|
246981
|
7.5 |
HIGH
Network
|
paloaltonetworks
|
expedition
|
The Expedition Migration tool 1.0.106 and earlier may allow an unauthenticated attacker to enumerate files on the operating system.
|
CWE-200
Information Exposure
|
CVE-2018-10142
|
2024-11-21 12:40 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246982
|
5.3 |
MEDIUM
Network
|
google
|
monorail
|
Google Monorail before 2018-04-04 has a Cross-Site Search (XS-Search) vulnerability because CSV downloads are affected by CSRF, and calculations of download times (for requests with duplicated column…
|
CWE-352
Origin Validation Error
|
CVE-2018-10099
|
2024-11-21 12:40 |
2018-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246983
|
6.1 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
GlobalProtect Portal Login page in Palo Alto Networks PAN-OS before 8.1.4 allows an unauthenticated attacker to inject arbitrary JavaScript or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10141
|
2024-11-21 12:40 |
2018-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246984
|
9.8 |
CRITICAL
Network
|
rust-lang
|
rust
|
The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integer Overflow to Buffer Overflow vulnerability in standard lib…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-1000810
|
2024-11-21 12:40 |
2018-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246985
|
7.5 |
HIGH
Network
|
privacyidea
|
privacyidea
|
privacyIDEA version 2.23.1 and earlier contains a Improper Input Validation vulnerability in token validation api that can result in Denial-of-Service. This attack appear to be exploitable via http r…
|
CWE-20
Improper Input Validation
|
CVE-2018-1000809
|
2024-11-21 12:40 |
2018-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246986
|
9.8 |
CRITICAL
Network
|
contiki-ng
|
contiki-ng
|
contiki-ng version 4 contains a Buffer Overflow vulnerability in AQL (Antelope Query Language) database engine that can result in Attacker can perform Remote Code Execution on device using Contiki-NG…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-1000804
|
2024-11-21 12:40 |
2018-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246987
|
5.3 |
MEDIUM
Network
|
gitea
|
gitea
|
Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appear to be exploitable via Watch a repository to rece…
|
CWE-200
Information Exposure
|
CVE-2018-1000803
|
2024-11-21 12:40 |
2018-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246988
|
5.9 |
MEDIUM
Network
|
pyopenssl_project canonical redhat
|
pyopenssl ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server gluster_storage openstack
|
Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Reference vulnerability in PKCS #12 Store that can result in Denia…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2018-1000808
|
2024-11-21 12:40 |
2018-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246989
|
8.1 |
HIGH
Network
|
pyopenssl canonical redhat
|
pyopenssl ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server openstack
|
Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free can lead to possibl…
|
CWE-416
Use After Free
|
CVE-2018-1000807
|
2024-11-21 12:40 |
2018-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246990
|
8.8 |
HIGH
Network
|
paramiko redhat debian canonical
|
paramiko enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus virtualization_host enterprise_linux_server_eus enterprise_linu…
|
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via net…
|
CWE-863
Incorrect Authorization
|
CVE-2018-1000805
|
2024-11-21 12:40 |
2018-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|