|
246611
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_835_firmware sd_845_firmware sd_850_firmware sda660_firmware
|
A stack-based buffer overflow can occur in a firmware routine in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835, SD 845, SD 850, SDA660
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11824
|
2024-11-21 12:44 |
2018-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246612
|
7.8 |
HIGH
Local
|
qualcomm
|
sd_835_firmware sd_845_firmware sd_850_firmware sda660_firmware
|
A possible integer overflow may happen in WLAN during memory allocation in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-11822
|
2024-11-21 12:44 |
2018-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246613
|
7.8 |
HIGH
Local
|
qualcomm
|
ipq8074_firmware mdm9206_firmware mdm9607_firmware mdm9650_firmware sd_425_firmware sd_427_firmware sd_430_firmware sd_435_firmware sd_450_firmware sd_625_firmware sd_65…
|
Possible integer overflow may happen in WLAN during memory allocation in Snapdragon Mobile, Snapdragon Wear in version IPQ8074, MDM9206, MDM9607, MDM9650, SD 425, SD 427, SD 430, SD 435, SD 450, SD 6…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-11821
|
2024-11-21 12:44 |
2018-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246614
|
9.8 |
CRITICAL
Network
|
apache
|
impala
|
In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allow…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-11792
|
2024-11-21 12:44 |
2018-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246615
|
6.5 |
MEDIUM
Network
|
apache
|
impala
|
Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to inject random data into a running query, leading to wrong results for a query.
|
CWE-862
Missing Authorization
|
CVE-2018-11785
|
2024-11-21 12:44 |
2018-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246616
|
7.5 |
HIGH
Network
|
apache
|
spark
|
Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has been included in release branches since 1.3.x, up to…
|
NVD-CWE-noinfo
|
CVE-2018-11804
|
2024-11-21 12:44 |
2018-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246617
|
6.1 |
MEDIUM
Network
|
symantec
|
web_isolation
|
Symantec Web Isolation (WI) 1.11 prior to 1.11.21 is susceptible to a reflected cross-site scripting (XSS) vulnerability. A remote attacker can target end users protected by WI with social engineerin…
|
CWE-79
Cross-site Scripting
|
CVE-2018-12246
|
2024-11-21 12:44 |
2018-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246618
|
5.5 |
MEDIUM
Local
|
intel
|
graphics_driver
|
Denial of Service in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.5057 (aka 15.36.x.5057) and 20.19.x.5058 (aka 15.40.x.5058) may allow an unprivi…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-12154
|
2024-11-21 12:44 |
2018-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246619
|
5.5 |
MEDIUM
Local
|
intel
|
quickassist_technology
|
Insufficient access control in driver stack for Intel QuickAssist Technology for Linux before version 4.2 may allow an unprivileged user to potentially disclose information via local access.
|
NVD-CWE-noinfo
|
CVE-2018-12193
|
2024-11-21 12:44 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246620
|
7.6 |
HIGH
Physics
|
intel
|
server_board_s2600bp_firmware server_board_s2600wf_firmware server_board_s2600st_firmware server_board_s2600bpr_firmware server_board_s2600wfr_firmware server_board_s2600str_firmware
|
Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before firmware version 00.01.0014 may allow an unauthenticated attacker to potentially …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-12173
|
2024-11-21 12:44 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|