Latest CVE Feed
-
9.8
CRITICALCVE-2018-14939
The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in certain environments such as FreeBSD libc, which might allow attackers to cause a denial of service (buffer overflow and application c... Read more
Affected Products : libreoffice- Published: Aug. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5175
During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepath, leading to a potentially exploitable crash. This vulnerability affects Firefox < 118.... Read more
Affected Products : firefox- Published: Sep. 27, 2023
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2018-14817
Fuji Electric V-Server 4.0.3.0 and prior, An integer underflow vulnerability has been identified, which may allow remote code execution.... Read more
- Published: Sep. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14818
WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior have a stack-based buffer overflow vulnerability which may allow remote code execution.... Read more
- Published: Oct. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14823
Fuji Electric V-Server 4.0.3.0 and prior, A stack-based buffer overflow vulnerability has been identified, which may allow remote code execution.... Read more
- Published: Sep. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14981
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control for SystemUI application intents. The LG ID is LVE-SMP-180005.... Read more
- Published: Aug. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14809
Fuji Electric V-Server 4.0.3.0 and prior, A use after free vulnerability has been identified, which may allow remote code execution.... Read more
- Published: Sep. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-22524
Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.... Read more
- Published: Dec. 06, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14804
Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution.... Read more
Affected Products : ams_device_manager- Published: Oct. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14816
Advantech WebAccess 8.3.1 and earlier has several stack-based buffer overflow vulnerabilities that have been identified, which may allow an attacker to execute arbitrary code.... Read more
Affected Products : webaccess- Published: Oct. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14794
Fuji Electric Alpha5 Smart Loader Versions 3.7 and prior. The device does not perform a check on the length/size of a project file before copying the entire contents of the file to a heap-based buffer.... Read more
- Published: Oct. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14767
In Kamailio before 5.0.7 and 5.1.x before 5.1.4, a crafted SIP message with a double "To" header and an empty "To" tag causes a segmentation fault and crash. The reason is missing input validation in the "build_res_buf_from_sip_req" core function. This co... Read more
- Published: Jul. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14718
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.... Read more
- Published: Jan. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14720
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.... Read more
- Published: Jan. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14701
System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL parameter.... Read more
- Published: Dec. 03, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2002-2119
Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password guessing.... Read more
Affected Products : edirectory- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2018-14685
The add function in www/Lib/Lib/Action/Admin/TplAction.class.php in Gxlcms v1.1.4 allows remote attackers to read arbitrary files via a crafted index.php?s=Admin-Tpl-ADD-id request, related to Lib/Common/Admin/function.php.... Read more
Affected Products : gxlcms- Published: Jul. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45666
stb_image is a single file MIT licensed library for processing images. It may look like `stbi__load_gif_main` doesn’t give guarantees about the content of output value `*delays` upon failure. Although it sets `*delays` to zero at the beginning, it doesn’... Read more
- Published: Oct. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14620
The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially allow an attacker to serve malicious code to the image builder and install in the resultant container ima... Read more
Affected Products : openstack- Published: Sep. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14592
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.... Read more
- Published: Sep. 20, 2018
- Modified: Nov. 21, 2024