|
246621
|
9.8 |
CRITICAL
Network
|
moxa
|
oncell_g3150-hspa_firmware oncell_g3150-hspa-t_firmware
|
A weak Cookie parameter is used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker can brute force parameters required to bypass authentication …
|
CWE-287
Improper Authentication
|
CVE-2018-11426
|
2024-11-21 12:43 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246622
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware msm8909w_firmware msm8996au_firmware qcs605_firmware qm215_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd…
|
Improper authentication can happen on Remote command handling due to inappropriate handling of events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdra…
|
CWE-287
Improper Authentication
|
CVE-2018-11271
|
2024-11-21 12:43 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246623
|
9.8 |
CRITICAL
Network
|
emerson
|
ve6046_firmware
|
Emerson DeltaV Smart Switch Command Center application, available in versions 11.3.x and 12.3.1, was unable to change the DeltaV Smart Switches’ management password upon commissioning. Emerson releas…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-11691
|
2024-11-21 12:43 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246624
|
7.4 |
HIGH
Network
|
apache
|
hadoop
|
In Apache Hadoop 2.9.0 to 2.9.1, 2.8.3 to 2.8.4, 2.7.5 to 2.7.6, KMS blocking users or granting access to users incorrectly, if the system uses non-default groups mapping mechanisms.
|
CWE-269
Improper Privilege Management
|
CVE-2018-11767
|
2024-11-21 12:43 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246625
|
9.8 |
CRITICAL
Network
|
puppet
|
discovery
|
Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container. In version 1.4.0, a unique certificate will be generated on installation or the user will be …
|
CWE-295
Improper Certificate Validation
|
CVE-2018-11747
|
2024-11-21 12:43 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246626
|
7.8 |
HIGH
Local
|
qualcomm
|
ipq8074_firmware mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9650_firmware mdm9655_firmware msm8996au_firmware qca8081_firmware qcs605_firmware sd_210_firmware
|
Data truncation during higher to lower type conversion which causes less memory allocation than desired can lead to a buffer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-11289
|
2024-11-21 12:43 |
2019-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246627
|
5.5 |
MEDIUM
Local
|
apache
|
spark
|
When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.…
|
NVD-CWE-noinfo
|
CVE-2018-11760
|
2024-11-21 12:43 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246628
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware mdm9655_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_410_firmware sd_412_firmware sd…
|
Possible undefined behavior due to lack of size check in function for parameter segment_idx can lead to a read outside of the intended region in snapdragon automobile, snapdragon mobile and snapdrago…
|
CWE-129
Improper Validation of Array Index
|
CVE-2018-11288
|
2024-11-21 12:43 |
2019-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246629
|
9.3 |
CRITICAL
Network
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_625_firmware sd_636_firmware sda660_firmware sdm630_firmware sdm660…
|
Spoofed SMS can be used to send a large number of messages to the device which will in turn initiate a flood of registration updates with the server in snapdragon mobile and snapdragon wear in versio…
|
NVD-CWE-noinfo
|
CVE-2018-11284
|
2024-11-21 12:43 |
2019-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246630
|
8.8 |
HIGH
Adjacent
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9615_firmware mdm9625_firmware mdm9635m_firmware mdm9640_firmware mdm9645_firmware mdm9650_firmware mdm9655_firmware msm8909w_firmware<…
|
Lack of check of input size can make device memory get corrupted because of buffer overflow in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-11279
|
2024-11-21 12:43 |
2019-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|