|
247971
|
5.5 |
MEDIUM
Local
|
asus
|
zenfone_3_max_firmware
|
The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-keys contains a pre-installed platform app with a p…
|
NVD-CWE-noinfo
|
CVE-2018-14992
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247972
|
7.5 |
HIGH
Network
|
mxq_project
|
mxq_tv_box_firmware
|
The MXQ TV Box 4.4.2 Android device with a build fingerprint of MBX/m201_N/m201_N:4.4.2/KOT49H/20160106:user/test-keys contains the Android framework with a package name of android (versionCode=19, v…
|
CWE-20
Improper Input Validation
|
CVE-2018-14988
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247973
|
7.1 |
HIGH
Local
|
mxq_project
|
mxq_tv_box_firmware
|
The MXQ TV Box 4.4.2 Android device with a build fingerprint of MBX/m201_N/m201_N:4.4.2/KOT49H/20160106:user/test-keys contains the Android framework with a package name of android (versionCode=19, v…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-14987
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247974
|
7.5 |
HIGH
Network
|
leagoo
|
z5c_firmware
|
The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.m…
|
CWE-200
Information Exposure
|
CVE-2018-14986
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247975
|
7.1 |
HIGH
Local
|
leagoo
|
z5c_firmware
|
The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed platform app with a package name of com.…
|
NVD-CWE-noinfo CWE-862
Missing Authorization
|
CVE-2018-14985
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247976
|
7.5 |
HIGH
Network
|
leagoo
|
z5c_firmware
|
The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.m…
|
CWE-200
Information Exposure
|
CVE-2018-14984
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247977
|
4.7 |
MEDIUM
Local
|
asus
|
zenfone_3_max_firmware
|
The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-keys contains a pre-installed app with a package na…
|
CWE-200
Information Exposure
|
CVE-2018-14979
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247978
|
5.9 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
When APM 13.0.0-13.1.x is deployed as an OAuth Resource Server, APM becomes a client application to an external OAuth authorization server. In certain cases when communication between the BIG-IP APM …
|
NVD-CWE-noinfo
|
CVE-2018-15335
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247979
|
4.3 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
A cross-site request forgery (CSRF) vulnerability in the APM webtop 11.2.1 or greater may allow attacker to force an APM webtop session to log out and require re-authentication.
|
CWE-352
Origin Validation Error
|
CVE-2018-15334
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247980
|
5.5 |
MEDIUM
Local
|
f5
|
big-ip_local_traffic_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_access_policy_manager big-ip_domain_name_system big-ip_…
|
On versions 11.2.1. and greater, unrestricted Snapshot File Access allows BIG-IP system's user with any role, including Guest Role, to have access and download previously generated and available snap…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-15333
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|