Writeup Exploits

62,891 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-14349 WRITEUP CRITICAL
Mutt <1.10.1 - Info Disclosure
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a NO response without a message.
CVSS 9.8
CVE-2018-14350 WRITEUP CRITICAL
Mutt < 1.10.1 and NeoMutt < 20180716 - Stack-based Buffer Overflow via Long INTERNALDATE Field
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long INTERNALDATE field.
CVSS 9.8
CVE-2018-14351 WRITEUP CRITICAL
Mutt < 1.10.1 and NeoMutt < 20180716 - Denial of Service via IMAP Status Mailbox Literal Count
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/command.c mishandles a long IMAP status mailbox literal count size.
CVSS 9.8
CVE-2018-14352 WRITEUP CRITICAL
Mutt < 1.10.1 and NeoMutt < 20180716 - Stack-based Buffer Overflow in imap_quote_string
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote characters, leading to a stack-based buffer overflow.
CVSS 9.8
CVE-2018-14353 WRITEUP CRITICAL
Mutt < 1.10.1 and NeoMutt < 20180716 - Integer Underflow in imap_quote_string
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c has an integer underflow.
CVSS 9.8
CVE-2018-14354 WRITEUP CRITICAL
Mutt < 1.10.1 and NeoMutt < 20180716 - OS Command Injection via IMAP Mailboxes Command
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with a manual subscription or unsubscription.
CVSS 9.8
CVE-2018-14355 WRITEUP MEDIUM
Mutt <1.10.1 - Path Traversal
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/util.c mishandles ".." directory traversal in a mailbox name.
CVSS 5.3
CVE-2018-14356 WRITEUP CRITICAL
Mutt <1.10.1 - Info Disclosure
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c mishandles a zero-length UID.
CVSS 9.8
CVE-2018-14357 WRITEUP CRITICAL
Mutt < 1.10.1 and NeoMutt < 20180716 - Remote Command Execution via IMAP Mailbox Subscription
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an automatic subscription.
CVSS 9.8
CVE-2018-14358 WRITEUP CRITICAL
Mutt < 1.10.1 and NeoMutt < 20180716 - Stack-based Buffer Overflow via Long RFC822.SIZE FETCH Response
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long RFC822.SIZE field.
CVSS 9.8
CVE-2018-14359 WRITEUP CRITICAL
Mutt < 1.10.1 and NeoMutt < 20180716 - Buffer Overflow via Base64 Data
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data.
CVSS 9.8
CVE-2018-14362 WRITEUP CRITICAL
Mutt < 1.10.1 and NeoMutt < 20180716 - Path Traversal via Message-Cache Pathname
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.
CVSS 9.8
CVE-2018-14461 WRITEUP HIGH
tcpdump < 4.9.3 - Out-of-bounds Read in LDP Parser
The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().
CVSS 7.5
CVE-2018-14462 WRITEUP HIGH
tcpdump < 4.9.3 - Out-of-bounds Read in ICMP Parser
The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().
CVSS 7.5
CVE-2018-14463 WRITEUP HIGH
tcpdump < 4.9.3 - Out-of-bounds Read in VRRP Parser
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167.
CVSS 7.5
CVE-2018-14464 WRITEUP HIGH
tcpdump < 4.9.3 - Out-of-bounds Read in LMP Parser
The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs().
CVSS 7.5
CVE-2018-14465 WRITEUP HIGH
tcpdump < 4.9.3 - Out-of-bounds Read in RSVP Parser
The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().
CVSS 7.5
CVE-2018-14466 WRITEUP HIGH
tcpdump < 4.9.3 - Out-of-bounds Read in Rx Parser
The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_cache_insert().
CVSS 7.5
CVE-2018-14467 WRITEUP HIGH
tcpdump < 4.9.3 - Out-of-bounds Read in BGP Parser
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP).
CVSS 7.5
CVE-2018-14468 WRITEUP HIGH
tcpdump < 4.9.3 - Out-of-bounds Read in FRF.16 Parser
The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().
CVSS 7.5
CVE-2018-14469 WRITEUP HIGH
tcpdump < 4.9.3 - Out-of-bounds Read in IKEv1 Parser
The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().
CVSS 7.5
CVE-2018-14470 WRITEUP HIGH
tcpdump < 4.9.3 - Out-of-bounds Read in Babel Parser
The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2().
CVSS 7.5
CVE-2018-14718 WRITEUP CRITICAL
FasterXML Jackson <2.9.7 - Code Injection
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
CVSS 9.8
CVE-2018-14719 WRITEUP CRITICAL
FasterXML jackson-databind 2.0.0-2.6.7.2 - Remote Code Execution via BlazeDS Polymorphic Deserialization
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
CVSS 9.8
CVE-2018-14720 WRITEUP CRITICAL
FasterXML jackson-databind 2.6.0-2.6.7.1 - XML External Entity Injection via Polymorphic Deserialization
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
CVSS 9.8