Vulnerabilities (CVE)

Total 404199 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-17439 1 Hdfgroup 1 Hdf5 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
An issue was discovered in the HDF HDF5 1.10.3 library. There is a stack-based buffer overflow in the function H5S_extent_get_dims() in H5S.c. Specifically, this issue occurs while converting an HDF5 file to a GIF file.
CVE-2018-17438 1 Hdfgroup 1 Hdf5 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.
CVE-2018-17437 1 Hdfgroup 1 Hdf5 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
Memory leak in the H5O_dtype_decode_helper() function in H5Odtype.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.
CVE-2018-17436 1 Hdfgroup 1 Hdf5 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
ReadCode() in decompress.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (invalid write access) via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.
CVE-2018-17435 1 Hdfgroup 1 Hdf5 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
A heap-based buffer over-read in H5O_attr_decode() in H5Oattr.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while converting an HDF file to GIF file.
CVE-2018-17434 1 Hdfgroup 1 Hdf5 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
A SIGFPE signal is raised in the function apply_filters() of h5repack_filters.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.
CVE-2018-17433 1 Hdfgroup 1 Hdf5 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
A heap-based buffer overflow in ReadGifImageDesc() in gifread.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.
CVE-2018-17432 1 Hdfgroup 1 Hdf5 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
A NULL pointer dereference in H5O_sdspace_encode() in H5Osdspace.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service via a crafted HDF5 file.
CVE-2018-17431 1 Comodo 1 Unified Threat Management Firewall 2026-06-17 7.5 HIGH 9.8 CRITICAL
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL.
CVE-2018-17429 1 Jtbc 1 Jtbc 2026-06-17 6.8 MEDIUM 8.8 HIGH
/console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account.
CVE-2018-17428 1 Nexusfi 1 Opac Easyweb Five 2026-06-17 7.5 HIGH 9.8 CRITICAL
An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio parameter.
CVE-2018-17427 1 Simdcomp Project 1 Simdcomp 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
SIMDComp before 0.1.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) because it can read (and then discard) extra bytes.
CVE-2018-17426 1 Wuzhicms 1 Wuzhicms 2026-06-17 3.5 LOW 5.4 MEDIUM
WUZHI CMS 4.1.0 has stored XSS via the "Extension module" "SMS in station" field under the index.php?m=core URI.
CVE-2018-17425 1 Wuzhicms 1 Wuzhicms 2026-06-17 3.5 LOW 5.4 MEDIUM
WUZHI CMS 4.1.0 has stored XSS via the "Membership Center" "I want to ask" "detailed description" field under the index.php?m=member URI.
CVE-2018-17423 1 E107 1 E107 2026-06-17 3.5 LOW 4.8 MEDIUM
An issue was discovered in e107 v2.1.9. There is a XSS attack on e107_admin/comment.php.
CVE-2018-17422 1 Dotcms 1 Dotcms 2026-06-17 5.8 MEDIUM 6.1 MEDIUM
dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.
CVE-2018-17421 1 Zrlog 1 Zrlog 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname.
CVE-2018-17420 1 Zrlog 1 Zrlog 2026-06-17 6.5 MEDIUM 7.2 HIGH
An issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via the keywords parameter.
CVE-2018-17419 1 Dns Library Project 1 Dns Library 2026-06-17 5.0 MEDIUM 7.5 HIGH
An issue was discovered in setTA in scan_rr.go in the Miek Gieben DNS library before 1.0.10 for Go. A dns.ParseZone() parsing error causes a segmentation violation, leading to denial of service.
CVE-2018-17418 1 Monstra 1 Monstra 2026-06-17 6.5 MEDIUM 7.2 HIGH
Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, because plugins\box\filesmanager\filesmanager.admin.php mishandles the forbidden_types variable.