Latest CVE Feed
-
9.8
CRITICALCVE-2018-12972
An issue was discovered in OpenTSDB 2.3.0. Many parameters to the /q URI can execute commands, including o, key, style, and yrange and y2range and their JSON input.... Read more
Affected Products : opentsdb- Published: Jun. 29, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-12971
EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users.... Read more
Affected Products : easycms- Published: Jun. 29, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12959
The approveAndCall function of a smart contract implementation for Aditus (ADI), an Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer all contract balances into their account).... Read more
Affected Products : aditustoken- Published: Jul. 19, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-12944
Persistent Cross-Site Scripting (XSS) vulnerability in the "Categories" feature in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the name field.... Read more
Affected Products : seeddms- Published: Jul. 31, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-12943
Cross-Site Scripting (XSS) vulnerability in every page that includes the "action" URL parameter in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter.... Read more
Affected Products : seeddms- Published: Jul. 31, 2018
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2018-12942
SQL injection vulnerability in the "Users management" functionality in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows authenticated attackers to manipulate an SQL query within the application by sending additional SQL commands to the application... Read more
Affected Products : seeddms- Published: Jul. 31, 2018
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2018-12941
This vulnerability allows remote attackers to execute arbitrary code in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 by adding a system command at the end of the "cacheDir" path and following usage of the "Clear Cache" functionality. This allows an a... Read more
Affected Products : seeddms- Published: Jul. 31, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-12940
Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to execute arbitrary code by uploading a file with an executable extension specified by the "qqfile" parameter.... Read more
Affected Products : seeddms- Published: Jul. 31, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-12939
A directory traversal flaw in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows an authenticated attacker to write to (or potentially delete) arbitrary files via a .. (dot dot) in the "op/op.UploadChunks.php" "qquuid" parameter. NOTE: this can be ... Read more
Affected Products : seeddms- Published: Jul. 31, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12934
remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt.... Read more
Affected Products : binutils- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12933
PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact because the attacker controls the pCreatePen->ihPen array index.... Read more
Affected Products : wine- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12932
PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by triggering a large pAlphaBlend->cbBitsSrc value.... Read more
Affected Products : wine- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-12931
ntfs_attr_find in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified other impact via a crafted ntfs file... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-12930
ntfs_end_buffer_async_read in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified other impact via a craft... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-12929
ntfs_read_locked_inode in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a use-after-free read and possibly cause a denial of service (kernel oops or panic) via a crafted ntfs filesystem.... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-12928
In the Linux kernel 4.15.0, a NULL pointer dereference was discovered in hfs_ext_read_extent in hfs.ko. This can occur during a mount of a crafted hfs filesystem.... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12927
Northern Electric & Power (NEP) inverter devices allow remote attackers to obtain potentially sensitive information via a direct request for the nep/status/index/1 URI.... Read more
Affected Products : northern_electric_\&_power_inverter_firmware northern_electric_\&_power_inverter- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12926
Pharos Controls devices allow remote attackers to obtain potentially sensitive information via a direct request for the default/index.lsp or default/log.lsp URI.... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-12925
Baseon Lantronix MSS devices do not require a password for TELNET access.... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-12924
Sollae Serial-Ethernet-Module and Remote-I/O-Device-Server devices have a default password of sollae for the TELNET service.... Read more
Affected Products : cie-h10_firmware cie-h12_firmware cie-h14_firmware cse-m53n_firmware cse-m32_firmware cse-m24_firmware cse-m73_firmware cse-b63n2_firmware cie-h10 cie-h12 +6 more products- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024