Latest CVE Feed
-
7.8
HIGHCVE-2018-10777
Buffer overflow in the WriteMP3GainAPETag function in apetag.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.... Read more
Affected Products : mp3gain- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10776
The getbits function in mpglibDBL/common.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (segmentation fault and application crash) or possibly have unspecified other impact.... Read more
Affected Products : mp3gain- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10775
NULL pointer dereference in the _fields_add function in fields.c in libbibcore.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by end2xml.... Read more
Affected Products : bibutils- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10774
Read access violation in the isiin_keyword function in isiin.c in libbibutils.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by isi2xml.... Read more
Affected Products : bibutils- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10773
NULL pointer deference in the addsn function in serialno.c in libbibcore.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by copac2xml.... Read more
Affected Products : bibutils- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10772
The tEXtToDataBuf function in pngimage.cpp in Exiv2 through 0.26 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.... Read more
Affected Products : exiv2- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10771
Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.... Read more
- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10770
download.rsp on ShenZhen Anni "5 in 1 XVR" devices allows remote attackers to download the configuration (without a login) to discover the password.... Read more
- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-10769
The transferProxy and approveProxy functions of a smart contract implementation for SmartMesh (SMT), an Ethereum ERC20 token, allow attackers to accomplish an unauthorized transfer of digital assets because replay attacks can occur with the same-named fun... Read more
- Published: Aug. 10, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10768
There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not aff... Read more
- Published: May. 06, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10767
There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead t... Read more
Affected Products : enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation ansible_tower libgxps- Published: May. 06, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-10763
Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2) Sub heading fields in the Partial Branding configuration page.... Read more
Affected Products : synaman- Published: Sep. 14, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10760
Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file... Read more
Affected Products : projectpier- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10759
PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbitrary commands or SQL statements via the id parameter.... Read more
Affected Products : projectpier- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10758
The edit/ URI in Datenstrom Yellow 0.7.3 has CSRF via a delete action that can delete articles.... Read more
Affected Products : yellow- Published: May. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10757
CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a login attempt.... Read more
Affected Products : csp_mysql_user_manager- Published: May. 05, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10756
Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.... Read more
- Published: May. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10753
Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.... Read more
- Published: May. 05, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-10752
The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action.... Read more
Affected Products : tagregator- Published: May. 05, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-10751
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-20... Read more
Affected Products : samsung_mobile- Published: May. 29, 2018
- Modified: Nov. 21, 2024