Unknown · CVSS Not scored
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to delete a log file via the index.php?m=admin&c=data&a=clear URI.
Published Nov 20, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017.
Published Nov 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The vcpu_scan_ioapic function in arch/x86/kvm/x86.c in the Linux kernel through 4.19.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) via crafted system calls that reach a situation where ioapic is uninitialized.
Published Nov 21, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in bus.py and jsonrpc.py. This connection attempt fails, but it contains in the header the current session of the user. This session could then be stolen by a man-in-the-middle.
Published Nov 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.
Published Nov 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion.
Published Nov 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15. BankMatching.php has Blind SQL injection via the AmtClear_ parameter.
Published Nov 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf_write_int in sndfile.c, which will lead to a denial of service.
Published Nov 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
zb_system/function/lib/upload.php in Z-BlogPHP through 1.5.1 allows remote attackers to execute arbitrary PHP code by using the image/jpeg content type in an upload to the zb_system/admin/index.php?act=UploadMng URI. NOTE: The vendor's position is "We have no dynamic including. No one can run PHP by uploading an image in current version." It also requires authentication
Published Nov 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.
Published Nov 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter.
Published Nov 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Google Monorail before 2018-06-07 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with a crafted groupby value) can be used to obtain sensitive information about the content of bug reports.
Published Nov 20, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty.
Published Nov 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
kvm_pv_send_ipi in arch/x86/kvm/lapic.c in the Linux kernel through 4.19.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) via crafted system calls that reach a situation where the apic map is uninitialized.
Published Nov 21, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
HuCart 5.7.4 has SQL injection in get_ip() in system/class/helper_class.php via the X-Forwarded-For HTTP header to the user/index.php?load=login&act=act_login URI.
Published Nov 23, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.
Published Nov 21, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the Sales component in webERP 4.15. SalesInquiry.php has SQL Injection via the SortBy parameter.
Published Nov 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the Manufacturing component in webERP 4.15. CollectiveWorkOrderCost.php has Blind SQL Injection via the SearchParts parameter.
Published Nov 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.
Published Nov 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used.
Published Nov 21, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a memmove call, as demonstrated by sadf.
Published Nov 21, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call for the com, dotnet, or variant class.
Published Nov 20, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.
Published Nov 21, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Discuz! X3.4 allows XSS via admin.php because admincp/admincp_setting.php and template\default\common\footer.htm mishandles statcode field from third-party stats code.
Published Nov 22, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (Break instruction exception and application crash) via TIFF data because of a ConvertToPDF_x86!ConnectedPDF::ConnectedPDFSDK::FCP_SendEmailNotification issue.
Published Nov 20, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read, access violation, and application crash) via TIFF data because of a ConvertToPDF_x86!ReleaseFXURLToHtml issue.
Published Nov 20, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordPress allows an SEO Manager to perform command execution on the Operating System via a ZIP import.
Published Nov 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (Break instruction exception and application crash) via BMP data because of a ConvertToPDF_x86!ConnectedPDF::ConnectedPDFSDK::FCP_SendEmailNotification issue.
Published Nov 20, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In YXcms 1.4.7, protected/apps/appmanage/controller/indexController.php allow remote authenticated Administrators to execute any PHP code by creating a ZIP archive containing a config.php file, hosting the .zip file at an external URL, and visiting index.php?r=appmanage/index/onlineinstall&url= followed by that URL. This is related to the onlineinstall and import functions.
Published Nov 21, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the MQTT server in Contiki-NG before 4.2. The function parse_publish_vhdr() that parses MQTT PUBLISH messages with a variable length header uses memcpy to input data into a fixed size buffer. The allocated buffer can fit only MQTT_MAX_TOPIC_LENGTH (default 64) bytes, and a length check is missing. This could lead to Remote Code Execution via a stack-smashing attack (overwriting the function return address). Contiki-NG does not separate the MQTT server from other servers and the OS modules, so access to all memory regions is possible.
Published Nov 21, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.
Published Nov 18, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
pkg/sentry/kernel/shm/shm.go in Google gVisor before 2018-11-01 allows attackers to overwrite memory locations in processes running as root (but not escape the sandbox) via vectors involving IPC_RMID shmctl calls, because reference counting is mishandled.
Published Nov 17, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equal to product (for upload destinations under modules/productfiles), order (for upload destinations under modules/files), or cart (for upload destinations under modules/cartfiles).
Published Nov 19, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Guriddo Form PHP 5.3 has XSS via the demos/jqform/defaultnodb/default.php OrderID, ShipName, ShipAddress, ShipCity, ShipPostalCode, ShipCountry, Freight, or details parameter.
Published Nov 17, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In notebook/nbconvert/handlers.py, NbconvertFileHandler and NbconvertPostHandler do not set a Content Security Policy to prevent this.
Published Nov 18, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in S-CMS v1.5. There is a CSRF vulnerability that can add a new user via the admin/ajax.php?type=member&action=add URI.
Published Nov 17, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.
Published Nov 17, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The ansilove_ansi function in loaders/ansi.c in libansilove 1.0.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.
Published Nov 18, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Google Monorail before 2018-05-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with an unsupported axis) can be used to obtain sensitive information about the content of bug reports.
Published Nov 20, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php.
Published Nov 17, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset.
Published Nov 12, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The skin-management feature in tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/user/skin/list directly because controller\usercontroller.java maps a /skin/list request to the function skinList, and lacks an authorization check.
Published Nov 8, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ethereumjs-vm 2.4.0 allows attackers to cause a denial of service (vm.runCode failure and REVERT) via a "code: Buffer.from(my_code, 'hex')" attribute. NOTE: the vendor disputes this because REVERT is a normal bytecode that can be triggered from high-level source code, leading to a normal programmatic execution result.
Published Nov 12, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in S-CMS v1.5. There is a SQL injection vulnerability in search.php via the keyword parameter.
Published Nov 17, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file
Published Nov 14, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In modules/HELPBOT_MODULE in Budabot 0.6 through 4.0, lax syntax validation allows remote attackers to perform a command injection attack against the PHP daemon with a crafted command, resulting in a denial of service or possibly unspecified other impact, as demonstrated by the "!calc 5 x 5" command. In versions before 3.0, modules/HELPBOT_MODULE/calc.php has the vulnerable code; in 3.0 and above, modules/HELPBOT_MODULE/HelpbotController.class.php has the vulnerable code.
Published Nov 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Libav 12.3, there is a heap-based buffer over-read in decode_frame in libavcodec/lcldec.c that allows an attacker to cause denial-of-service via a crafted avi file.
Published Nov 9, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.
Published Nov 12, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.
Published Nov 12, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and ! characters.
Published Nov 12, 2018 · Updated Aug 5, 2024