|
248381
|
7.8 |
HIGH
Local
|
unzip_project
|
unzip
|
A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve co…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-1000035
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248382
|
9.1 |
CRITICAL
Network
|
info-zip
|
unzip
|
An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-1000034
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248383
|
9.1 |
CRITICAL
Network
|
info-zip
|
unzip
|
An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-1000033
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248384
|
7.8 |
HIGH
Local
|
info-zip
|
unzip
|
A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-1000032
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248385
|
7.8 |
HIGH
Local
|
info-zip
|
unzip
|
A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-1000031
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248386
|
6.1 |
MEDIUM
Network
|
elsa_project
|
elsa
|
mcholste Enterprise Log Search and Archive (ELSA) version revision 1205, commit 2cc17f1 and earlier contains a Cross Site Scripting (XSS) vulnerability in index view (/) that can result in . This att…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000029
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248387
|
7.4 |
HIGH
Network
|
linux
|
linux_kernel
|
Linux kernel version after commit bdcf0a423ea1 - 4.15-rc4+, 4.14.8+, 4.9.76+, 4.4.111+ contains a Incorrect Access Control vulnerability in NFS server (nfsd) that can result in remote users reading o…
|
CWE-269
Improper Privilege Management
|
CVE-2018-1000028
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248388
|
7.5 |
HIGH
Network
|
squid-cache debian canonical
|
squid debian_linux ubuntu_linux
|
The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Response X-Forwarded-For header processing that can re…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-1000027
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248389
|
7.7 |
HIGH
Network
|
linux canonical redhat debian
|
linux_kernel ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server debian_linux
|
Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmwar…
|
CWE-20
Improper Input Validation
|
CVE-2018-1000026
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248390
|
8.1 |
HIGH
Network
|
firebase_admin_sdk_for_php_project
|
firebase_admin_sdk_for_php
|
Jerome Gamez Firebase Admin SDK for PHP version from 3.2.0 to 3.8.0 contains a Incorrect Access Control vulnerability in src/Firebase/Auth/IdTokenVerifier.php does not verify for token signature that…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-1000025
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|