|
246071
|
9.8 |
CRITICAL
Network
|
circontrol
|
circarlife_firmware
|
Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible without authentication.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-17922
|
2024-11-21 12:55 |
2018-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246072
|
9.8 |
CRITICAL
Network
|
circontrol
|
circarlife_firmware
|
Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a specific page.
|
CWE-287
Improper Authentication
|
CVE-2018-17918
|
2024-11-21 12:55 |
2018-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246073
|
7.5 |
HIGH
Network
|
sauter-controls
|
case_suite
|
An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow remote file disclosure.
|
CWE-611
XXE
|
CVE-2018-17912
|
2024-11-21 12:55 |
2018-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246074
|
9.8 |
CRITICAL
Network
|
aveva
|
indusoft_web_studio intouch_machine_edition_2014 edge
|
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker could send a carefully crafted packet to exploit a…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17916
|
2024-11-21 12:55 |
2018-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246075
|
9.8 |
CRITICAL
Network
|
aveva
|
indusoft_web_studio intouch_machine_edition_2014 edge
|
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely e…
|
NVD-CWE-noinfo
|
CVE-2018-17914
|
2024-11-21 12:55 |
2018-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246076
|
8.8 |
HIGH
Network
|
vecna
|
vgo_firmware
|
VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) connected to the VGo XAMPP. User accounts may be able to execute commands that are outside the scope of their pri…
|
NVD-CWE-noinfo
|
CVE-2018-17933
|
2024-11-21 12:55 |
2018-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246077
|
6.8 |
MEDIUM
Physics
|
vecna
|
vgo_firmware
|
If an attacker has physical access to the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) they may be able to alter scripts, which may allow code execution with …
|
CWE-284
Improper Access Control
|
CVE-2018-17931
|
2024-11-21 12:55 |
2018-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246078
|
7.8 |
HIGH
Local
|
linux canonical debian
|
linux_kernel ubuntu_linux debian_linux
|
Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the…
|
CWE-459
Incomplete Cleanup
|
CVE-2018-18281
|
2024-11-21 12:55 |
2018-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246079
|
8.8 |
HIGH
Network
|
playsms_project
|
playsms
|
playSMS through 1.4.2 allows Privilege Escalation through Daemon abuse.
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2018-18387
|
2024-11-21 12:55 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246080
|
7.8 |
HIGH
Local
|
advantech
|
webaccess
|
WebAccess Versions 8.3.2 and prior. The application fails to properly validate the length of user-supplied data, causing a buffer overflow condition that allows for arbitrary remote code execution.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-17910
|
2024-11-21 12:55 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|