|
247131
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a crafted HTML page.
|
CWE-285
Improper Authorization
|
CVE-2018-16073
|
2024-11-21 12:52 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247132
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Integer overflows in Skia in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2018-16070
|
2024-11-21 12:52 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247133
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Unintended floating-point error accumulation in SwiftShader in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-16069
|
2024-11-21 12:52 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247134
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a…
|
CWE-20
Improper Input Validation
|
CVE-2018-16064
|
2024-11-21 12:52 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247135
|
8.1 |
HIGH
Network
|
sophos
|
sfos
|
A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attackers to execute arbitrary OS commands via shell metac…
|
CWE-78
OS Command
|
CVE-2018-16118
|
2024-11-21 12:52 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247136
|
8.8 |
HIGH
Network
|
sophos
|
sfos
|
A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary OS commands via shell metacharacters…
|
CWE-78
OS Command
|
CVE-2018-16117
|
2024-11-21 12:52 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247137
|
8.8 |
HIGH
Network
|
sophos
|
sfos
|
SQL injection vulnerability in AccountStatus.jsp in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary SQL commands via the "username" GET parame…
|
CWE-89
SQL Injection
|
CVE-2018-16116
|
2024-11-21 12:52 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247138
|
6.1 |
MEDIUM
Network
|
b3log
|
solo
|
b3log Solo 2.9.3 has XSS in the Input page under the "Publish Articles" menu with an ID of "articleTags" stored in the "tag" JSON field, which allows remote attackers to inject arbitrary Web scripts …
|
CWE-79
Cross-site Scripting
|
CVE-2018-16248
|
2024-11-21 12:52 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247139
|
5.4 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
YzmCMS 5.1 has XSS via the admin/system_manage/user_config_add.html title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16247
|
2024-11-21 12:52 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247140
|
7.2 |
HIGH
Network
|
tp-link
|
tl-wr1043nd_firmware
|
Stack-based buffer overflow in the httpd server of TP-Link WR1043nd (Firmware Version 3) allows remote attackers to execute arbitrary code via a malicious MediaServer request to /userRpm/MediaServerF…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-16119
|
2024-11-21 12:52 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|