|
246531
|
5.5 |
MEDIUM
Local
|
intel
|
quickassist_technology_for_linux
|
Improper configuration of hardware access in Intel QuickAssist Technology for Linux (all versions) may allow an authenticated user to potentially enable a denial of service via local access.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-12206
|
2024-11-21 12:44 |
2018-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246532
|
4.2 |
MEDIUM
Physics
|
avantimarkets
|
market_card
|
A vulnerability in the UPC bar code of the Avanti Markets MarketCard could allow an unauthenticated, local attacker to access funds within the customer's MarketCard balance, and also could lead to Cu…
|
CWE-200
Information Exposure
|
CVE-2018-12076
|
2024-11-21 12:44 |
2018-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246533
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possible buffer overflow in WLAN function due to lack of input validation in values received…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-11905
|
2024-11-21 12:44 |
2018-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246534
|
5.5 |
MEDIUM
Local
|
intel
|
integrated_performance_primitives
|
Data leakage in cryptographic libraries for Intel IPP before 2019 update1 release may allow an authenticated user to potentially enable information disclosure via local access.
|
CWE-200
Information Exposure
|
CVE-2018-12155
|
2024-11-21 12:44 |
2018-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246535
|
7.5 |
HIGH
Network
|
asustor
|
data_master
|
Denial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in the title.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12319
|
2024-11-21 12:44 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246536
|
8.8 |
HIGH
Network
|
asustor
|
data_master
|
Information disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext.
|
CWE-200
Information Exposure
|
CVE-2018-12318
|
2024-11-21 12:44 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246537
|
8.8 |
HIGH
Network
|
asustor
|
data_master
|
OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST parameter.
|
CWE-78
OS Command
|
CVE-2018-12317
|
2024-11-21 12:44 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246538
|
8.8 |
HIGH
Network
|
asustor
|
data_master
|
OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST parameter.
|
CWE-78
OS Command
|
CVE-2018-12316
|
2024-11-21 12:44 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246539
|
6.5 |
MEDIUM
Network
|
asustor
|
data_master
|
Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without entering the current password.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2018-12315
|
2024-11-21 12:44 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246540
|
7.5 |
HIGH
Network
|
asustor
|
data_master
|
Directory Traversal in downloadwallpaper.cgi in ASUSTOR ADM version 3.1.1 allows attackers to download arbitrary files by manipulating the "file" and "folder" URL parameters.
|
CWE-22
Path Traversal
|
CVE-2018-12314
|
2024-11-21 12:44 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|