|
245991
|
6.2 |
MEDIUM
Physics
|
symantec
|
norton_app_lock
|
Norton App Lock prior to 1.4.0.445 can be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking the device, th…
|
NVD-CWE-noinfo
|
CVE-2018-18363
|
2024-11-21 12:55 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245992
|
7.3 |
HIGH
Local
|
intel
|
sgx_platform_software sgx_sdk
|
Improper file verification in install routine for Intel(R) SGX SDK and Platform Software for Windows before 2.2.100 may allow an escalation of privilege via local access.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-18098
|
2024-11-21 12:55 |
2019-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245993
|
6.1 |
MEDIUM
Network
|
vivotek
|
camera
|
Cross-site scripting in syslog.html in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript code via an HTTP Referer Header.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18244
|
2024-11-21 12:55 |
2019-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245994
|
6.1 |
MEDIUM
Network
|
vivotek
|
camera
|
Cross-site scripting in event_script.js in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript via a URL query string parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18005
|
2024-11-21 12:55 |
2019-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245995
|
5.3 |
MEDIUM
Network
|
vivotek
|
camera
|
Incorrect Access Control in mod_inetd.cgi in VIVOTEK Network Camera Series products with firmware before XXXXXX-VVTK-0X09a allows remote attackers to enable arbitrary system services via a URL parame…
|
CWE-862
Missing Authorization
|
CVE-2018-18004
|
2024-11-21 12:55 |
2019-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245996
|
7.5 |
HIGH
Network
|
kubernetes
|
dashboard
|
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2018-18264
|
2024-11-21 12:55 |
2019-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245997
|
7.5 |
HIGH
Network
|
hashheroes
|
hashheroes
|
The determineWinner function of a smart contract implementation for HashHeroes Tiles, an Ethereum game, uses a certain blockhash value in an attempt to generate a random number for the case where NUM…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2018-17987
|
2024-11-21 12:55 |
2018-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245998
|
7.8 |
HIGH
Local
|
suse
|
repository_mirroring_tool
|
The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwords on process commandline, allowing local attackers to access or corrupt the R…
|
CWE-287
Improper Authentication
|
CVE-2018-17957
|
2024-11-21 12:55 |
2018-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245999
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-140l_firmware dir-640l_firmware
|
dirary0.js on D-Link DIR-140L, DIR-640L devices allows remote unauthenticated attackers to discover admin credentials.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-18009
|
2024-11-21 12:55 |
2018-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246000
|
9.8 |
CRITICAL
Network
|
dlink
|
dsl-2770l_firmware dir-140l_firmware dir-640l_firmware dwr-116_firmware dwr-512_firmware dwr-555_firmware dwr-921_firmware
|
spaces.htm on multiple D-Link devices (DSL, DIR, DWR) allows remote unauthenticated attackers to discover admin credentials.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-18008
|
2024-11-21 12:55 |
2018-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|