|
246641
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, memory allocated with devm_kzalloc is automatically released by the kernel if the probe fun…
|
CWE-415
Double Free
|
CVE-2018-11270
|
2024-11-21 12:43 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246642
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, possible buffer overflow while incrementing the log_buf of type uint64_t in memcpy function…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-11265
|
2024-11-21 12:43 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246643
|
8.8 |
HIGH
Adjacent
|
google
|
android
|
In all Android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel, radio_id is received from the FW and is used to access the buffer to copy the radio stats r…
|
CWE-129
Improper Validation of Array Index
|
CVE-2018-11263
|
2024-11-21 12:43 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246644
|
7.8 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel while trying to find out total number of partition via a non zero check, there could …
|
CWE-787 CWE-682
Out-of-bounds Write Incorrect Calculation
|
CVE-2018-11262
|
2024-11-21 12:43 |
2018-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246645
|
7.5 |
HIGH
Network
|
xovis
|
pc2r_firmware pc3_firmware pc2_firmware
|
Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2018-11720
|
2024-11-21 12:43 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246646
|
4.9 |
MEDIUM
Network
|
xovis
|
pc2r_firmware pc3_firmware pc2_firmware
|
Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow XXE.
|
CWE-611
XXE
|
CVE-2018-11719
|
2024-11-21 12:43 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246647
|
8.8 |
HIGH
Network
|
xovis
|
pc2r_firmware pc3_firmware pc2_firmware
|
Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2018-11718
|
2024-11-21 12:43 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246648
|
8.8 |
HIGH
Network
|
tencent
|
foxmail
|
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.9.115. User interaction is required to exploit this vulnerability in that the t…
|
CWE-78
OS Command
|
CVE-2018-11616
|
2024-11-21 12:43 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246649
|
7.5 |
HIGH
Network
|
mosca_project
|
mosca
|
This vulnerability allows remote attackers to deny service on vulnerable installations of npm mosca 2.8.1. Authentication is not required to exploit this vulnerability. The specific flaw exists withi…
|
CWE-185
Incorrect Regular Expression
|
CVE-2018-11615
|
2024-11-21 12:43 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246650
|
7.5 |
HIGH
Network
|
seasofsolutions
|
ip_camera_firmware
|
Information disclosure in Netwave IP camera at get_status.cgi (via HTTP on port 8000) allows an unauthenticated attacker to exfiltrate sensitive information from the device.
|
CWE-200
Information Exposure
|
CVE-2018-11654
|
2024-11-21 12:43 |
2018-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|