Unknown · CVSS Not scored
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-mmse.c by preventing length overflows.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash. This was addressed in epan/dissectors/packet-dcom.c by adding '\0' termination.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the dissection engine could crash. This was addressed in epan/tvbuff_composite.c by preventing a heap-based buffer over-read.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
libjpeg-turbo 2.0.1 has a heap-based buffer over-read in the put_pixel_rows function in wrbmp.c, as demonstrated by djpeg.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in tp5cms through 2017-05-25. admin.php/upload/picture.html allows remote attackers to execute arbitrary PHP code by uploading a .php file with the image/jpeg content type.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the LBMPDM dissector could crash. In addition, a remote attacker could write arbitrary data to any memory locations before the packet-scoped memory. This was addressed in epan/dissectors/packet-lbmpdm.c by disallowing certain negative values.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer boundary.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the PVFS dissector could crash. This was addressed in epan/dissectors/packet-pvfs2.c by preventing a NULL pointer dereference.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Cesanta Mongoose 6.13, a SIGSEGV exists in the mongoose.c mg_mqtt_add_session() function.
Published Nov 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Interspire Email Marketer through 6.1.6 has SQL Injection via an updateblock sortorder request to Dynamiccontenttags.php
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Dotcms through 5.0.3. Attackers may perform XSS attacks via the inode, identifier, or fieldName parameter in html/js/dotcms/dijit/image/image_tool.jsp.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
JTBC(PHP) 3.0.1.7 has XSS via the console/xml/manage.php?type=action&action=edit content parameter.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a heap-based buffer overflow in the function excluded_channels() in libfaad/syntax.c.
Published Nov 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload in the content parameter.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuration file that is encrypted with the 478DA50BF9E3D2CF key and uploaded through the web GUI by using the web admin account. The default password of admin may be used in some cases.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the PdfXObject, as demonstrated by podofoimpose. It allows an attacker to cause Denial of Service.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
zb_system/admin/index.php?act=UploadMng in Z-BlogPHP 1.5 mishandles file preview, leading to content spoofing. NOTE: the software maintainer disputes that this is a vulnerability
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_rimap function in c-client/imap4r1.c and the tcp_aopen function in osdep/unix/tcp_unix.c) without preventing argument injection, which might allow remote attackers to execute arbitrary OS commands if the IMAP server name is untrusted input (e.g., entered by a user of a web application) and if rsh has been replaced by a program with different argument semantics. For example, if rsh is a link to ssh (as seen on Debian and Ubuntu systems), then the attack can use an IMAP server name containing a "-oProxyCommand" argument.
Published Nov 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an index.php/list/5/?current={pboot:if(evAl($_GET[a]))}1{/pboot:if}&a=phpinfo(); URI, because of an incorrect apps\home\controller\ParserController.php parserIfLabel protection mechanism.
Published Nov 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cpp may cause a denial of service (application crash due to a heap-based buffer over-read) via a crafted PNG file.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In tcpdump 4.9.2, a stack-based buffer over-read exists in the print_prefix function of print-hncp.c via crafted packet data because of missing initialization.
Published Nov 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Interspire Email Marketer through 6.1.6 has SQL Injection via a checkduplicatetags tagname request to Dynamiccontenttags.php.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
JEECMS 9.3 has CSRF via the api/admin/content/save URI to add news.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in SDCMS 1.6 with PHP 5.x. app/admin/controller/themecontroller.php uses a check_bad function in an attempt to block certain PHP functions such as eval, but does not prevent use of preg_replace 'e' calls, allowing users to execute arbitrary code by leveraging access to admin template management.
Published Nov 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a stack-based buffer overflow in the function calculate_gain() in libfaad/sbr_hfadj.c.
Published Nov 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
index.php?r=site%2Flogin in EduSec through 4.2.6 does not restrict sending a series of LoginForm[username] and LoginForm[password] parameters, which might make it easier for remote attackers to obtain access via a brute-force approach.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses java.beans.XMLEncoder unsafely when configured without an xml.codec= setting.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a admin/temp/surveys/ URI.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.0.15, 2.0.16. There is a heap-based buffer over-read of size 8 in the function jas_image_depalettize in libjasper/base/jas_image.c.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a denial of service.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
tp4a TELEPORT 3.1.0 has CSRF via user/do-reset-password to change any password, such as the administrator password.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in arcms through 2018-03-19. SQL injection exists via the json/newslist limit parameter because of ctl/main/Json.php, ctl/main/service/Data.php, and comp/Db/Mysql.php.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Exiv2::isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
Published Nov 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in arcms through 2018-03-19. No authentication is required for index/main, user/useradd, or img/images.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo terminal is used as a backend.
Published Nov 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in the Gdn_Format class.
Published Nov 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There is a NULL pointer dereference in ifilter_bank() in libfaad/filtbank.c.
Published Nov 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses XStream unsafely when configured with an xml.codec=httl.spi.codecs.XstreamCodec setting.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.
Published Nov 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.0.15, 2.0.16. There is a heap-based buffer overflow of size 1 in the function jas_icctxtdesc_input in libjasper/base/jas_icc.c.
Published Nov 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ext/standard/var.c in PHP 5.x through 7.1.24 on Windows allows attackers to cause a denial of service (NULL pointer dereference and application crash) because com and com_safearray_proxy return NULL in com_properties_get in ext/com_dotnet/com_handlers.c, as demonstrated by a serialize call on COM("WScript.Shell").
Published Nov 20, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot postscript terminal is used as a backend.
Published Nov 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
i4 assistant 7.85 allows XSS via a crafted machine name field within iOS settings.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is too large, which allows attackers to cause a denial of service (SEGV on unknown address with READ memory access in a tsk_getu16 call in hfs_dir_open_meta_cb in tsk/fs/hfs_dent.c).
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
TP-Link TL-WR886N 7.0 1.1.0 devices allow remote attackers to cause a denial of service (Tlb Load Exception) via crafted DNS packets to port 53/udp.
Published Nov 26, 2018 · Updated Aug 5, 2024