|
247181
|
5.5 |
MEDIUM
Local
|
puppet
|
cisco_ios
|
Previous releases of the Puppet cisco_ios module output SSH session debug information including login credentials to a world readable file on every run. These issues have been resolved in the 0.4.0 r…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-11752
|
2024-11-21 12:43 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247182
|
6.5 |
MEDIUM
Network
|
puppet
|
cisco_ios_module
|
Previous releases of the Puppet cisco_ios module did not validate a host's identity before starting a SSH connection. As of the 0.4.0 release of cisco_ios, host key checking is enabled by default.
|
CWE-20
Improper Input Validation
|
CVE-2018-11750
|
2024-11-21 12:43 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247183
|
7.8 |
HIGH
Local
|
puppet
|
device_manager
|
Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world readable. This issue has been resolved as of device_manager 2.7.0.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-11748
|
2024-11-21 12:43 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247184
|
5.9 |
MEDIUM
Network
|
apache canonical redhat oracle netapp
|
http_server ubuntu_linux enterprise_linux retail_xstore_point_of_service hospitality_guest_access enterprise_manager_ops_center secure_global_desktop instantis_enterprisetrack
|
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This…
|
NVD-CWE-noinfo
|
CVE-2018-11763
|
2024-11-21 12:43 |
2018-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247185
|
8.8 |
HIGH
Network
|
samsung
|
samsung_members
|
This vulnerability allows remote attackers to escalate privileges on vulnerable installations of Samsung Members Fixed in version 2.4.25. An attacker must first obtain the ability to execute low-priv…
|
NVD-CWE-noinfo
|
CVE-2018-11614
|
2024-11-21 12:43 |
2018-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247186
|
4.0 |
MEDIUM
Network
|
wallabag
|
wallabag
|
The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScr…
|
CWE-79
Cross-site Scripting
|
CVE-2018-11352
|
2024-11-21 12:43 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247187
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8909w_firmware msm8996au_firmware qca6574au_firmware qca6584_firmware sd210_firmware sd212_firmware
|
In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCA6574AU, QCA6584, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 45…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2018-11292
|
2024-11-21 12:43 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247188
|
7.5 |
HIGH
Network
|
qualcomm
|
ipq8074_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8996au_firmware qca4531_firmware qca6174a_firmware qca6564_firmware qca6574_firmware…
|
In Snapdragon (Automobile, Mobile, Wear) in version IPQ8074, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA4531, QCA6174A, QCA6564, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA93…
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2018-11291
|
2024-11-21 12:43 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247189
|
7.5 |
HIGH
Network
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8996au_firmware qca6574au_firmware sd210_firmware sd212_firmware sd205_firmware sd425_firmware sd4…
|
In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, QCA6584, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52,…
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2018-11290
|
2024-11-21 12:43 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247190
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware msm8909w_firmware msm8996au_firmware sd210_firmware sd212_firmware sd205_firmware sd425_firmware sd427_firmware sd430_…
|
In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, S…
|
CWE-20
Improper Input Validation
|
CVE-2018-11287
|
2024-11-21 12:43 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|