Latest CVE Feed
-
7.5
HIGHCVE-2018-12078
The mintToken function of a smart contract implementation for PolyAI (AI), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tra... Read more
Affected Products : polyai- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2018-12076
A vulnerability in the UPC bar code of the Avanti Markets MarketCard could allow an unauthenticated, local attacker to access funds within the customer's MarketCard balance, and also could lead to Customer Information Disclosure. The vulnerability is due ... Read more
Affected Products : market_card- Published: Dec. 13, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-12073
An issue was discovered on Eminent EM4544 9.10 devices. The device does not require the user's current password to set a new one within the web interface. Therefore, it is possible to exploit this issue (e.g., in combination with a successful XSS, or at a... Read more
Affected Products : em4544- Published: Jun. 17, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-12072
An issue was discovered in Cloud Media Popcorn A-200 03-05-130708-21-POP-411-000 firmware. It is configured to provide TELNET remote access (without a password) that pops a shell as root. If an attacker can connect to port 23 on the device, he can complet... Read more
- Published: Jun. 17, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12070
The sell function of a smart contract implementation for SEC, a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manip... Read more
Affected Products : sec- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12068
The sell function of a smart contract implementation for Target Coin (TGT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amou... Read more
Affected Products : target_coin- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12067
The sell function of a smart contract implementation for Substratum (SUB), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amoun... Read more
Affected Products : substratum- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-12066
BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon crash) via BGP mask expressions in birdc.... Read more
Affected Products : bird- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12065
A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP files (execute PHP code) or read non-PHP files by replacing a helper.json file.... Read more
Affected Products : witycms- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12064
tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h.... Read more
Affected Products : tinyexr- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12063
The sell function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argum... Read more
Affected Products : node_token- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12062
The sell function of a smart contract implementation for SwftCoin (SWFTC), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amoun... Read more
Affected Products : swftcoin- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12056
The maxRandom function of a smart contract implementation for All For One, an Ethereum gambling game, generates a random value with publicly readable variables because the _seed value can be retrieved with a getStorageAt call. Therefore, it allows attacke... Read more
Affected Products : all_for_one- Published: Aug. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12055
Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.php, faq.php, about.php, photo_gallery.php, privacy.php, and so on.... Read more
Affected Products : schools_alert_management_script- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12054
Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absolute path traversal.... Read more
Affected Products : schools_alert_management_script- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12053
Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.php by using directory traversal.... Read more
Affected Products : schools_alert_management_script- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12052
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.... Read more
Affected Products : schools_alert_management_script- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12051
Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script via $_FILE in /webmasterst/general.php, as demonstrated by a .php file with the image/jpeg content type.... Read more
Affected Products : schools_alert_management_script- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-12049
A remote attacker can bypass the System Manager Mode on the Canon LBP6030w web interface without a PIN for /checkLogin.cgi via vectors involving /portal_top.html to get full access to the device. NOTE: the vendor reportedly responded that this issue occur... Read more
- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-12048
A remote attacker can bypass the Management Mode on the Canon LBP7110Cw web interface without a PIN for /checkLogin.cgi via vectors involving /portal_top.html to get full access to the device. NOTE: the vendor reportedly responded that this issue occurs w... Read more
- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024