|
247081
|
5.9 |
MEDIUM
Network
|
arm debian
|
mbed_tls debian_linux
|
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuite) via a timing-based side-channel attack. This vu…
|
NVD-CWE-noinfo
|
CVE-2018-0497
|
2024-11-21 12:38 |
2018-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247082
|
7.4 |
HIGH
Network
|
dhc
|
dhc_online_shop
|
The DHC Online Shop App for Android version 3.2.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive infor…
|
CWE-295
Improper Certificate Validation
|
CVE-2018-0622
|
2024-11-21 12:38 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247083
|
7.8 |
HIGH
Local
|
logitech
|
connection_utility_software
|
Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2018-0621
|
2024-11-21 12:38 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247084
|
7.8 |
HIGH
Local
|
logitech
|
game_software
|
Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2018-0620
|
2024-11-21 12:38 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247085
|
7.8 |
HIGH
Local
|
glarysoft
|
glary_utilities
|
Untrusted search path vulnerability in the installer of Glarysoft Glary Utilities (Glary Utilities 5.99 and earlier and Glary Utilities Pro 5.99 and earlier) allows an attacker to gain privileges via…
|
CWE-426
Untrusted Search Path
|
CVE-2018-0619
|
2024-11-21 12:38 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247086
|
5.4 |
MEDIUM
Network
|
gnu debian
|
mailman debian_linux
|
Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2018-0618
|
2024-11-21 12:38 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247087
|
7.5 |
HIGH
Network
|
chama
|
memocgi
|
Directory traversal vulnerability in ChamaNet MemoCGI v2.1800 to v2.2200 allows remote attackers to read arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2018-0617
|
2024-11-21 12:38 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247088
|
6.1 |
MEDIUM
Network
|
necplatforms
|
calsos_csdx_firmware calsos_csdx\(p\)_firmware calsos_csdx\(s\)_firmware calsos_csdx\(d\)_firmware calsos_csdj-b_firmware calsos_csdj-d_firmware calsos_csdj-h_firmware calsos_csd…
|
Cross-site scripting vulnerability in NEC Platforms Calsos CSDX and CSDJ series products (CSDX 1.37210411 and earlier, CSDX(P) 4.37210411 and earlier, CSDX(D) 3.37210411 and earlier, CSDX(S) 2.372104…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0614
|
2024-11-21 12:38 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247089
|
8.8 |
HIGH
Network
|
necplatforms
|
calsos_csdx_firmware calsos_csdx\(p\)_firmware calsos_csdx\(s\)_firmware calsos_csdx\(d\)_firmware calsos_csdj-b_firmware calsos_csdj-d_firmware calsos_csdj-h_firmware calsos_csd…
|
NEC Platforms Calsos CSDX and CSDJ series products (CSDX 1.37210411 and earlier, CSDX(P) 4.37210411 and earlier, CSDX(D) 3.37210411 and earlier, CSDX(S) 2.37210411 and earlier, CSDJ-B 01.03.00 and ea…
|
CWE-269
Improper Privilege Management
|
CVE-2018-0613
|
2024-11-21 12:38 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247090
|
8.8 |
HIGH
Network
|
cybozu
|
garoon
|
SQL injection vulnerability in the Notifications application in the Cybozu Garoon 3.5.0 to 4.6.2 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2018-0607
|
2024-11-21 12:38 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|