Unknown · CVSS Not scored
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060c4.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
dsmall v20180320 allows XSS via the member search box at the public/index.php/home/membersnsfriend/findlist.html URI.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_x86.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402004.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
CoverCMS v1.1.6 has XSS via the fourth input box to index.php, related to admina/mconfigs.inc.php.
Published Mar 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060d0.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Open-AudIT Professional 2.1 has XSS via a crafted src attribute of an IMG element within a URI.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c. Remote attackers could leverage this vulnerability to cause a crash and denial of service via a crafted mng file.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-26 Q16 does not properly restrict memory allocation, leading to a heap-based buffer over-read.
Published Mar 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402004.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.
Published Mar 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002021.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win7_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402000.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The pm_mallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, as demonstrated by pbmmask.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002002.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002004.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a certain special case of a zero name length, which causes silent omission of hostname verification, and consequently allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. NOTE: the LibreSSL documentation indicates that this special case is supported, but the BoringSSL documentation does not.
Published Mar 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win7_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060cc.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win10_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060cc.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
dsmall v20180320 allows XSS via the main page search box at the public/index.php/home URI.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
dsmall v20180320 allows XSS via the public/index.php/home/predeposit/index.html pdr_sn parameter (aka the CMS search box).
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_x86.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060c4.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_firstone in libjasper/jpc/jpc_math.c.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002006.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002833.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002007.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win7_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c4060d0.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win7_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402004.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd ==" line in the HTML source code. This means, in effect, that authentication occurs only on the client side.
Published Mar 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringFormat out-of-bounds read) via a crafted file.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002008.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl request.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.
Published Mar 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The AMD Ryzen and Ryzen Pro processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-2, RYZENFALL-3, and RYZENFALL-4.
Published Mar 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Exiv2 0.26, the Exiv2::Internal::printCsLensFFFF function in canonmn_int.cpp allows remote attackers to cause a denial of service (invalid memory access) via a crafted file.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002849.
Published Mar 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via the /cgi-bin/cgiServer.exx page parameter, aka absolute path traversal. In some cases, authentication can be achieved via the admin account with its default admin password.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.
Published Mar 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002010.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request.
Published Mar 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.
Published Mar 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In libming 0.4.8, there is a use-after-free in the decompileJUMP function of the decompile.c file.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002005.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf1002001.
Published Mar 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft an HTML page and use it to trick a victim into clicking on it; once executed, a malicious user will be created with admin privileges. This happens due to lack of an anti-CSRF token in state modification requests.
Published Mar 31, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Open-AudIT Professional 2.1. It is possible to inject a malicious payload in the redirect_url parameter to the /login URI to trigger an open redirect. A "data:text/html;base64," payload can be used with JavaScript code.
Published Mar 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorization response page, which might lead to XSS in some configurations.
Published Mar 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient enforcement of Hardware Validated Boot, aka MASTERKEY-1, MASTERKEY-2, and MASTERKEY-3.
Published Mar 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (segmentation fault) via a large attribute section.
Published Mar 22, 2018 · Updated Aug 5, 2024