|
246141
|
8.8 |
HIGH
Network
|
s-cms
|
s-cms
|
s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the robots.php txt parameter.
|
CWE-94
Code Injection
|
CVE-2018-18426
|
2024-11-21 12:55 |
2018-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246142
|
8.8 |
HIGH
Network
|
usualtool
|
usualtoolcms
|
UsualToolCMS 8.0 allows CSRF for adding a user account via the cmsadmin/a_adminx.php?x=a URI.
|
CWE-352
Origin Validation Error
|
CVE-2018-18422
|
2024-11-21 12:55 |
2018-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246143
|
5.5 |
MEDIUM
Local
|
digitalcorpora fedoraproject canonical
|
tcpflow fedora ubuntu_linux
|
A stack-based buffer over-read exists in setbit() at iptree.h of TCPFLOW 1.5.0, due to received incorrect values causing incorrect computation, leading to denial of service during an address_histogra…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-18409
|
2024-11-21 12:55 |
2018-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246144
|
9.8 |
CRITICAL
Network
|
broadcom fedoraproject
|
tcpreplay fedora
|
A use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1. The issue gets triggered in the function post_args() at tcpbridge.c, causing a denial of service or possibly unspecif…
|
CWE-416
Use After Free
|
CVE-2018-18408
|
2024-11-21 12:55 |
2018-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246145
|
5.5 |
MEDIUM
Local
|
broadcom fedoraproject
|
tcpreplay fedora
|
A heap-based buffer over-read was discovered in the tcpreplay-edit binary of Tcpreplay 4.3.0 beta1, during the incremental checksum operation. The issue gets triggered in the function csum_replace4()…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-18407
|
2024-11-21 12:55 |
2018-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246146
|
7.8 |
HIGH
Local
|
lcds
|
laquis_scada
|
LAquis SCADA Versions 4.1.0.3870 and prior has several stack-based buffer overflow vulnerabilities, which may allow remote code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17911
|
2024-11-21 12:55 |
2018-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246147
|
7.8 |
HIGH
Local
|
lcds
|
laquis_scada
|
LAquis SCADA Versions 4.1.0.3870 and prior, when processing project files the application fails to sanitize user input prior to performing write operations on a stack object, which may allow an attac…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17901
|
2024-11-21 12:55 |
2018-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246148
|
8.8 |
HIGH
Network
|
lcds
|
laquis_scada
|
LAquis SCADA Versions 4.1.0.3870 and prior has a path traversal vulnerability, which may allow remote code execution.
|
CWE-22
Path Traversal
|
CVE-2018-17899
|
2024-11-21 12:55 |
2018-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246149
|
9.8 |
CRITICAL
Network
|
lcds
|
laquis_scada
|
LAquis SCADA Versions 4.1.0.3870 and prior has several integer overflow to buffer overflow vulnerabilities, which may allow remote code execution.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-17897
|
2024-11-21 12:55 |
2018-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246150
|
9.8 |
CRITICAL
Network
|
lcds
|
laquis_scada
|
LAquis SCADA Versions 4.1.0.3870 and prior has several out-of-bounds read vulnerabilities, which may allow remote code execution.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-17895
|
2024-11-21 12:55 |
2018-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|