|
247971
|
4.9 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to alter setting data of session authentication via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2018-0533
|
2024-11-21 12:38 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247972
|
2.7 |
LOW
Network
|
cybozu
|
garoon
|
Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to alter setting data of the Standard database via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2018-0532
|
2024-11-21 12:38 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247973
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to view or alter an access privilege of a folder and/or notification settings via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2018-0531
|
2024-11-21 12:38 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247974
|
8.8 |
HIGH
Network
|
cybozu
|
garoon
|
SQL injection vulnerability in the Cybozu Garoon 3.5.0 to 4.2.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2018-0530
|
2024-11-21 12:38 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247975
|
8.8 |
HIGH
Adjacent
|
buffalo
|
wzr-1750dhp2_firmware
|
Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2018-0556
|
2024-11-21 12:38 |
2018-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247976
|
7.8 |
HIGH
Local
|
buffalo
|
wzr-1750dhp2_firmware
|
Buffer overflow in Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary code via a specially crafted file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-0555
|
2024-11-21 12:38 |
2018-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247977
|
8.8 |
HIGH
Adjacent
|
buffalo
|
wzr-1750dhp2_firmware
|
Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified vectors.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2018-0554
|
2024-11-21 12:38 |
2018-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247978
|
7.4 |
HIGH
Network
|
glamo
|
iremocon_wifi
|
The iRemoconWiFi App for Android version 4.1.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informat…
|
CWE-295
Improper Certificate Validation
|
CVE-2018-0553
|
2024-11-21 12:38 |
2018-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247979
|
9.8 |
CRITICAL
Network
|
lxr_project
|
lxr
|
LXR version 1.0.0 to 2.3.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2018-0545
|
2024-11-21 12:38 |
2018-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247980
|
7.2 |
HIGH
Network
|
eyrie debian
|
remctl debian_linux
|
remctld in remctl before 3.14, when an attacker is authorized to execute a command that uses the sudo option, has a use-after-free that leads to a daemon crash, memory corruption, or arbitrary comman…
|
CWE-416
Use After Free
|
CVE-2018-0493
|
2024-11-21 12:38 |
2018-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|