|
246531
|
7.5 |
HIGH
Network
|
enigmail
|
enigmail
|
The signature verification routine in Enigmail before 2.0.7 interprets user ids as status/control messages and does not correctly keep track of the status of multiple signatures, which allows remote …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2018-12019
|
2024-11-21 12:44 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246532
|
6.1 |
MEDIUM
Network
|
sensiolabs
|
symfony
|
Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _pro…
|
CWE-79
Cross-site Scripting
|
CVE-2018-12040
|
2024-11-21 12:44 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246533
|
6.8 |
MEDIUM
Physics
|
apollotechnologiesinc
|
momentum_axel_720p_firmware momentum_axel_720p
|
An issue was discovered on Momentum Axel 720P 5.1.8 devices. A password of EHLGVG is hard-coded for the root and admin accounts, which makes it easier for physically proximate attackers to login at t…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-12323
|
2024-11-21 12:44 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246534
|
5.5 |
MEDIUM
Local
|
radare
|
radare2
|
There is a heap out of bounds read in radare2 2.6.0 in _6502_op() in libr/anal/p/anal_6502.c via a crafted iNES ROM binary file.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-12322
|
2024-11-21 12:44 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246535
|
7.8 |
HIGH
Local
|
radare
|
radare2
|
There is a heap out of bounds read in radare2 2.6.0 in java_switch_op() in libr/anal/p/anal_java.c via a crafted Java binary file.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-12321
|
2024-11-21 12:44 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246536
|
7.8 |
HIGH
Local
|
radare
|
radare2
|
There is a use after free in radare2 2.6.0 in r_anal_bb_free() in libr/anal/bb.c via a crafted Java binary file.
|
CWE-416
Use After Free
|
CVE-2018-12320
|
2024-11-21 12:44 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246537
|
8.2 |
HIGH
Local
|
qemu canonical redhat debian
|
qemu ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_eus openstack enterprise_linux_server_tus enterprise_linux_ser…
|
m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11806
|
2024-11-21 12:44 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246538
|
9.8 |
CRITICAL
Network
|
palemoon
|
pale_moon
|
A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.
|
CWE-416
Use After Free
|
CVE-2018-12292
|
2024-11-21 12:44 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246539
|
7.5 |
HIGH
Network
|
matrix
|
synapse
|
The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied …
|
NVD-CWE-noinfo
|
CVE-2018-12291
|
2024-11-21 12:44 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246540
|
6.1 |
MEDIUM
Network
|
yii2-statemachine
|
yii2-statemachine
|
The Yii2-StateMachine extension v2.x.x for Yii2 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12290
|
2024-11-21 12:44 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|