Unknown · CVSS Not scored
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.
Published Nov 12, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
LAOBANCMS 2.0 allows install/mysql_hy.php?riqi=../ Directory Traversal.
Published Nov 17, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c.
Published Nov 12, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.
Published Nov 15, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.28) allows SQL Injection via the main.php searchH parameter.
Published Nov 14, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the success.php fort_id parameter.
Published Nov 14, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to the main.php?p=20408 URI.
Published Nov 16, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In LibSass 3.5-stable, there is an illegal address access at Sass::Eval::operator that will lead to a DoS attack.
Published Nov 12, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In LibSass 3.5-stable, there is an illegal address access at Sass::Parser::parse_css_variable_value_token that will lead to a DoS attack.
Published Nov 12, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Memory corruption in PDMODELProvidePDModelHFT in pdmodel.dll in pdfforge PDF Architect 6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of a "Data from Faulting Address controls Code Flow" issue.
Published Nov 10, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ftpuser1 account has a blank password, which cannot be changed.
Published Nov 7, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Netwide Assembler (NASM) 2.14rc15 has a NULL pointer dereference in the function find_label in asm/labels.c that will lead to a DoS attack.
Published Nov 12, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Open Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before 5.0.31 allows an admin to conduct an XSS attack via a modified URL because user and customer preferences are mishandled.
Published Nov 11, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h.
Published Nov 12, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
CloakCoin through 2.2.2.0 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk.
Published Nov 5, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload.
Published Nov 9, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with founder permissions.
Published Nov 17, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
tp4a TELEPORT 3.1.0 allows XSS via the login page because a crafted username is mishandled when an administrator later views the system log.
Published Nov 15, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
stratisX through 2.0.0.5 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk.
Published Nov 5, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
emercoin through 0.7 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends invalid headers/blocks. The attack requires no stake and can fill the victim's disk and RAM.
Published Nov 5, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The exported device configuration is encrypted with the hardcoded Pxift* password in some cases.
Published Nov 7, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In JEESNS 1.3, com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java allows stored XSS via an HTML EMBED element, a different vulnerability than CVE-2018-17886.
Published Nov 11, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Poppler 0.71.0. There is a out-of-bounds read in EmbFile::save2 in FileSpec.cc, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating embedded files before save attempts.
Published Nov 7, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI.
Published Nov 9, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c.
Published Nov 9, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The firewall feature makes it easier for remote attackers to ascertain credentials and firewall rules because invalid credentials lead to error -2, whereas rule-based blocking leads to error -8.
Published Nov 7, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment.
Published Nov 10, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro.
Published Nov 14, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
particl through 0.17 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends invalid headers/blocks. The attack requires no stake and can fill the victim's disk and RAM.
Published Nov 5, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. RtspServer allows remote attackers to cause a denial of service (daemon hang or restart) via a negative integer in the RTSP Content-Length header.
Published Nov 7, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status code and instead writes an unlimited amount of data to the heap.
Published Nov 8, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status Details > Services" screen.
Published Nov 16, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS method allows remote attackers to execute arbitrary OS commands via the IPv4Address field.
Published Nov 7, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
Published Nov 16, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS method allows remote attackers to conduct stack-based buffer overflow attacks via the IPv4Address field.
Published Nov 7, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in DiliCMS 2.4.0. There is a CSRF vulnerability that can delete a user or group via an admin/index.php/user/del/1 or admin/index.php/role/del/2 URI.
Published Nov 15, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13 allows an authenticated user to delete files via a modified submission form because upload caching is mishandled.
Published Nov 11, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue has been found in libIEC61850 v1.3. It is a SEGV in Ethernet_receivePacket in ethernet_bsd.c.
Published Nov 9, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substring that triggers a call to getImage in Image/ImageProcessor.php. NOTE: the software maintainer disputes this, stating "If you allow users to pass HTML without sanitising it, you're asking for trouble.
Published Nov 7, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF.
Published Nov 17, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Open Ticket Request System (OTRS) 6.0.x before 6.0.13 allows an admin to conduct an XSS attack via a modified URL.
Published Nov 11, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.
Published Nov 12, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Divi through 4.0.5 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk.
Published Nov 5, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An XML External Entity (XXE) vulnerability exists in the Charles 4.2.7 import/export setup option. If a user imports a "Charles Settings.xml" file from an attacker, an intranet network may be accessed and information may be leaked.
Published Nov 13, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cmd/evm/runner.go in Go Ethereum (aka geth) 1.8.17 allows attackers to cause a denial of service (SEGV) via crafted bytecode.
Published Nov 12, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The server in mubu note 2018-11-11 has XSS by configuring an account with a crafted name value (along with an arbitrary username value), and then creating and sharing a note.
Published Nov 15, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Phore through 1.3.3.1 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk.
Published Nov 5, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.
Published Nov 12, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement.
Published Nov 14, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with the file upload capability). With this vulnerability, one can automatically upload files (by default, it allows html, pdf, xml, zip, and many other file types). A file can be accessed publicly under the "/assets/files" directory.
Published Nov 11, 2018 · Updated Aug 5, 2024