|
246361
|
7.5 |
HIGH
Network
|
dnnsoftware
|
dotnetnuke
|
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
|
CWE-331
Insufficient Entropy
|
CVE-2018-15812
|
2024-11-21 12:51 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246362
|
9.8 |
CRITICAL
Network
|
actiontec
|
web6000q_firmware
|
On Telus Actiontec WEB6000Q v1.1.02.22 devices, an attacker can login with root level access with the user "root" and password "admin" by using the enabled onboard UART headers.
|
CWE-662
Improper Synchronization
|
CVE-2018-15555
|
2024-11-21 12:51 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246363
|
9.8 |
CRITICAL
Network
|
lexmark
|
cx82x_firmware cx860_firmware xc6152_firmware xc8155_firmware xc8160_firmware cx72x_firmware xc41x0_firmware cx92x_firmware xc92x5_firmware mx321_firmware mb2338_firmwar…
|
Various Lexmark devices have a Buffer Overflow (issue 2 of 2).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15520
|
2024-11-21 12:51 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246364
|
8.8 |
HIGH
Adjacent
|
actiontec
|
web6000q_firmware
|
An issue was discovered in the Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 devices. An attacker can statically set his/her IP to anything on the 169.254.1.0/24 subnet, and obtain…
|
CWE-269
Improper Privilege Management
|
CVE-2018-15557
|
2024-11-21 12:51 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246365
|
9.8 |
CRITICAL
Network
|
actiontec
|
web6000q_firmware
|
The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty password by using the enabled onboard UART headers.
|
CWE-287
Improper Authentication
|
CVE-2018-15556
|
2024-11-21 12:51 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246366
|
5.5 |
MEDIUM
Local
|
stopzilla
|
antimalware
|
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating the output buffer address value from IOCtl 0x8000…
|
CWE-20
Improper Input Validation
|
CVE-2018-15735
|
2024-11-21 12:51 |
2019-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246367
|
5.5 |
MEDIUM
Local
|
stopzilla
|
antimalware
|
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating the output buffer address value from IOCtl 0x8000…
|
CWE-20
Improper Input Validation
|
CVE-2018-15734
|
2024-11-21 12:51 |
2019-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246368
|
5.5 |
MEDIUM
Local
|
stopzilla
|
antimalware
|
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a NULL Pointer Dereference vulnerability due to not validating the size of the output buffer value from …
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-15733
|
2024-11-21 12:51 |
2019-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246369
|
5.5 |
MEDIUM
Local
|
stopzilla
|
antimalware
|
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating the output buffer address value from IOCtl 0x8000…
|
CWE-20
Improper Input Validation
|
CVE-2018-15732
|
2024-11-21 12:51 |
2019-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246370
|
5.5 |
MEDIUM
Local
|
stopzilla
|
antimalware
|
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x800…
|
CWE-20
Improper Input Validation
|
CVE-2018-15731
|
2024-11-21 12:51 |
2019-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|