Show filters
733 Total Results
Displaying 351-360 of 733
Sort by:
Attacker Value
Unknown

CVE-2018-20185

Disclosure Date: December 17, 2018 (last updated November 27, 2024)
In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPImage function of bmp.c, which allows attackers to cause a denial of service via a crafted bmp image file. This only affects GraphicsMagick installations with customized BMP limits.
Attacker Value
Unknown

CVE-2018-19464

Disclosure Date: November 22, 2018 (last updated November 27, 2024)
Discuz! X3.4 allows XSS via admin.php because admincp/admincp_setting.php and template\default\common\footer.htm mishandles statcode field from third-party stats code.
Attacker Value
Unknown

CVE-2018-16224

Disclosure Date: November 20, 2018 (last updated November 27, 2024)
Incorrect access control for the diagnostic files of the iSmartAlarm Cube One through 2.2.4.10 allows an attacker to retrieve them via a specifically crafted TCP request to port 12345 and 22306, and access sensitive information from the device.
0
Attacker Value
Unknown

CVE-2018-16222

Disclosure Date: November 20, 2018 (last updated November 27, 2024)
Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.0.8 for Android allows an attacker to retrieve the username and password.
0
Attacker Value
Unknown

CVE-2018-18544

Disclosure Date: October 21, 2018 (last updated November 27, 2024)
There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScript of coders/msl.c in GraphicsMagick before 1.3.31.
0
Attacker Value
Unknown

CVE-2018-18270

Disclosure Date: October 12, 2018 (last updated November 27, 2024)
XSS exists in CMS Made Simple version 2.2.7 via the m1_news_url parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.
0
Attacker Value
Unknown

CVE-2018-18271

Disclosure Date: October 12, 2018 (last updated November 27, 2024)
XSS exists in CMS Made Simple version 2.2.7 via the m1_extra parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.
0
Attacker Value
Unknown

CVE-2018-16456

Disclosure Date: October 04, 2018 (last updated February 15, 2024)
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a keyword. NOTE: This may overlap with CVE-2018-6870 which has XSS via the Listings Search feature.
0
Attacker Value
Unknown

CVE-2018-16326

Disclosure Date: October 04, 2018 (last updated February 15, 2024)
PHP Scripts Mall Olx Clone 3.4.2 has XSS.
0
Attacker Value
Unknown

CVE-2018-13982

Disclosure Date: September 18, 2018 (last updated November 27, 2024)
Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read arbitrary files.