameter allows remote…
- CVE-2018-88211 PoCwindrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a crafted .exe file.
- CVE-2018-88232 PoCsmodules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0…
- CVE-2018-88241 PoCmodules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0…
- CVE-2018-88312 PoCsA Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the…
- CVE-2018-88731 PoCIn 2345 Security Guard 3.6, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-88741 PoCIn 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-88751 PoCIn 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-88761 PoCIn 2345 Security Guard 3.6, the driver file (2345Wrath.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-88801 PoCLutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing the /deviceIP…
- CVE-2018-88941 PoCIn 2345 Security Guard 3.6, the driver file (2345BdPcSafe.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-88951 PoCIn 2345 Security Guard 3.6, the driver file (2345DumpBlock.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-88961 PoCIn 2345 Security Guard 3.6, the driver file (2345DumpBlock.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-88977 PoCsA statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in…
- CVE-2018-88982 PoCsA flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012"…
- CVE-2018-89032 PoCsOpen-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.
- CVE-2018-89041 PoCIn Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial…
- CVE-2018-89052 PoCsIn LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF file, as…
- CVE-2018-89061 PoCdsmall v20180320 has XSS via a crafted street address to public/index.php/home/memberaddress/index.html, which is mishandled at…
- CVE-2018-89081 PoCAn issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious…
- CVE-2018-89091 PoCThe Wire application before 2018-03-07 for Android allows attackers to write to pathnames outside of the downloads directory via a ../ in…
- CVE-2018-89371 PoCAn issue was discovered in Open-AudIT Professional 2.1. It is possible to inject a malicious payload in the redirect_url parameter to the…
- CVE-2018-89401 PoCClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and…
- CVE-2018-89411 PoCDiagnostics functionality on D-Link DSL-3782 devices with firmware EU v. 1.01 has a buffer overflow, allowing authenticated remote…
- CVE-2018-89451 PoCThe bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30,…
- CVE-2018-89472 PoCsrap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote…
- CVE-2018-89551 PoCThe installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which…
- CVE-2018-89601 PoCThe ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-26 Q16 does not properly restrict memory allocation, leading to a…
- CVE-2018-89611 PoCIn libming 0.4.8, the decompilePUSHPARAM function of decompile.c has a use-after-free. Remote attackers could leverage this vulnerability…
- CVE-2018-89621 PoCIn libming 0.4.8, the decompileSingleArgBuiltInFunctionCall function of decompile.c has a use-after-free. Remote attackers could leverage…
- CVE-2018-89631 PoCIn libming 0.4.8, the decompileGETVARIABLE function of decompile.c has a use-after-free. Remote attackers could leverage this…
- CVE-2018-89641 PoCIn libming 0.4.8, the decompileDELETE function of decompile.c has a use-after-free. Remote attackers could leverage this vulnerability to…
- CVE-2018-89651 PoCAn issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory traversal sequences…
- CVE-2018-89661 PoCAn issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by…
- CVE-2018-89671 PoCAn issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request.
- CVE-2018-89681 PoCAn issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory traversal sequences…
- CVE-2018-89691 PoCAn issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via directory traversal…
- CVE-2018-89701 PoCThe int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a certain special…
- CVE-2018-89731 PoCOTCMS 3.20 allows XSS by adding a keyword or link to an article, as demonstrated by an admin/keyWord_deal.php?mudi=add request.
- CVE-2018-89741 PoCCenters for Disease Control and Prevention MicrobeTRACE 0.1.11 allows remote attackers to execute arbitrary code, related to code…
- CVE-2018-89751 PoCThe pm_mallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 allows remote attackers to cause a denial of service…
- CVE-2018-89761 PoCIn Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringFormat out-of-bounds…
- CVE-2018-89771 PoCIn Exiv2 0.26, the Exiv2::Internal::printCsLensFFFF function in canonmn_int.cpp allows remote attackers to cause a denial of service…
- CVE-2018-89781 PoCOpen-AudIT Professional 2.1 has XSS via a crafted src attribute of an IMG element within a URI.
- CVE-2018-89792 PoCsOpen-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI.
- CVE-2018-89881 PoCIn Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial…
- CVE-2018-89891 PoCIn Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial…
- CVE-2018-89901 PoCIn Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial…
- CVE-2018-89911 PoCIn Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial…
- CVE-2018-89921 PoCIn Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial…
- CVE-2018-89931 PoCIn Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial…
- CVE-2018-89941 PoCIn Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial…
- CVE-2018-89951 PoCIn Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial…
- CVE-2018-89961 PoCIn Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial…
- CVE-2018-89971 PoCIn Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial…
- CVE-2018-89981 PoCIn Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_x86.sys) allows local users to cause a denial of service (BSOD) or…
- CVE-2018-89991 PoCIn Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win7_x64.sys) allows local users to cause a denial of service (BSOD)…