Export limit exceeded: 42406 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (42406 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2018-7322 | 2 Debian, Wireshark | 2 Debian Linux, Wireshark | 2024-11-21 | N/A |
| In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-dcm.c had an infinite loop that was addressed by checking for integer wraparound. | ||||
| CVE-2018-7321 | 1 Wireshark | 1 Wireshark | 2024-11-21 | N/A |
| In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-thrift.c had a large loop that was addressed by not proceeding with dissection after encountering an unexpected type. | ||||
| CVE-2018-7319 | 1 Os Property Real Estate Project | 1 Os Property Real Estate | 2024-11-21 | N/A |
| SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system1, or laundry parameter. | ||||
| CVE-2018-7318 | 2 Belitsoft, Oracle | 2 Checklist, Data Integrator | 2024-11-21 | 9.8 Critical |
| SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, description_search, or filter_order parameter. | ||||
| CVE-2018-7315 | 1 Harmistechnology | 1 Ek Rishta | 2024-11-21 | N/A |
| SQL Injection exists in the Ek Rishta 2.9 component for Joomla! via the gender, age1, age2, religion, mothertounge, caste, or country parameter. | ||||
| CVE-2018-7314 | 1 Mlwebtechnologies | 1 Prayercenter | 2024-11-21 | N/A |
| SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429. | ||||
| CVE-2018-7313 | 1 Cwjoomla | 1 Cw Tags | 2024-11-21 | N/A |
| SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter. | ||||
| CVE-2018-7312 | 1 Alexandriabooklibrary | 1 Alexandria Book Library | 2024-11-21 | N/A |
| SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla! via the letter parameter. | ||||
| CVE-2018-7282 | 1 Titool | 1 Printmonitor | 2024-11-21 | 9.8 Critical |
| The username parameter of the TITool PrintMonitor solution during the login request is vulnerable to and/or time-based blind SQLi. | ||||
| CVE-2018-7269 | 1 Yiiframework | 1 Yii | 2024-11-21 | N/A |
| The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocumented need to sanitize array input. | ||||
| CVE-2018-7245 | 1 Schneider-electric | 11 66074 Mge Network Management Card Transverse, Mge Comet Ups, Mge Eps 6000 and 8 more | 2024-11-21 | N/A |
| An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to change UPS control and shutdown parameters or other critical settings without authorization. | ||||
| CVE-2018-7225 | 4 Canonical, Debian, Libvncserver Project and 1 more | 10 Ubuntu Linux, Debian Linux, Libvncserver and 7 more | 2024-11-21 | N/A |
| An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets. | ||||
| CVE-2018-7180 | 1 Saxum2003 | 1 Astro | 2024-11-21 | N/A |
| SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter. | ||||
| CVE-2018-7179 | 1 Squadmanagement Project | 1 Squadmanagement | 2024-11-21 | N/A |
| SQL Injection exists in the SquadManagement 1.0.3 component for Joomla! via the id parameter. | ||||
| CVE-2018-7178 | 1 Saxum2003 | 1 Saxum Picker | 2024-11-21 | N/A |
| SQL Injection exists in the Saxum Picker 3.2.10 component for Joomla! via the publicid parameter. | ||||
| CVE-2018-7177 | 1 Saxum2003 | 1 Numerology | 2024-11-21 | N/A |
| SQL Injection exists in the Saxum Numerology 3.0.4 component for Joomla! via the publicid parameter. | ||||
| CVE-2018-7174 | 1 Xpdfreader | 1 Xpdf | 2024-11-21 | N/A |
| An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams. | ||||
| CVE-2018-7167 | 2 Nodejs, Redhat | 2 Node.js, Rhel Software Collections | 2024-11-21 | 7.5 High |
| Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron"), 8.x (LTS "Carbon"), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable. | ||||
| CVE-2018-7107 | 1 Hpe | 1 Device Entitlement Gateway | 2024-11-21 | N/A |
| A potential security vulnerability has been identified in HPE Device Entitlement Gateway (DEG) v3.2.4, v3.3 and v3.3.1. The vulnerability could be remotely exploited to allow local SQL injection and elevation of privilege. | ||||
| CVE-2018-7079 | 1 Arubanetworks | 1 Clearpass Policy Manager | 2024-11-21 | N/A |
| Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules, which allows any authenticated administrative user to execute those operations regardless of privilege level. This could allow low-privilege users to view, modify, or delete guest users. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix. | ||||