|
247441
|
8.8 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an administrator can send emails to his/her account when there are changes to the device's network. Howe…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10695
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247442
|
8.1 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and does not use any encryption mechanism by default. An administrator who uses the open wir…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2018-10694
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247443
|
7.5 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, the same functionality allows an attacker to downloa…
|
CWE-284
Improper Access Control
|
CVE-2018-10691
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247444
|
8.1 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insecure communication mechanism for a user connecting to the web server. This allow…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2018-10690
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247445
|
6.1 |
MEDIUM
Network
|
lantronix
|
securelinx_spider_firmware
|
Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10383
|
2024-11-21 12:41 |
2019-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247446
|
9.8 |
CRITICAL
Network
|
oisf
|
suricata
|
Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in app-layer-enip-comm…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-10244
|
2024-11-21 12:41 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247447
|
9.8 |
CRITICAL
Network
|
oisf
|
libhtp
|
htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-10243
|
2024-11-21 12:41 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247448
|
7.5 |
HIGH
Network
|
oisf debian
|
suricata debian_linux
|
Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-10242
|
2024-11-21 12:41 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247449
|
9.8 |
CRITICAL
Network
|
codesys
|
control_for_beaglebone_sl control_for_empc-a\/imx6_sl control_for_iot2000_sl control_for_linux_sl control_for_pfc100_sl control_for_pfc200_sl control_for_raspberry_pi_sl control_…
|
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker…
|
CWE-311 CWE-732
Missing Encryption of Sensitive Data Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10612
|
2024-11-21 12:41 |
2019-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247450
|
7.2 |
HIGH
Network
|
netgain-systems
|
enterprise_manager
|
NetGain Enterprise Manager (EM) is affected by OS Command Injection vulnerabilities in versions before 10.0.57. These vulnerabilities could allow remote authenticated attackers to inject arbitrary co…
|
CWE-78
OS Command
|
CVE-2018-10587
|
2024-11-21 12:41 |
2018-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|