|
247381
|
7.8 |
HIGH
Local
|
debian canonical artifex redhat pulsesecure
|
debian_linux ubuntu_linux ghostscript gpl_ghostscript enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linu…
|
In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially exec…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2018-15911
|
2024-11-21 12:51 |
2018-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247382
|
7.8 |
HIGH
Local
|
debian canonical artifex redhat pulsesecure
|
debian_linux ubuntu_linux ghostscript gpl_ghostscript enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linu…
|
In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially e…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2018-15909
|
2024-11-21 12:51 |
2018-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247383
|
7.8 |
HIGH
Local
|
artifex debian canonical redhat
|
ghostscript debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_server_aus
|
In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.
|
NVD-CWE-noinfo
|
CVE-2018-15908
|
2024-11-21 12:51 |
2018-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247384
|
9.8 |
CRITICAL
Network
|
a10networks
|
acos_web_application_firewall
|
A10 ACOS Web Application Firewall (WAF) 2.7.1 and 2.7.2 before 2.7.2-P12, 4.1.0 before 4.1.0-P11, 4.1.1 before 4.1.1-P8, and 4.1.2 before 4.1.2-P4 mishandles the configured rules for blocking SQL inj…
|
CWE-89
SQL Injection
|
CVE-2018-15904
|
2024-11-21 12:51 |
2018-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247385
|
8.8 |
HIGH
Network
|
asus
|
dsl-n12e_c1_firmware
|
Main_Analysis_Content.asp in ASUS DSL-N12E_C1 1.1.2.3_345 is prone to Authenticated Remote Command Execution, which allows a remote attacker to execute arbitrary OS commands via service parameters, s…
|
CWE-78
OS Command
|
CVE-2018-15887
|
2024-11-21 12:51 |
2018-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247386
|
7.5 |
HIGH
Network
|
visiology
|
flipbox
|
Visiology Flipbox Software Suite before 2.7.0 allows directory traversal via %5c%2e%2e%2f because it does not sanitize filename parameters.
|
CWE-22
Path Traversal
|
CVE-2018-15810
|
2024-11-21 12:51 |
2018-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247387
|
6.1 |
MEDIUM
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in the middle can take advantage of this by inserting Javascript into the configura…
|
CWE-79
Cross-site Scripting
|
CVE-2018-15699
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247388
|
6.5 |
MEDIUM
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing the full path to loginimage.cgi.
|
CWE-200
Information Exposure
|
CVE-2018-15698
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247389
|
6.5 |
MEDIUM
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full path. For example, /home/admin/.ash_history.
|
CWE-200
Information Exposure
|
CVE-2018-15697
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247390
|
4.3 |
MEDIUM
Network
|
asustor
|
data_master
|
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi.
|
CWE-200
Information Exposure
|
CVE-2018-15696
|
2024-11-21 12:51 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|