National Vulnerability Database

Subscribe to National Vulnerability Database feed
This feed contains the most recent CVE cyber vulnerabilities published within the National Vulnerability Database.
Updated: 10 hours 58 min ago

CVE-2018-14455

Fri, 07/20/2018 - 11:29
An issue was discovered in libgig 4.1.0. There is an out-of-bounds write in pData[0] access in the function store32 in helper.h.
Categories: Security News

CVE-2018-14456

Fri, 07/20/2018 - 11:29
An issue was discovered in libgig 4.1.0. There is an out-of-bounds write in the function DLS::Info::SaveString in DLS.cpp.
Categories: Security News

CVE-2018-14457

Fri, 07/20/2018 - 11:29
An issue was discovered in libgig 4.1.0. There is an out-of-bounds write in the function DLS::Info::UpdateChunks in DLS.cpp.
Categories: Security News

CVE-2018-14458

Fri, 07/20/2018 - 11:29
An issue was discovered in libgig 4.1.0. There is a heap-based buffer overflow in pData[1] access in the function store32 in helper.h.
Categories: Security News

CVE-2018-14459

Fri, 07/20/2018 - 11:29
An issue was discovered in libgig 4.1.0. There is an out-of-bounds write in pData[0] access in the function store16 in helper.h.
Categories: Security News

CVE-2018-14460

Fri, 07/20/2018 - 11:29
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_sdspace_decode in H5Osdspace.c.
Categories: Security News

CVE-2018-14443

Fri, 07/20/2018 - 09:29
get_first_owned_object in dwg.c in GNU LibreDWG 0.5.1036 allows remote attackers to cause a denial of service (SEGV).
Categories: Security News

CVE-2018-14444

Fri, 07/20/2018 - 09:29
libdxfrw 0.6.3 has an Integer Overflow in dwgCompressor::decompress18 in dwgutil.cpp, leading to an out-of-bounds read and application crash.
Categories: Security News

CVE-2018-14445

Fri, 07/20/2018 - 09:29
In Bento4 v1.5.1-624, AP4_File::ParseStream in Ap4File.cpp allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 file.
Categories: Security News

CVE-2018-14446

Fri, 07/20/2018 - 09:29
MP4Integer32Property::Read in atom_avcC.cpp in MP4v2 2.1.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted MP4 file.
Categories: Security News

CVE-2018-14447

Fri, 07/20/2018 - 09:29
trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read.
Categories: Security News

CVE-2018-14448

Fri, 07/20/2018 - 09:29
Codec::parse in track.cpp in Untrunc through 2018-06-07 has a NULL pointer dereference via a crafted MP4 file because of improper interaction with libav.
Categories: Security News

CVE-2018-14442

Fri, 07/20/2018 - 08:29
Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.
Categories: Security News

CVE-2016-10727

Fri, 07/20/2018 - 00:29
camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server code was intended to report an error and not proceed, but the code was written incorrectly.
Categories: Security News

CVE-2018-8018

Thu, 07/19/2018 - 21:29
Apache Ignite 2.5 and earlier serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially prepared form of a serialized object to GridClientJdkMarshaller deserialization endpoint.
Categories: Security News

CVE-2018-14415

Thu, 07/19/2018 - 21:29
An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen.
Categories: Security News

CVE-2018-14418

Thu, 07/19/2018 - 21:29
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
Categories: Security News

CVE-2018-14419

Thu, 07/19/2018 - 21:29
MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.
Categories: Security News

CVE-2018-14420

Thu, 07/19/2018 - 21:29
MetInfo 6.0.0 allows a CSRF attack to add a user account via a doaddsave action to admin/index.php, as demonstrated by an admin/index.php?anyid=47&n=admin&c=admin_admin&a=doaddsave URI.
Categories: Security News

CVE-2018-14421

Thu, 07/19/2018 - 21:29
SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admin_video.php). The code is executed by visiting /details/index.php. This can also be exploited through CSRF.
Categories: Security News

Pages