|
246051
|
8.6 |
HIGH
Network
|
rockwellautomation
|
micrologix_1400_firmware 1756-enbt_firmware 1756-eweb_series_a_firmware 1756-eweb_series_b_firmware 1756-en2f_series_a_firmware 1756-en2f_series_b_firmware 1756-en2f_series_c_firmwa…
|
Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upo…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2018-17924
|
2024-11-21 12:55 |
2018-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246052
|
6.1 |
MEDIUM
Network
|
symantec
|
norton_password_manager
|
Norton Password Manager for Android (formerly Norton Identity Safe) may be susceptible to a cross site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-sid…
|
CWE-79
Cross-site Scripting
|
CVE-2018-18362
|
2024-11-21 12:55 |
2018-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246053
|
9.8 |
CRITICAL
Network
|
perl canonical debian redhat netapp
|
perl ubuntu_linux debian_linux enterprise_linux e-series_santricity_os_controller snap_creator_framework snapdrive snapcenter
|
Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-18312
|
2024-11-21 12:55 |
2018-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246054
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via Epic change descriptions.
|
CWE-200
Information Exposure
|
CVE-2018-17976
|
2024-11-21 12:55 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246055
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the GFM markdown API.
|
CWE-200
Information Exposure
|
CVE-2018-17975
|
2024-11-21 12:55 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246056
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the merge request JSON endpo…
|
CWE-200
Information Exposure
|
CVE-2018-17939
|
2024-11-21 12:55 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246057
|
9.8 |
CRITICAL
Network
|
teledynedalsa
|
sherlock
|
A stack-based buffer overflow vulnerability has been identified in Teledyne DALSA Sherlock Version 7.2.7.4 and prior, which may allow remote code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17930
|
2024-11-21 12:55 |
2018-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246058
|
6.4 |
MEDIUM
Physics
|
subaru
|
starlink_2017_firmware starlink_2018_firmware starlink_2019_firmware
|
A vulnerability in the update mechanism of Subaru StarLink Harman head units 2017, 2018, and 2019 may give an attacker (with physical access to the vehicle's USB ports) the ability to rewrite the fir…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2018-18203
|
2024-11-21 12:55 |
2018-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246059
|
9.8 |
CRITICAL
Network
|
nuuo
|
nuuo_cms
|
NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the server, which could allow remote code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-17936
|
2024-11-21 12:55 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246060
|
9.8 |
CRITICAL
Network
|
nuuo
|
nuuo_cms
|
NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. This could allow an attacker to impersona…
|
CWE-22
Path Traversal
|
CVE-2018-17934
|
2024-11-21 12:55 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|