|
247471
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. The diff formatter using rouge can block for a long time in Sidekiq j…
|
NVD-CWE-noinfo
|
CVE-2018-15472
|
2024-11-21 12:50 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247472
|
7.5 |
HIGH
Network
|
tcpdump redhat debian opensuse fedoraproject f5 apple
|
tcpdump enterprise_linux debian_linux leap fedora traffix_signaling_delivery_controller mac_os_x
|
The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-14882
|
2024-11-21 12:50 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247473
|
5.3 |
MEDIUM
Network
|
totemo
|
totemomail
|
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role.
|
CWE-284
Improper Access Control
|
CVE-2018-15513
|
2024-11-21 12:50 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247474
|
6.1 |
MEDIUM
Network
|
totemo
|
totemomail
|
Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15512
|
2024-11-21 12:50 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247475
|
6.1 |
MEDIUM
Network
|
totemo
|
totemomail
|
Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15511
|
2024-11-21 12:50 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247476
|
6.1 |
MEDIUM
Network
|
totemo
|
totemomail
|
Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15510
|
2024-11-21 12:50 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247477
|
7.5 |
HIGH
Network
|
loytec
|
lgate-902_firmware
|
LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2018-14918
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247478
|
9.1 |
CRITICAL
Network
|
loytec
|
lgate-902_firmware
|
LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-14916
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247479
|
6.5 |
MEDIUM
Network
|
odoo
|
odoo
|
Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows a remote attacker to deny access to the service and …
|
CWE-20
Improper Input Validation
|
CVE-2018-14887
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247480
|
4.9 |
MEDIUM
Network
|
odoo
|
odoo
|
The module-description renderer in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier does not disable RST's local file inclusion, which allows privileged authenticated users to rea…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-14886
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|