Unknown · CVSS Not scored
ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrated by a crafted window.open call.
Published May 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The mobi_decompress_huffman_internal function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file.
Published May 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.
Published May 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentially sensitive information about the specific times when alarm-system events occur.
Published May 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in BearAdmin 0.5. Remote attackers can download arbitrary files via /admin/databack/download.html?name= directory traversal sequences, as demonstrated by name=../application/database.php to read the MySQL credentials in the configuration.
Published May 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted audio file.
Published May 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in /classes/profile.class.php in Jigowatt "PHP Login & User Management" before 4.1.1, as distributed in the Envato Market, allows any remote authenticated user to upload .php files to the web server via a profile avatar field. This results in arbitrary code execution by requesting the .php file.
Published May 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The buffer_addraw function in buffer.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.
Published May 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a dedicated inode.
Published May 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The mobi_decompress_lz77 function in compression.c in Libmobi 0.3 allows remote attackers to cause remote code execution (heap-based buffer overflow) via a crafted mobi file.
Published May 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The string_scan_range() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.
Published May 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
jpegoptim.c in jpegoptim 1.4.5 (fixed in 1.4.6) has an invalid use of realloc() and free(), which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
Published May 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
SimpliSafe Original has Unencrypted Keypad Transmissions, which allows physically proximate attackers to discover the PIN.
Published May 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The mobi_reconstruct_parts function in parse_rawml.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file.
Published May 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Kliqqi 2.0.2 has CSRF in admin/admin_users.php.
Published May 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in BearAdmin 0.5. There is admin/admin_log/index.html?user_id= SQL injection because admin\controller\AdminLog.php constructs a MySQL query improperly.
Published May 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The sh_op() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted ELF file.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In SimpliSafe Original, the Base Station fails to detect tamper attempts: it does not send a notification if a physically proximate attacker removes the battery and external power.
Published May 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In SimpliSafe Original, RF Interference (e.g., an extremely strong 433.92 MHz signal) by a physically proximate attacker does not cause a notification.
Published May 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the RRC dissector and other dissectors could crash. This was addressed in epan/proto.c by avoiding a NULL pointer dereference.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the Q.931 dissector could crash. This was addressed in epan/dissectors/packet-q931.c by avoiding a use-after-free after a malformed packet prevented certain cleanup.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Liblouis 3.5.0. A invalid free in the compileRule function in compileTranslationTable.c allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
Published May 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
sav_parse_machine_integer_info_record in spss/readstat_sav_read.c in libreadstat.a in ReadStat 0.1.1 has a memory leak related to an iconv_open call.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The r_read_le32() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted ELF file.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.6.0, the IEEE 1905.1a dissector could crash. This was addressed in epan/dissectors/packet-ieee1905.c by making a certain correction to string handling.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The r_strbuf_fini() function in radare2 2.5.0 allows remote attackers to cause a denial of service (invalid free and application crash) via a crafted ELF file because of an uninitialized variable in the CPSE handler in libr/anal/p/anal_avr.c.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The get_debug_info() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted PE file.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The _inst__lds() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted Mach-O file.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The _inst__sts() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The transferFrom function of a smart contract implementation for DimonCoin (FUD), an Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer all victims' balances into their account) because certain computations involving _value are incorrect.
Published May 24, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.6.0, the RTCP dissector could crash. This was addressed in epan/dissectors/packet-rtcp.c by avoiding a buffer overflow for packet status chunks.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact via a crafted WASM file.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
sas/readstat_sas7bcat_read.c in libreadstat.a in ReadStat 0.1.1 has an infinite loop.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.6.0, the IEEE 802.11 protocol dissector could crash. This was addressed in epan/crypt/dot11decrypt.c by avoiding a buffer overflow during FTE processing in Dot11DecryptTDLSDeriveKey.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissector could crash. This was addressed in epan/dissectors/packet-gsm_a_dtap.c by fixing an off-by-one error that caused a buffer overflow.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by avoiding a buffer over-read upon encountering a missing '\0' character.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the DNS dissector could crash. This was addressed in epan/dissectors/packet-dns.c by avoiding a NULL pointer dereference for an empty name in an SRV record.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The avr_op_analyze() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
jpeg_size in pdfgen.c in PDFGen before 2018-04-09 has a heap-based buffer over-read.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could consume excessive memory. This was addressed in epan/tvbuff.c by rejecting negative lengths.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A persistent cross site scripting vulnerability in playlistmanger.cgi in the ASUSTOR SoundsGood application allows attackers to store cross site scripting payloads via the 'playlist' POST parameter.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An unrestricted file upload vulnerability in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data to a specified filename. This can be used to place attacker controlled code on the file system that is then executed.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An insecure direct object reference vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows the ability to reference the "download_sys_settings" action and then specify files arbitrarily throughout the system via the act parameter.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Blind SQL injection in coupon_code in the MemberMouse plugin 2.2.8 and prior for WordPress allows an unauthenticated attacker to dump the WordPress MySQL database via an applyCoupon action in an admin-ajax.php request.
Published May 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Directory traversal in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to navigate the file system via the filename parameter.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The DrugDealer function of a smart contract implementation for Ether Cartel, an Ethereum game, allows attackers to take over the contract's ownership, aka ceoAnyone. After that, all the digital assets (including Ether balance and tokens) might be manipulated by the attackers, as exploited in the wild in May 2018.
Published May 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials.
Published May 20, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext password for the administrator account at the confirmation screen.
Published May 22, 2018 · Updated Aug 5, 2024