Search Results (322553 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-14425 1 Synacor 1 Zimbra Collaboration Suite 2024-11-21 N/A
There is a Persistent XSS vulnerability in the briefcase component of Synacor Zimbra Collaboration Suite (ZCS) Zimbra Web Client (ZWC) 8.8.8 before 8.8.8 Patch 7 and 8.8.9 before 8.8.9 Patch 1.
CVE-2018-14424 1 Gnome 1 Gnome Display Manager 2024-11-21 N/A
The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code execution.
CVE-2018-14423 2 Debian, Uclouvain 2 Debian Linux, Openjpeg 2024-11-21 N/A
Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).
CVE-2018-14422 1 Sanscms 1 Sanscms 2024-11-21 N/A
blog/index.php in SansCMS 0.7 has XSS via the q parameter.
CVE-2018-14421 1 Seacms 1 Seacms 2024-11-21 N/A
SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admin_video.php). The code is executed by visiting /details/index.php. This can also be exploited through CSRF.
CVE-2018-14420 1 Metinfo 1 Metinfo 2024-11-21 N/A
MetInfo 6.0.0 allows a CSRF attack to add a user account via a doaddsave action to admin/index.php, as demonstrated by an admin/index.php?anyid=47&n=admin&c=admin_admin&a=doaddsave URI.
CVE-2018-14419 1 Metinfo 1 Metinfo 2024-11-21 N/A
MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.
CVE-2018-14418 1 Msvod 1 Msvod Cms 2024-11-21 N/A
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
CVE-2018-14417 1 Softnas 1 Cloud 2024-11-21 N/A
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions.
CVE-2018-14415 1 Icmsdev 1 Icms 2024-11-21 N/A
An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen.
CVE-2018-14403 1 Techsmith 1 Mp4v2 2024-11-21 N/A
MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for associated atoms. The resulting type confusion can cause out-of-bounds memory access.
CVE-2018-14402 1 Axmldec Project 1 Axmldec 2024-11-21 N/A
axmldec 1.2.0 has an out-of-bounds write in the jitana::axml_parser::parse_start_namespace function in lib/jitana/util/axml_parser.cpp.
CVE-2018-14401 1 Axml Parser Project 1 Axml Parser 2024-11-21 N/A
CopyData in AxmlParser.c in AXML Parser through 2018-01-04 has an out-of-bounds read.
CVE-2018-14399 1 Phpcms Project 1 Phpcms 2024-11-21 N/A
libs\classes\attachment.class.php in PHPCMS 9.6.0 allows remote attackers to upload and execute arbitrary PHP code via a .txt?.php#.jpg URI in the SRC attribute of an IMG element within info[content] JSON data to the index.php?m=member&c=index&a=register URI.
CVE-2018-14398 1 Cremecrm 1 Cremecrm 2024-11-21 N/A
An issue was discovered in Creme CRM 1.6.12. The value of the cancel button uses the content of the HTTP Referer header, and could be used to trick a user into visiting a fake login page in order to steal credentials.
CVE-2018-14397 1 Cremecrm 1 Cremecrm 2024-11-21 N/A
An issue was discovered in Creme CRM 1.6.12. The organization creation page is affected by 9 stored cross-site scripting vulnerabilities involving the name, billing_address-address, billing_address-zipcode, billing_address-city, billing_address-department, shipping_address-address, shipping_address-zipcode, shipping_address-city, and shipping_address-department parameters.
CVE-2018-14396 1 Cremecrm 1 Cremecrm 2024-11-21 N/A
An issue was discovered in Creme CRM 1.6.12. The salesman creation page is affected by 10 stored cross-site scripting vulnerabilities involving the firstname, lastname, billing_address-address, billing_address-zipcode, billing_address-city, billing_address-department, shipping_address-address, shipping_address-zipcode, shipping_address-city, and shipping_address-department parameters.
CVE-2018-14395 2 Debian, Ffmpeg 2 Debian Linux, Ffmpeg 2024-11-21 6.5 Medium
libavformat/movenc.c in FFmpeg 3.2 and 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a user crafted audio file when converting to the MOV audio format.
CVE-2018-14394 1 Ffmpeg 1 Ffmpeg 2024-11-21 N/A
libavformat/movenc.c in FFmpeg before 4.0.2 allows attackers to cause a denial of service (application crash caused by a divide-by-zero error) with a user crafted Waveform audio file.
CVE-2018-14392 1 Mybb 1 New Threads 2024-11-21 N/A
The New Threads plugin before 1.2 for MyBB has XSS.