|
246181
|
7.1 |
HIGH
Local
|
dell
|
emc_recoverpoint emc_recoverpoint_for_virtual_machines
|
Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an uncontrolled resource consumption vulnerability. A malicious boxmgmt user may potentially…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-15772
|
2024-11-21 12:51 |
2018-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246182
|
5.5 |
MEDIUM
Local
|
emc
|
recoverpoint recoverpoint_for_virtual_machines
|
Dell EMC RecoverPoint versions prior to 5.1.2.1 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an information disclosure vulnerability. A malicious boxmgmt user may potentially be able to…
|
CWE-200
Information Exposure
|
CVE-2018-15771
|
2024-11-21 12:51 |
2018-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246183
|
8.1 |
HIGH
Network
|
pivotal_software
|
bits_service
|
Cloud Foundry Bits Service Release, versions prior to 2.14.0, uses an insecure hashing algorithm to sign URLs. A remote malicious user may obtain a signed URL and extract the signing key, allowing th…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2018-15796
|
2024-11-21 12:51 |
2018-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246184
|
8.8 |
HIGH
Network
|
pivotal_software
|
operations_manager
|
Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for…
|
CWE-269
Improper Privilege Management
|
CVE-2018-15762
|
2024-11-21 12:51 |
2018-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246185
|
5.4 |
MEDIUM
Network
|
advantech
|
webaccess
|
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15707
|
2024-11-21 12:51 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246186
|
6.5 |
MEDIUM
Network
|
advantech
|
webaccess
|
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a directory traversal vulnerability in the readFile API.
|
CWE-22
Path Traversal
|
CVE-2018-15706
|
2024-11-21 12:51 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246187
|
6.5 |
MEDIUM
Network
|
advantech
|
webaccess
|
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFi…
|
CWE-22
Path Traversal
|
CVE-2018-15705
|
2024-11-21 12:51 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246188
|
8.8 |
HIGH
Adjacent
|
systemd_project debian canonical redhat
|
systemd debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_eus enterpr…
|
A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and includin…
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-15688
|
2024-11-21 12:51 |
2018-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246189
|
7.0 |
HIGH
Local
|
canonical systemd_project
|
ubuntu_linux systemd
|
A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239.
|
CWE-362
Race Condition
|
CVE-2018-15687
|
2024-11-21 12:51 |
2018-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246190
|
7.8 |
HIGH
Local
|
debian canonical systemd_project oracle
|
debian_linux ubuntu_linux systemd communications_cloud_native_core_network_function_cloud_native_environment
|
A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution an…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-15686
|
2024-11-21 12:51 |
2018-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|