|
252811
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8996au_firmware qca6174a_firmware qca6574au_firmware qca9377_firmware qca9379_firmwa…
|
Improper input validation on input which is used as an array index will lead to an out of bounds issue while processing AP find event from firmware in Snapdragon Auto, Snapdragon Consumer Electronics…
|
CWE-129
Improper Validation of Array Index
|
CVE-2018-11927
|
2024-11-21 12:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252812
|
7.8 |
HIGH
Local
|
qualcomm
|
ipq4019_firmware ipq8064_firmware ipq8074_firmware mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware qcs605_firmware sd_425_firmware s…
|
Data length received from firmware is not validated against the max allowed size which can result in buffer overflow. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Indus…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-11925
|
2024-11-21 12:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252813
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8996au_firmware qca6174a_firmware qca6574au_firmware qca9377_firmware qca9379_firmwa…
|
Improper buffer length validation in WLAN function can lead to a potential integer oveflow issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consu…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-11924
|
2024-11-21 12:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252814
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8996au_firmware qca6574au_firmware qcs605_firmware sd_425_firmware sd_427_firmware
|
Improper buffer length check before copying can lead to integer overflow and then a buffer overflow in WMA event handler in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon In…
|
CWE-119 CWE-190
Incorrect Access of Indexable Resource ('Range Error') Integer Overflow or Wraparound
|
CVE-2018-11923
|
2024-11-21 12:44 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252815
|
5.4 |
MEDIUM
Network
|
valvesoftware
|
steam_client
|
In Valve Steam 1528829181 BETA, it is possible to perform a homograph / homoglyph attack to create fake URLs in the client, which may trick users into visiting unintended web sites.
|
CWE-20
Improper Input Validation
|
CVE-2018-12270
|
2024-11-21 12:44 |
2019-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252816
|
6.1 |
MEDIUM
Network
|
seagate
|
nas_os
|
Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metadata fields: Short Description, Publisher Name, Publ…
|
CWE-79
Cross-site Scripting
|
CVE-2018-12304
|
2024-11-21 12:44 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252817
|
5.4 |
MEDIUM
Network
|
seagate
|
nas_os
|
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12303
|
2024-11-21 12:44 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252818
|
6.1 |
MEDIUM
Network
|
seagate
|
nas_os
|
Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12302
|
2024-11-21 12:44 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252819
|
7.5 |
HIGH
Network
|
seagate
|
nas_os
|
Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost.
|
CWE-200
Information Exposure
|
CVE-2018-12301
|
2024-11-21 12:44 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252820
|
6.1 |
MEDIUM
Network
|
seagate
|
nas_os
|
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.
|
CWE-601
Open Redirect
|
CVE-2018-12300
|
2024-11-21 12:44 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|