|
246671
|
8.8 |
HIGH
Network
|
d-link
|
dsl-3782_firmware
|
An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'staticGet' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) us…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10750
|
2024-11-21 12:41 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246672
|
8.8 |
HIGH
Network
|
d-link
|
dsl-3782_firmware
|
An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'commit' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10749
|
2024-11-21 12:41 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246673
|
8.8 |
HIGH
Network
|
d-link
|
dsl-3782_firmware
|
An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'show' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10748
|
2024-11-21 12:41 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246674
|
8.8 |
HIGH
Network
|
d-link
|
dsl-3782_firmware
|
An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as an 'unset' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10747
|
2024-11-21 12:41 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246675
|
8.8 |
HIGH
Network
|
d-link
|
dsl-3782_firmware
|
An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'get' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using th…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10746
|
2024-11-21 12:41 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246676
|
9.8 |
CRITICAL
Network
|
axublog
|
axublog
|
Axublog 1.1.0 allows remote Code Execution as demonstrated by injection of PHP code (contained in the webkeywords parameter) into the cmsconfig.php file.
|
CWE-94
Code Injection
|
CVE-2018-10740
|
2024-11-21 12:41 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246677
|
5.5 |
MEDIUM
Local
|
2345_security_guard_project
|
2345_security_guard
|
An issue was discovered in Shanghai 2345 Security Guard 3.7.0. 2345MPCSafe.exe allows local users to bypass intended process protections, and consequently terminate process, because WM_SYSCOMMAND is …
|
NVD-CWE-noinfo
|
CVE-2018-10739
|
2024-11-21 12:41 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246678
|
6.5 |
MEDIUM
Network
|
gnome redhat opensuse
|
libgxps enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server ansible_tower leap
|
There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-10733
|
2024-11-21 12:41 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246679
|
5.4 |
MEDIUM
Network
|
datenstrom
|
yellow
|
A stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the relevance of this report because an installation accessible to untrusted users…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10726
|
2024-11-21 12:41 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246680
|
8.1 |
HIGH
Network
|
dlink
|
dir-601_firmware
|
D-Link DIR-601 A1 1.02NA devices do not require the old password for a password change, which occurs in cleartext.
|
CWE-287
Improper Authentication
|
CVE-2018-10641
|
2024-11-21 12:41 |
2018-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|