|
246321
|
7.5 |
HIGH
Network
|
haproxy canonical redhat
|
haproxy ubuntu_linux enterprise_linux openshift_container_platform openshift
|
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-14645
|
2024-11-21 12:49 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246322
|
9.8 |
CRITICAL
Network
|
theforeman
|
foreman
|
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vuln…
|
-
|
CVE-2018-14643
|
2024-11-21 12:49 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246323
|
9.8 |
CRITICAL
Network
|
cwjoomla
|
cw_article_attachments_free cw_article_attachments_pro
|
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.
|
CWE-89
SQL Injection
|
CVE-2018-14592
|
2024-11-21 12:49 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246324
|
9.8 |
CRITICAL
Network
|
rockwellautomation
|
rslinx
|
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to intentionally send a malformed CIP packet to Port 44818, causing the software appl…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14829
|
2024-11-21 12:49 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246325
|
7.5 |
HIGH
Network
|
rockwellautomation
|
rslinx
|
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. A remote, unauthenticated threat actor may intentionally send specially crafted Ethernet/IP packets to Port 44818, causing the software …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-14827
|
2024-11-21 12:49 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246326
|
7.5 |
HIGH
Network
|
rockwellautomation
|
rslinx
|
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote, unauthenticated threat actor to intentionally send a malformed CIP packet to Port 44818, causing …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14821
|
2024-11-21 12:49 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246327
|
7.5 |
HIGH
Network
|
tec4data
|
smartcooler_firmware
|
Tec4Data SmartCooler, all versions prior to firmware 180806, the device responds to a remote unauthenticated reboot command that may be used to perform a denial of service attack.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2018-14796
|
2024-11-21 12:49 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246328
|
6.3 |
MEDIUM
Network
|
we-con
|
plc_editor
|
WECON PLC Editor version 1.3.3U may allow an attacker to execute code under the current process when processing project files.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14792
|
2024-11-21 12:49 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246329
|
5.3 |
MEDIUM
Network
|
redhat
|
undertow jboss_enterprise_application_platform
|
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full con…
|
CWE-200
Information Exposure
|
CVE-2018-14642
|
2024-11-21 12:49 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246330
|
5.9 |
MEDIUM
Network
|
linux
|
linux_kernel
|
A security flaw was found in the ip_frag_reasm() function in net/ipv4/ip_fragment.c in the Linux kernel from 4.19-rc1 to 4.19-rc3 inclusive, which can cause a later system crash in ip_do_fragment(). …
|
CWE-20
Improper Input Validation
|
CVE-2018-14641
|
2024-11-21 12:49 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|