|
246261
|
8.1 |
HIGH
Network
|
cybozu
|
remote_service_manager
|
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2018-16170
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246262
|
8.8 |
HIGH
Network
|
cybozu
|
remote_service_manager
|
Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-16169
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246263
|
9.8 |
CRITICAL
Network
|
jpcert
|
logontracer
|
LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors.
|
CWE-94
Code Injection
|
CVE-2018-16168
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246264
|
9.8 |
CRITICAL
Network
|
jpcert
|
logontracer
|
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2018-16167
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246265
|
8.8 |
HIGH
Network
|
jpcert
|
logontracer
|
LogonTracer 1.2.0 and earlier allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
|
CWE-611
XXE
|
CVE-2018-16166
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246266
|
6.1 |
MEDIUM
Network
|
jpcert
|
logontracer
|
Cross-site scripting vulnerability in LogonTracer 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16165
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246267
|
5.4 |
MEDIUM
Network
|
web-dorado
|
event_calendar_wd
|
Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16164
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246268
|
6.5 |
MEDIUM
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
A missing check for JS-simulated input events in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to download arbitrary files with no user input via a crafted HTML page.
|
CWE-20
Improper Input Validation
|
CVE-2018-16088
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246269
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Lack of proper state tracking in Permissions in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-16087
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246270
|
8.8 |
HIGH
Network
|
google
|
chrome
|
A use after free in ResourceCoordinator in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2018-16085
|
2024-11-21 12:52 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|