Latest CVE Feed
-
8.8
HIGHCVE-2018-11225
The dcputs function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denial of service (Segmentation fault and application crash) or poss... Read more
Affected Products : libming- Published: May. 17, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-11224
An issue was discovered in Libav 12.3. A read access violation in the in_table_init16 function in libavcodec/aacsbr.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv.... Read more
Affected Products : libav- Published: May. 17, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-11223
XSS in Artica Pandora FMS before 7.0 NG 723 allows an attacker to execute arbitrary code via a crafted "refr" parameter in a "/pandora_console/index.php?sec=estado&sec2=operation/agentes/estado_agente&refr=" call.... Read more
- Published: Jun. 16, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-11222
Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint.... Read more
- Published: Jun. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11221
Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/update_manager.ajax in the update system.... Read more
- Published: Jun. 16, 2018
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2018-11220
Bitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution via the system restore function.... Read more
Affected Products : antminer_d3_firmware antminer_l3\+_firmware antminer_s9_firmware antminer_d3 antminer_l3\+ antminer_s9- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11219
An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking.... Read more
- Published: Jun. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11218
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.... Read more
Affected Products : debian_linux openstack redis communications_operations_monitor vue_motion vue_pacs- Published: Jun. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11215
Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors.... Read more
Affected Products : data_science_workbench- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-11214
An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.... Read more
- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-11213
An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.... Read more
- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-11212
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.... Read more
Affected Products : ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation leap oncommand_unified_manager oncommand_workflow_automation jdk jre +3 more products- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11210
TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so. NOTE: The tinyxml2 developers have determined that the reported overflow is due to improper use of the library and not a vulnerability in tinyxml2... Read more
Affected Products : tinyxml2- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-11209
An issue was discovered in Z-BlogPHP 2.0.0. zb_system/cmd.php?act=verify relies on MD5 for the password parameter, which might make it easier for attackers to bypass intended access restrictions via a dictionary or rainbow-table attack. NOTE: the vendor d... Read more
Affected Products : z-blogphp- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-11208
An issue was discovered in Z-BlogPHP 2.0.0. There is a persistent XSS that allows remote attackers to inject arbitrary web script or HTML into background web site settings via the "copyright information office" field. NOTE: the vendor indicates that the p... Read more
Affected Products : z-blogphp- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-11207
A division by zero was discovered in H5D__chunk_init in H5Dchunk.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.... Read more
Affected Products : hdf5- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2018-11206
An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.... Read more
Affected Products : hdf5- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2018-11205
A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.... Read more
Affected Products : hdf5- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-11204
A NULL pointer dereference was discovered in H5O__chunk_deserialize in H5Ocache.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.... Read more
Affected Products : hdf5- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-11203
A division by zero was discovered in H5D__btree_decode_key in H5Dbtree.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.... Read more
Affected Products : hdf5- Published: May. 16, 2018
- Modified: Nov. 21, 2024