Latest CVE Feed
-
6.5
MEDIUMCVE-2018-10805
ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.... Read more
- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10804
ImageMagick version 7.0.7-28 contains a memory leak in WriteTIFFImage in coders/tiff.c.... Read more
- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-10803
Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 123125) allows remote attackers to inject arbitrary web script or HTML via a crafted description value. This c... Read more
Affected Products : manageengine_netflow_analyzer- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10801
TIFFClientOpen in tif_unix.c in LibTIFF 3.8.2 has memory leaks, as demonstrated by bmp2tiff.... Read more
Affected Products : libtiff- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10799
A hang issue was discovered in Brave before 0.14.0 (on, for example, Linux). This vulnerability is caused by the mishandling of a long URL formed by window.location+='?\u202a\uFEFF\u202b'; concatenation in a SCRIPT element.... Read more
Affected Products : brave- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10798
A hang issue was discovered in Brave before 0.14.0 (on, for example, Linux). The vulnerability is caused by mishandling of JavaScript code that triggers the reload of a page continuously with an interval of 1 second.... Read more
Affected Products : brave- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10796
In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222014.... Read more
Affected Products : 2345_security_guard- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10795
Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment via a browser/liferay/browser.html?Type= or html/js/editor/... Read more
- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-10790
The AP4_CttsAtom class in Core/Ap4CttsAtom.cpp in Bento4 1.5.1.0 allows remote attackers to cause a denial of service (application crash), related to a memory allocation failure, as demonstrated by mp2aac.... Read more
Affected Products : bento4- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10780
Exiv2::Image::byteSwap2 in image.cpp in Exiv2 0.26 has a heap-based buffer over-read.... Read more
Affected Products : exiv2- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10779
TIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based buffer over-read, as demonstrated by bmp2tiff.... Read more
- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10778
Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, a different vulnerability tha... Read more
Affected Products : mp3gain- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10777
Buffer overflow in the WriteMP3GainAPETag function in apetag.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.... Read more
Affected Products : mp3gain- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10776
The getbits function in mpglibDBL/common.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (segmentation fault and application crash) or possibly have unspecified other impact.... Read more
Affected Products : mp3gain- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10775
NULL pointer dereference in the _fields_add function in fields.c in libbibcore.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by end2xml.... Read more
Affected Products : bibutils- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10774
Read access violation in the isiin_keyword function in isiin.c in libbibutils.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by isi2xml.... Read more
Affected Products : bibutils- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10773
NULL pointer deference in the addsn function in serialno.c in libbibcore.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by copac2xml.... Read more
Affected Products : bibutils- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10772
The tEXtToDataBuf function in pngimage.cpp in Exiv2 through 0.26 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.... Read more
Affected Products : exiv2- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10771
Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.... Read more
- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10770
download.rsp on ShenZhen Anni "5 in 1 XVR" devices allows remote attackers to download the configuration (without a login) to discover the password.... Read more
- Published: May. 09, 2018
- Modified: Nov. 21, 2024