|
246681
|
9.8 |
CRITICAL
Network
|
dasannetworks
|
gpon_router_firmware
|
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping re…
|
CWE-78
OS Command
|
CVE-2018-10562
|
2024-11-21 12:41 |
2018-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246682
|
9.8 |
CRITICAL
Network
|
dasannetworks
|
gpon_router_firmware
|
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the…
|
CWE-287
Improper Authentication
|
CVE-2018-10561
|
2024-11-21 12:41 |
2018-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246683
|
7.8 |
HIGH
Local
|
cylance
|
cylanceprotect
|
In Cylance CylancePROTECT before 1470, an unprivileged local user can obtain SYSTEM privileges because users have Modify access to the %PROGRAMFILES%\Cylance\Desktop\log folder, the CyUpdate process …
|
CWE-59
Link Following
|
CVE-2018-10722
|
2024-11-21 12:41 |
2018-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246684
|
10.0 |
CRITICAL
Network
|
activision
|
call_of_duty_modern_warfare_2
|
Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary code via crafted packets.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-10718
|
2024-11-21 12:41 |
2018-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246685
|
8.8 |
HIGH
Network
|
miniupnp_project
|
ngiflib
|
The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 does not consider the bounds of the pixels data structure, which allows remote attackers to cause a denial of service (WritePixels heap-…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-10717
|
2024-11-21 12:41 |
2018-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246686
|
5.5 |
MEDIUM
Local
|
2345_security_guard_project
|
2345_security_guard
|
An issue was discovered in Shanghai 2345 Security Guard 3.7.0. 2345MPCSafe.exe, 2345SafeTray.exe, and 2345Speedup.exe allow local users to bypass intended process protections, and consequently termin…
|
NVD-CWE-noinfo
|
CVE-2018-10716
|
2024-11-21 12:41 |
2018-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246687
|
8.8 |
HIGH
Network
|
d-link
|
dsl-3782_firmware
|
An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'read' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10713
|
2024-11-21 12:41 |
2018-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246688
|
5.5 |
MEDIUM
Local
|
blktrace_project
|
blktrace
|
blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmap.c because the device and devno arrays are too small,…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10689
|
2024-11-21 12:41 |
2018-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246689
|
7.5 |
HIGH
Network
|
auroradao
|
idex_membership
|
The Owned smart contract implementation for Aurora IDEX Membership (IDXM), an Ethereum ERC20 token, allows attackers to acquire contract ownership because the setOwner function is declared as public.…
|
NVD-CWE-noinfo
|
CVE-2018-10666
|
2024-11-21 12:41 |
2018-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246690
|
9.8 |
CRITICAL
Network
|
long_range_zip_project
|
long_range_zip
|
In Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the lzma_decompress_buf function of stream.c, which allows remote attackers to cause a denial of service (application crash) or possi…
|
CWE-416
Use After Free
|
CVE-2018-10685
|
2024-11-21 12:41 |
2018-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|