|
247651
|
9.8 |
CRITICAL
Network
|
adobe redhat
|
flash_player_desktop_runtime flash_player enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2018-15981
|
2024-11-21 12:51 |
2018-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247652
|
7.5 |
HIGH
Network
|
adobe
|
photoshop_cc
|
Adobe Photoshop CC versions 19.1.6 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-15980
|
2024-11-21 12:51 |
2018-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247653
|
7.5 |
HIGH
Network
|
adobe
|
acrobat_dc acrobat_reader_dc
|
Adobe Acrobat and Reader versions 2019.008.20080 and earlier, 2017.011.30105 and earlier, and 2015.006.30456 and earlier have a ntlm sso hash theft vulnerability. Successful exploitation could lead t…
|
CWE-200
Information Exposure
|
CVE-2018-15979
|
2024-11-21 12:51 |
2018-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247654
|
7.5 |
HIGH
Network
|
adobe redhat
|
flash_player_desktop_runtime flash_player enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Flash Player versions 31.0.0.122 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-15978
|
2024-11-21 12:51 |
2018-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247655
|
8.8 |
HIGH
Network
|
pivotal_software
|
cloudfoundry_uaa_release cloud_foundry_uaa
|
Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the ur…
|
NVD-CWE-noinfo
|
CVE-2018-15761
|
2024-11-21 12:51 |
2018-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247656
|
9.8 |
CRITICAL
Network
|
pivotal_software
|
on_demand_services_sdk broker_api
|
Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials. A remote unauthenticated malicious user may make many requests to the service…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2018-15759
|
2024-11-21 12:51 |
2018-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247657
|
7.5 |
HIGH
Network
|
dell oracle
|
bsafe jd_edwards_enterpriseone_tools security_service enterprise_manager_ops_center application_testing_suite retail_predictive_application_server communications_ip_service_activato…
|
RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in 4.0.x series) and versions prior to 4.1.6.2 (in 4.1.x series) contain a key management error issue. A malicious TLS server could potentially…
|
NVD-CWE-noinfo
|
CVE-2018-15769
|
2024-11-21 12:51 |
2018-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247658
|
6.4 |
MEDIUM
Network
|
inova-software
|
inova_partner
|
Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass via insecure direct object reference.
|
CWE-863
Incorrect Authorization
|
CVE-2018-15693
|
2024-11-21 12:51 |
2018-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247659
|
6.4 |
MEDIUM
Network
|
inova-software
|
inova_partner
|
Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass and data manipulation in certain functions.
|
CWE-863
Incorrect Authorization
|
CVE-2018-15692
|
2024-11-21 12:51 |
2018-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247660
|
6.1 |
MEDIUM
Network
|
nagios
|
nagios_xi
|
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15714
|
2024-11-21 12:51 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|