|
247441
|
8.1 |
HIGH
Network
|
electronjs
|
electron
|
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnera…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2018-15685
|
2024-11-21 12:51 |
2018-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247442
|
6.5 |
MEDIUM
Network
|
hdfgroup
|
hdf5
|
An issue was discovered in the HDF HDF5 1.10.2 library. Excessive stack consumption has been detected in the function H5P__get_cb() in H5Pint.c during an attempted parse of a crafted HDF file. This r…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-15671
|
2024-11-21 12:51 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247443
|
4.3 |
MEDIUM
Network
|
bloop
|
airmail
|
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolicyForNavigationAction:request:frame:decisionListener:" such that OpenURL is the …
|
CWE-20
Improper Input Validation
|
CVE-2018-15670
|
2024-11-21 12:51 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247444
|
5.3 |
MEDIUM
Network
|
bloop
|
airmail_3
|
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolicyForNavigationAction:request:frame:decisionListener:" such that requests from H…
|
NVD-CWE-noinfo
|
CVE-2018-15669
|
2024-11-21 12:51 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247445
|
5.3 |
MEDIUM
Network
|
bloop
|
airmail_3
|
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. The "send" command in the airmail:// URL scheme allows an external application to send arbitrary emails from an active account. URL paramet…
|
CWE-200
Information Exposure
|
CVE-2018-15668
|
2024-11-21 12:51 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247446
|
7.5 |
HIGH
Network
|
olacabs
|
ola_money
|
An issue was discovered in the Ola Money (aka com.olacabs.olamoney) application 1.9.0 for Android. If an attacker controls an application with accessibility permissions and the ability to read SMS me…
|
CWE-200
Information Exposure
|
CVE-2018-15661
|
2024-11-21 12:51 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247447
|
5.9 |
MEDIUM
Network
|
olacabs
|
olamoney
|
An issue was discovered in the Ola Money (aka com.olacabs.olamoney) application 1.9.0 for Android. If an attacker controls an application with accessibility permissions, then the attacker can read ce…
|
NVD-CWE-noinfo
|
CVE-2018-15660
|
2024-11-21 12:51 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247448
|
7.5 |
HIGH
Network
|
airmailapp
|
airmail
|
An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. It registers and uses the airmail:// URL scheme. The "send" command in the URL scheme allows an external application to send arbitrary emai…
|
CWE-287
Improper Authentication
|
CVE-2018-15667
|
2024-11-21 12:51 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247449
|
9.8 |
CRITICAL
Network
|
geutebrueck
|
re_porter_16_firmware
|
Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information including usernames and hashes via a direct request for /statistics/gscsetup.xml on TCP…
|
CWE-200
Information Exposure
|
CVE-2018-15534
|
2024-11-21 12:51 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247450
|
6.1 |
MEDIUM
Network
|
geutebrueck
|
re_porter_16_firmware
|
A reflected cross-site scripting vulnerability exists in Geutebrueck re_porter 16 before 7.8.974.20 by appending a query string to /modifychannel/exec or /images/*.png on TCP port 12005.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15533
|
2024-11-21 12:51 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|