Export limit exceeded: 43050 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (43050 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2018-7480 | 3 Canonical, Debian, Linux | 3 Ubuntu Linux, Debian Linux, Linux Kernel | 2024-11-21 | 7.8 High |
| The blkcg_init_queue function in block/blk-cgroup.c in the Linux kernel before 4.11 allows local users to cause a denial of service (double free) or possibly have unspecified other impact by triggering a creation failure. | ||||
| CVE-2018-7479 | 1 Yzmcms | 1 Yzmcms | 2024-11-21 | 5.3 Medium |
| YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.php. | ||||
| CVE-2018-7477 | 1 School Management Script Project | 1 School Management Script | 2024-11-21 | N/A |
| SQL Injection exists in PHP Scripts Mall School Management Script 3.0.4 via the Username and Password fields to parents/Parent_module/parent_login.php. | ||||
| CVE-2018-7476 | 1 Finecms | 1 Finecms | 2024-11-21 | N/A |
| controllers/admin/Linkage.php in dayrui FineCms 5.3.0 has Cross Site Scripting (XSS) via the id or lid parameter in a c=linkage,m=import request to admin.php, because the xss_clean protection mechanism is defeated by crafted input that lacks a '<' or '>' character. | ||||
| CVE-2018-7472 | 1 Invt | 1 Studio | 2024-11-21 | N/A |
| INVT Studio 1.2 allows remote attackers to cause a denial of service during import operations. | ||||
| CVE-2018-7471 | 1 Bj-tct | 1 Kingview | 2024-11-21 | N/A |
| KingView 7.5SP1 has an integer overflow during stgopenstorage API read operations. | ||||
| CVE-2018-7470 | 1 Imagemagick | 1 Imagemagick | 2024-11-21 | N/A |
| An issue was discovered in ImageMagick 7.0.7-22 Q16. The IsWEBPImageLossless function in coders/webp.c allows attackers to cause a denial of service (segmentation violation) via a crafted file. | ||||
| CVE-2018-7469 | 1 Entrepreneur Job Portal Script Project | 1 Entrepreneur Job Portal Script | 2024-11-21 | N/A |
| PHP Scripts Mall Entrepreneur Job Portal Script 2.0.9 has XSS via the p_name (aka Edit Category Name) field to admin/categories_industry.php (aka Categories - Industry Type). | ||||
| CVE-2018-7467 | 1 Axxonsoft | 1 Next | 2024-11-21 | N/A |
| AxxonSoft Axxon Next has Directory Traversal via an initial /css//..%2f substring in a URI. | ||||
| CVE-2018-7466 | 1 Testlink | 1 Testlink | 2024-11-21 | N/A |
| install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES data during installation to provide a long, crafted value. | ||||
| CVE-2018-7463 | 1 Asanhamayesh | 1 Asanhamayesh Cms | 2024-11-21 | N/A |
| SQL injection vulnerability in files.php in the "files" component in ASANHAMAYESH CMS 3.4.6 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter. | ||||
| CVE-2018-7456 | 4 Canonical, Debian, Libtiff and 1 more | 4 Ubuntu Linux, Debian Linux, Libtiff and 1 more | 2024-11-21 | N/A |
| A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 when using the tiffinfo tool to print crafted TIFF information, a different vulnerability than CVE-2017-18013. (This affects an earlier part of the TIFFPrintDirectory function that was not addressed by the CVE-2017-18013 patch.) | ||||
| CVE-2018-7455 | 1 Xpdfreader | 1 Xpdf | 2024-11-21 | N/A |
| An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. | ||||
| CVE-2018-7454 | 1 Xpdfreader | 1 Xpdf | 2024-11-21 | N/A |
| A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. | ||||
| CVE-2018-7453 | 1 Xpdfreader | 1 Xpdf | 2024-11-21 | N/A |
| Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lack of loop checking, as demonstrated by pdftohtml. | ||||
| CVE-2018-7452 | 1 Xpdfreader | 1 Xpdf | 2024-11-21 | N/A |
| A NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. | ||||
| CVE-2018-7448 | 1 Cmsmadesimple | 1 Cms Made Simple | 2024-11-21 | N/A |
| Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure. | ||||
| CVE-2018-7447 | 1 Mojoportal | 1 Mojoportal | 2024-11-21 | N/A |
| mojoPortal through 2.6.0.0 is prone to multiple persistent cross-site scripting vulnerabilities because it fails to sanitize user-supplied input. The 'Title' and 'Subtitle' fields of the 'Blog' page are vulnerable. NOTE: The software maintainer disputes this as a vulnerability because the fields claimed to be vulnerable to XSS are only available to administrators who are supposed to have access to add scripts | ||||
| CVE-2018-7443 | 3 Canonical, Debian, Imagemagick | 3 Ubuntu Linux, Debian Linux, Imagemagick | 2024-11-21 | N/A |
| The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-23 Q16 does not properly validate the amount of image data in a file, which allows remote attackers to cause a denial of service (memory allocation failure in the AcquireMagickMemory function in MagickCore/memory.c). | ||||
| CVE-2018-7442 | 1 Leptonica | 1 Leptonica | 2024-11-21 | N/A |
| An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function does not block '/' characters in the gplot rootname argument, potentially leading to path traversal and arbitrary file overwrite. | ||||