|
248291
|
9.8 |
CRITICAL
Network
|
rsyslog debian canonical redhat
|
librelp debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server enterpr…
|
rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-1000140
|
2024-11-21 12:39 |
2018-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248292
|
6.1 |
MEDIUM
Network
|
i-librarian
|
i_librarian
|
I, Librarian version 4.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in "id" parameter in stable.php that can result in an attacker using the XSS to send a malicious script to an …
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000139
|
2024-11-21 12:39 |
2018-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248293
|
9.1 |
CRITICAL
Network
|
i-librarian
|
i_librarian
|
I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php that can result in the attacker abusing functionality on the server to read or upd…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-1000138
|
2024-11-21 12:39 |
2018-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248294
|
8.8 |
HIGH
Network
|
i-librarian
|
i_librarian
|
I, Librarian version 4.8 and earlier contains a Cross site Request Forgery (CSRF) vulnerability in users.php that can result in the password of the admin being forced to be changed without the admini…
|
CWE-352
Origin Validation Error
|
CVE-2018-1000137
|
2024-11-21 12:39 |
2018-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248295
|
8.1 |
HIGH
Network
|
electronjs
|
electron
|
Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Webviews that can result in remote code execution. This attack…
|
CWE-20
Improper Input Validation
|
CVE-2018-1000136
|
2024-11-21 12:39 |
2018-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248296
|
7.5 |
HIGH
Network
|
gnome canonical
|
networkmanager ubuntu_linux
|
GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DNS queries leaked to local network's DNS servers, w…
|
CWE-200
Information Exposure
|
CVE-2018-1000135
|
2024-11-21 12:39 |
2018-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248297
|
7.5 |
HIGH
Network
|
secluded
|
trident
|
Pitchfork version 1.4.6 RC1 contains an Improper Privilege Management vulnerability in Trident Pitchfork components that can result in A standard unprivileged user could gain system administrator per…
|
CWE-269
Improper Privilege Management
|
CVE-2018-1000133
|
2024-11-21 12:39 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248298
|
9.8 |
CRITICAL
Network
|
pingidentity
|
ldapsdk
|
UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, where the issue was reported and fixed contains an Incorrect Acc…
|
CWE-521
Weak Password Requirements
|
CVE-2018-1000134
|
2024-11-21 12:39 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248299
|
9.1 |
CRITICAL
Network
|
debian canonical haxx redhat oracle
|
debian_linux ubuntu_linux curl enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_manager_ops_center peoplesoft_enterprise_peopletools co…
|
A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage
|
CWE-125
Out-of-bounds Read
|
CVE-2018-1000122
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248300
|
7.5 |
HIGH
Network
|
debian canonical haxx redhat oracle
|
debian_linux ubuntu_linux curl enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_manager_ops_center peoplesoft_enterprise_peopletools co…
|
A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-1000121
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|