|
246771
|
8.8 |
HIGH
Network
|
xiph.org debian redhat
|
libvorbis debian_linux enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus
|
mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-rea…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2018-10392
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246772
|
4.8 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
An issue was discovered in WUZHI CMS 4.1.0. There is XSS via the email parameter to the index.php?m=member&v=register URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10391
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246773
|
9.8 |
CRITICAL
Network
|
mcafee
|
tunnelbear
|
TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service. This service establishes a NetNamedPipe endpoint that allows arbit…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10381
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246774
|
5.4 |
MEDIUM
Network
|
vaultize
|
enterprise_file_sharing
|
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is XSS in invitation mail received from a different user, who can modify the HTML in that mail before sending it.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10213
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246775
|
5.4 |
MEDIUM
Network
|
vaultize
|
enterprise_file_sharing
|
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization leading to creation of folders within another account via a modified device value.
|
CWE-863
Incorrect Authorization
|
CVE-2018-10212
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246776
|
5.3 |
MEDIUM
Network
|
vaultize
|
enterprise_file_sharing
|
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization when listing the history of another user via a modified "vaultize_session_id" value in a cookie.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2018-10211
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246777
|
5.3 |
MEDIUM
Network
|
vaultize
|
enterprise_file_sharing
|
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. Enumeration of users is possible through the password-reset feature.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2018-10210
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246778
|
5.4 |
MEDIUM
Network
|
vaultize
|
enterprise_file_sharing
|
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is Stored XSS on the file or folder download pop-up via a crafted file or folder name.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10209
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246779
|
6.1 |
MEDIUM
Network
|
vaultize
|
enterprise_file_sharing
|
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is anonymous reflected XSS on the error page via a /share/error?message= URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10208
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246780
|
5.3 |
MEDIUM
Network
|
vaultize
|
enterprise_file_sharing
|
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. An attacker can exploit Missing Authorization on the FlexPaperViewer SWF reader, and export files that should have been restricte…
|
CWE-862
Missing Authorization
|
CVE-2018-10207
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|