Unknown · CVSS Not scored
ok-file-formats through 2018-10-16 has a heap-based buffer overflow in the ok_wav_decode_ms_adpcm_data function in ok_wav.c.
Published Dec 31, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 has XSS via the Administrator/add_pictures.php article ID.
Published Dec 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 has XSS via the Administrator/users.php user ID.
Published Dec 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a Profile field such as Company Address, a related issue to CVE-2018-15896.
Published Dec 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a NULL pointer dereference at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that will cause a denial of service.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.beta19.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for 24bpp data.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects the test suite and not the underlying library. It cannot be exploited in any real-world application
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 1bpp data.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Orange Livebox 00.96.320S devices allow cgi-bin/autodialing.exe and cgi-bin/phone_test.exe CSRF, leading to arbitrary outbound telephone calls to an attacker-specified telephone number. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to construction of invalid rich media annotation assets in the AnnotRichMedia class in Annot.c.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe, and cgi-bin/upgradep.exe CSRF. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during a line-number increment attempt.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a heap-based buffer over-read at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that will cause a denial of service.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a Segmentation fault triggered by illegal address access at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that will cause a denial of service.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
MiniCMS V1.10 has XSS via the mc-admin/post-edit.php query string, a related issue to CVE-2018-10296 and CVE-2018-16233.
Published Dec 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a heap-based buffer-overflow at generator_spgemm_csc_reader.c (function libxsmm_sparse_csc_reader) in LIBXSMM 1.10, a different vulnerability than CVE-2018-20541 (which is in a different part of the source code and is seen at a different address).
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is memory leak at liblas::Open (liblas/liblas.hpp) in libLAS 1.8.1.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
Published Dec 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a NULL pointer dereference at ext/testcase.c (function testcase_read) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is an attempted excessive memory allocation at libxsmm_sparse_csc_reader in generator_spgemm_csc_reader.c in LIBXSMM 1.10 that will cause a denial of service.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in S-CMS 1.0. It allows reading certain files, such as PHP source code, via the admin/download.php DownName parameter with a mixed-case extension, as demonstrated by a DownName=download.Php value.
Published Dec 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the jsmol.php data parameter.
Published Dec 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a heap-based buffer overflow in libxsmm_sparse_csc_reader at generator_spgemm_csc_reader.c in LIBXSMM 1.10, a different vulnerability than CVE-2018-20542 (which is in a different part of the source code and is seen at different addresses).
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control (issue 2 of 6).
Published Dec 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes a cleartext username and password to be displayed in a URI field.
Published Dec 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during certain finishes tests.
Published Dec 28, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
Published Dec 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in S-CMS 1.0. It allows SQL Injection via the wap_index.php?type=newsinfo S_id parameter.
Published Dec 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.
Published Dec 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GitLab Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the Linux kernel before 4.18.11. The ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain sensitive kernel address information by leveraging CAP_NET_ADMIN to read the ipddp_route dev and next fields via an SIOCFINDIPDDPRT ioctl call.
Published Dec 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-service (application crash via an r_num_calc out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20459.
Published Dec 25, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in S-CMS 3.0. It allows SQL Injection via the bank/callback1.php P_no field.
Published Dec 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
Published Dec 30, 2019 · Updated Aug 5, 2024