|
247371
|
7.5 |
HIGH
Network
|
barco
|
clickshare_cse-200_firmware clickshare_cs-100_firmware
|
An issue was discovered on Barco ClickShare CSE-200 and CS-100 Base Units with firmware before 1.6.0.3. Sending an arbitrary unexpected string to TCP port 7100 respecting a certain frequency timing d…
|
CWE-20
Improper Input Validation
|
CVE-2018-10943
|
2024-11-21 12:42 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247372
|
6.5 |
MEDIUM
Network
|
libgit2 debian
|
libgit2 debian_linux
|
A flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead to an out-of-bound read while reading a binary delta file. An attacker may use…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-10888
|
2024-11-21 12:42 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247373
|
8.1 |
HIGH
Network
|
libgit2 debian
|
libgit2 debian_linux
|
A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c file may lead to an integer overflow which in turn l…
|
CWE-125 CWE-190 CWE-681
Out-of-bounds Read Integer Overflow or Wraparound Incorrect Conversion between Numeric Types
|
CVE-2018-10887
|
2024-11-21 12:42 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247374
|
8.1 |
HIGH
Network
|
ceph redhat opensuse debian
|
ceph enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server ceph_storage_osd ceph_storage_mon ceph_storage leap debian_linux
|
A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches mas…
|
CWE-287
Improper Authentication
|
CVE-2018-10861
|
2024-11-21 12:42 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247375
|
5.3 |
MEDIUM
Network
|
docker mobyproject redhat opensuse
|
docker moby enterprise_linux enterprise_linux_server openstack leap
|
The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disa…
|
-
|
CVE-2018-10892
|
2024-11-21 12:42 |
2018-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247376
|
5.4 |
MEDIUM
Network
|
opmantek
|
open-audit
|
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted attribut…
|
CWE-79
Cross-site Scripting
|
CVE-2018-11124
|
2024-11-21 12:42 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247377
|
7.8 |
HIGH
Local
|
diqee
|
diqee360_firmware
|
An issue was discovered on Diqee Diqee360 devices. A firmware update process, integrated into the firmware, starts at boot and tries to find the update folder on the microSD card. It executes code, w…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2018-10988
|
2024-11-21 12:42 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247378
|
7.5 |
HIGH
Network
|
diqee
|
diqee360_firmware
|
An issue was discovered on Dongguan Diqee Diqee360 devices. The affected vacuum cleaner suffers from an authenticated remote code execution vulnerability. An authenticated attacker can send a special…
|
CWE-78
OS Command
|
CVE-2018-10987
|
2024-11-21 12:42 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247379
|
7.5 |
HIGH
Network
|
redhat
|
openshift
|
In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash when using ovs-networkpolicy plugin. An attacker can use this flaw to cause a D…
|
CWE-20
Improper Input Validation
|
CVE-2018-10885
|
2024-11-21 12:42 |
2018-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247380
|
9.8 |
CRITICAL
Network
|
dellemc
|
elastic_cloud_storage
|
Dell EMC ECS versions 3.2.0.0 and 3.2.0.1 contain an authentication bypass vulnerability. A remote unauthenticated attacker could exploit this vulnerability to read and modify S3 objects by supplying…
|
CWE-287
Improper Authentication
|
CVE-2018-11052
|
2024-11-21 12:42 |
2018-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|