Export limit exceeded: 87193 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (87193 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2018-16717 | 1 Nih | 1 Ncbi Toolbox | 2024-11-21 | N/A |
| A heap-based buffer overflow exists in nph-viewgif.cgi in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox. | ||||
| CVE-2018-16715 | 1 Absolute | 1 Ctes Windows Agent | 2024-11-21 | N/A |
| An issue was discovered in Absolute Software CTES Windows Agent through 1.0.0.1479. The security permissions on the %ProgramData%\CTES folder and sub-folders may allow write access to low-privileged user accounts. This allows unauthorized replacement of service program executable (EXE) or dynamically loadable library (DLL) files, causing elevated (SYSTEM) user access. Configuration control files or data files under this folder could also be similarly modified to affect service process behavior. | ||||
| CVE-2018-16703 | 1 Gleeztech | 1 Gleez Cms | 2024-11-21 | N/A |
| A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can further help an attacker to perform login attempts in excess of the configured login attempt limit. The vulnerability is due to insufficient server-side access control and login attempt limit enforcement. An attacker could exploit this vulnerability by sending modified login attempts to the Portal login page. An exploit could allow the attacker to identify existing users and perform brute-force password attacks on the Portal, as demonstrated by navigating to the user/4 URI. | ||||
| CVE-2018-16666 | 1 Contiki-ng | 1 Contiki-ng. | 2024-11-21 | N/A |
| An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in next_string in os/storage/antelope/aql-lexer.c while parsing AQL (parsing next string). | ||||
| CVE-2018-16663 | 1 Contiki-ng | 1 Contiki-ng. | 2024-11-21 | N/A |
| An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in parse_relations in os/storage/antelope/aql-parser.c while parsing AQL (storage of relations). | ||||
| CVE-2018-16660 | 1 Imperva | 1 Securesphere | 2024-11-21 | N/A |
| A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated access to execute arbitrary OS commands on a vulnerable installation. | ||||
| CVE-2018-16655 | 1 Gxlcms | 1 Gxlcms | 2024-11-21 | N/A |
| Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php. | ||||
| CVE-2018-16654 | 1 Zurmo | 1 Zurmo Crm | 2024-11-21 | N/A |
| Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1. | ||||
| CVE-2018-16653 | 1 Rejucms Project | 1 Rejucms | 2024-11-21 | N/A |
| rejucms 2.1 has XSS via the ucenter/cms_user_add.php u_name parameter. | ||||
| CVE-2018-16645 | 4 Canonical, Debian, Imagemagick and 1 more | 4 Ubuntu Linux, Debian Linux, Imagemagick and 1 more | 2024-11-21 | N/A |
| There is an excessive memory allocation issue in the functions ReadBMPImage of coders/bmp.c and ReadDIBImage of coders/dib.c in ImageMagick 7.0.8-11, which allows remote attackers to cause a denial of service via a crafted image file. | ||||
| CVE-2018-16642 | 4 Canonical, Debian, Imagemagick and 1 more | 4 Ubuntu Linux, Debian Linux, Imagemagick and 1 more | 2024-11-21 | N/A |
| The function InsertRow in coders/cut.c in ImageMagick 7.0.7-37 allows remote attackers to cause a denial of service via a crafted image file due to an out-of-bounds write. | ||||
| CVE-2018-16641 | 1 Imagemagick | 1 Imagemagick | 2024-11-21 | N/A |
| ImageMagick 7.0.8-6 has a memory leak vulnerability in the TIFFWritePhotoshopLayers function in coders/tiff.c. | ||||
| CVE-2018-16640 | 3 Canonical, Imagemagick, Redhat | 3 Ubuntu Linux, Imagemagick, Enterprise Linux | 2024-11-21 | N/A |
| ImageMagick 7.0.8-5 has a memory leak vulnerability in the function ReadOneJNGImage in coders/png.c. | ||||
| CVE-2018-16639 | 1 Typesettercms | 1 Typesetter | 2024-11-21 | N/A |
| Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation. | ||||
| CVE-2018-16638 | 1 Modx | 1 Evolution Cms | 2024-11-21 | N/A |
| Evolution CMS 1.4.x allows XSS via the manager/ search parameter. | ||||
| CVE-2018-16637 | 1 Modx | 1 Evolution Cms | 2024-11-21 | N/A |
| Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI. | ||||
| CVE-2018-16636 | 1 Nucleuscms | 1 Nucleus Cms | 2024-11-21 | N/A |
| Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter. | ||||
| CVE-2018-16635 | 1 Blackcat-cms | 1 Blackcat Cms | 2024-11-21 | N/A |
| Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php. | ||||
| CVE-2018-16633 | 1 Pluck-cms | 1 Pluck | 2024-11-21 | N/A |
| Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title. | ||||
| CVE-2018-16632 | 1 Jupo | 1 Mezzanine | 2024-11-21 | N/A |
| Mezzanine CMS v4.3.1 allows XSS via the /admin/blog/blogcategory/add/?_to_field=id&_popup=1 title parameter at admin/blog/blogpost/add/. | ||||