Export limit exceeded: 348775 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (348775 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2018-19881 | 1 Artifex | 1 Mupdf | 2024-11-21 | N/A |
| In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl. | ||||
| CVE-2018-19879 | 1 Teltonika | 2 Rut950, Rut950 Firmware | 2024-11-21 | N/A |
| An issue was discovered in /cgi-bin/luci on Teltonika RTU9XX (e.g., RUT950) R_31.04.89 before R_00.05.00.5 devices. The authentication functionality is not protected from automated tools used to make login attempts to the application. An anonymous attacker has the ability to make unlimited login attempts with an automated tool. This ability could lead to cracking a targeted user's password. | ||||
| CVE-2018-19878 | 1 Teltonika | 2 Rut950, Rut950 Firmware | 2024-11-21 | N/A |
| An issue was discovered on Teltonika RTU950 R_31.04.89 devices. The application allows a user to login without limitation. For every successful login request, the application saves a session. A user can re-login without logging out, causing the application to store the session in memory. Exploitation of this vulnerability will increase memory use and consume free space. | ||||
| CVE-2018-19877 | 1 Adiscon | 1 Loganalyzer | 2024-11-21 | N/A |
| login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field. | ||||
| CVE-2018-19876 | 1 Cairographics | 1 Cairo | 2024-11-21 | N/A |
| cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMalloc, leading to an application crash with a "free(): invalid pointer" error. | ||||
| CVE-2018-19872 | 4 Fedoraproject, Opensuse, Qt and 1 more | 4 Fedora, Leap, Qt and 1 more | 2024-11-21 | N/A |
| An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp. | ||||
| CVE-2018-19871 | 3 Opensuse, Qt, Redhat | 3 Leap, Qt, Enterprise Linux | 2024-11-21 | N/A |
| An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption. | ||||
| CVE-2018-19870 | 4 Debian, Opensuse, Qt and 1 more | 4 Debian Linux, Leap, Qt and 1 more | 2024-11-21 | N/A |
| An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault. | ||||
| CVE-2018-19869 | 3 Opensuse, Qt, Redhat | 3 Leap, Qt, Enterprise Linux | 2024-11-21 | N/A |
| An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp. | ||||
| CVE-2018-19865 | 2 Opensuse, Qt | 2 Leap, Qt | 2024-11-21 | N/A |
| A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3. | ||||
| CVE-2018-19864 | 1 Nuuo | 1 Nvrmini2 Firmware | 2024-11-21 | N/A |
| NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability to read camera feeds or reconfigure the device. | ||||
| CVE-2018-19863 | 1 Agilebits | 1 1password | 2024-11-21 | N/A |
| An issue was discovered in 1Password 7.2.3.BETA before 7.2.3.BETA-3 on macOS. A mistake in error logging resulted in instances where sensitive data passed from Safari to 1Password could be logged locally on the user's machine. This data could include usernames and passwords that a user manually entered into Safari. | ||||
| CVE-2018-19862 | 1 Minishare Project | 1 Minishare | 2024-11-21 | N/A |
| Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST request. NOTE: this product is discontinued. | ||||
| CVE-2018-19861 | 1 Minishare Project | 1 Minishare | 2024-11-21 | N/A |
| Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request. NOTE: this product is discontinued. | ||||
| CVE-2018-19860 | 2 Broadcom, Cypress | 126 Bcm4335c0, Bcm4335c0 Firmware, Bcm43438a1 and 123 more | 2024-11-21 | N/A |
| Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecifed other devices does not properly restrict LMP commnds and executes certain memory contents upon receiving an LMP command, as demonstrated by executing an HCI command. | ||||
| CVE-2018-19859 | 1 Openrefine | 1 Openrefine | 2024-11-21 | N/A |
| OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive. | ||||
| CVE-2018-19858 | 1 Princexml | 1 Princexml | 2024-11-21 | N/A |
| PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities. If an attacker passes HTML referencing an XML file (e.g., in an IFRAME element), PrinceXML will fetch the XML and parse it, thus giving an attacker file-read access and full-fledged SSRF. | ||||
| CVE-2018-19857 | 2 Debian, Videolan | 2 Debian Linux, Vlc Media Player | 2024-11-21 | N/A |
| The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to an unsigned int even if that value is negative. This could result in a denial of service and/or a potential infoleak. | ||||
| CVE-2018-19856 | 1 Gitlab | 1 Gitlab | 2024-11-21 | N/A |
| GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API. | ||||
| CVE-2018-19855 | 1 Uipath | 1 Orchestrator | 2024-11-21 | N/A |
| UiPath Orchestrator before 2018.3.4 allows CSV Injection, related to the Audit export, Robot log export, and Transaction log export features. | ||||