|
247531
|
5.3 |
MEDIUM
Adjacent
|
mimobaby
|
mimo_baby_2_firmware
|
Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turtle to a Lilypad, which allows attackers to inject fake information about the po…
|
CWE-287 CWE-311
Improper Authentication Missing Encryption of Sensitive Data
|
CVE-2018-10825
|
2024-11-21 12:42 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247532
|
7.5 |
HIGH
Network
|
libav
|
libav
|
An issue was discovered in Libav 12.3. A read access violation in the mov_probe function in libavformat/mov.c allows remote attackers to cause a denial of service (application crash), as demonstrated…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-11102
|
2024-11-21 12:42 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247533
|
8.8 |
HIGH
Network
|
libming
|
libming
|
The decompileSETTARGET function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-11100
|
2024-11-21 12:42 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247534
|
7.2 |
HIGH
Network
|
frog_cms_project
|
frog_cms
|
An issue was discovered in Frog CMS 0.9.5. There is a file upload vulnerability via the admin/?/plugin/file_manager/upload URI, a similar issue to CVE-2014-4912.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-11098
|
2024-11-21 12:42 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247535
|
7.5 |
HIGH
Network
|
cstring_project
|
cstring
|
An issue was discovered in cloudwu/cstring through 2016-11-09. There is a memory leak vulnerability that could lead to a program crash.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-11097
|
2024-11-21 12:42 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247536
|
8.8 |
HIGH
Network
|
libming
|
libming
|
The decompileJUMP function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, which allows remote attackers to cause a denia…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-11095
|
2024-11-21 12:42 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247537
|
6.1 |
MEDIUM
Network
|
mybiz
|
myprocurenet
|
An XSS issue was discovered in MyBiz MyProcureNet 5.0.0. This vulnerability within "ProxyPage.aspx" allows an attacker to inject malicious client side scripting which will be executed in the browser …
|
CWE-79
Cross-site Scripting
|
CVE-2018-11090
|
2024-11-21 12:42 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247538
|
6.1 |
MEDIUM
Network
|
signal
|
signal-desktop
|
js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10994
|
2024-11-21 12:42 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247539
|
9.9 |
CRITICAL
Network
|
mybiz
|
myprocurenet
|
An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. It is possible for an attacker to upload a script to issue operating system comm…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-11091
|
2024-11-21 12:42 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247540
|
6.6 |
MEDIUM
Network
|
commscope
|
arris_tg1682g_firmware
|
Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices are distributed by some ISPs with a default password of "password" for the admin account that is used over an unencrypted http://192.168.0…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2018-10989
|
2024-11-21 12:42 |
2018-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|