Latest CVE Feed
-
7.5
HIGHCVE-2018-11396
ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrated by a crafted window.open call.... Read more
Affected Products : epiphany- Published: May. 23, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-11392
An arbitrary file upload vulnerability in /classes/profile.class.php in Jigowatt "PHP Login & User Management" before 4.1.1, as distributed in the Envato Market, allows any remote authenticated user to upload .php files to the web server via a profile ava... Read more
Affected Products : php_login_\&_user_management- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2018-11386
An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under ... Read more
- Published: Jun. 13, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2018-11385
An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login feature may allow an attack... Read more
- Published: Jun. 13, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11384
The sh_op() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted ELF file.... Read more
Affected Products : radare2- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11383
The r_strbuf_fini() function in radare2 2.5.0 allows remote attackers to cause a denial of service (invalid free and application crash) via a crafted ELF file because of an uninitialized variable in the CPSE handler in libr/anal/p/anal_avr.c.... Read more
Affected Products : radare2- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11382
The _inst__sts() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.... Read more
Affected Products : radare2- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11381
The string_scan_range() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.... Read more
Affected Products : radare2- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11380
The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted Mach-O file.... Read more
Affected Products : radare2- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11379
The get_debug_info() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted PE file.... Read more
Affected Products : radare2- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-11378
The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact via a crafted WASM file.... Read more
Affected Products : radare2- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11377
The avr_op_analyze() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.... Read more
Affected Products : radare2- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11376
The r_read_le32() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted ELF file.... Read more
Affected Products : radare2- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11375
The _inst__lds() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.... Read more
Affected Products : radare2- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11373
iScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter.... Read more
Affected Products : eswap- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11372
iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter.... Read more
Affected Products : eswap- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-11371
SkyCaiji 1.2 allows CSRF to add an Administrator user.... Read more
Affected Products : skycaiji- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11369
An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the database via the \apps\home\controller\ParserController.php scode parameter.... Read more
Affected Products : pbootcms- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-11367
An issue was discovered in CppCMS before 1.2.1. There is a denial of service in the JSON parser module.... Read more
Affected Products : cppcms- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-11366
init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging is mishandled. This is fixed in 1.4.0.... Read more
Affected Products : loginizer- Published: May. 22, 2018
- Modified: Nov. 21, 2024