|
247031
|
7.2 |
HIGH
Network
|
openmicroscopy
|
omero
|
The Open Microscopy Environment OMERO.web version prior to 5.4.7 contains an Information Exposure Through Log Files vulnerability in the login form and change password form that can result in User's …
|
CWE-200
Information Exposure
|
CVE-2018-1000633
|
2024-11-21 12:40 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247032
|
7.5 |
HIGH
Network
|
dom4j_project debian oracle redhat netapp
|
dom4j debian_linux flexcube_investor_servicing retail_integration_bus utilities_framework primavera_p6_enterprise_project_portfolio_management rapid_planning satellite_capsule
|
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents th…
|
CWE-91
Blind XPath Injection
|
CVE-2018-1000632
|
2024-11-21 12:40 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247033
|
4.3 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
The PAN-OS Management Web Interface in Palo Alto Networks PAN-OS 8.1.2 and earlier may allow an authenticated user to shut down all management sessions, resulting in all logged in users to be redirec…
|
CWE-20
Improper Input Validation
|
CVE-2018-10140
|
2024-11-21 12:40 |
2018-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247034
|
6.1 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
The PAN-OS response for GlobalProtect Gateway in Palo Alto Networks PAN-OS 6.1.21 and earlier, PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and earlier may allow an unauthenticated attacker to inject arb…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10139
|
2024-11-21 12:40 |
2018-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247035
|
5.5 |
MEDIUM
Local
|
quazip_project
|
quazip
|
QuaZIP before 0.7.6 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vu…
|
CWE-22
Path Traversal
|
CVE-2018-1002209
|
2024-11-21 12:40 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247036
|
5.5 |
MEDIUM
Local
|
sharpziplib_project
|
sharpziplib
|
SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. …
|
CWE-22
Path Traversal
|
CVE-2018-1002208
|
2024-11-21 12:40 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247037
|
5.5 |
MEDIUM
Local
|
archiver_project
|
archiver
|
mholt/archiver golang package before e4ef56d48eb029648b0e895bb0b6a393ef0829c3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an arch…
|
CWE-22
Path Traversal
|
CVE-2018-1002207
|
2024-11-21 12:40 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247038
|
5.5 |
MEDIUM
Local
|
sharpcompress_project
|
sharpcompress
|
SharpCompress before 0.21.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction.…
|
CWE-22
Path Traversal
|
CVE-2018-1002206
|
2024-11-21 12:40 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247039
|
5.5 |
MEDIUM
Local
|
dotnetzip.semverd_project
|
dotnetzip.semverd
|
DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extrac…
|
CWE-22
Path Traversal
|
CVE-2018-1002205
|
2024-11-21 12:40 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247040
|
5.5 |
MEDIUM
Local
|
adm-zip_project
|
adm-zip
|
adm-zip npm library before 0.4.9 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extrac…
|
CWE-22
Path Traversal
|
CVE-2018-1002204
|
2024-11-21 12:40 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|