|
247051
|
8.8 |
HIGH
Network
|
miniupnp_project
|
ngiflib
|
The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-10677
|
2024-11-21 12:41 |
2018-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247052
|
9.8 |
CRITICAL
Network
|
tbkvision
|
tbk-dvr4216_firmware tbk-dvr4104_firmware
|
CeNova, Night OWL, Novo, Pulnix, QSee, Securus, and TBK Vision DVR devices allow remote attackers to download a file and obtain sensitive credential information via a direct request for the download.…
|
NVD-CWE-noinfo
|
CVE-2018-10676
|
2024-11-21 12:41 |
2018-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247053
|
7.8 |
HIGH
Local
|
linux redhat canonical
|
linux_kernel enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_eus vir…
|
The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafte…
|
CWE-416
Use After Free
|
CVE-2018-10675
|
2024-11-21 12:41 |
2018-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247054
|
6.1 |
MEDIUM
Network
|
ilias
|
ilias
|
ILIAS 5.3.4 has XSS through unsanitized output of PHP_SELF, related to shib_logout.php and third-party demo files.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10665
|
2024-11-21 12:41 |
2018-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247055
|
7.5 |
HIGH
Network
|
matrix
|
synapse
|
Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/me…
|
CWE-20
Improper Input Validation
|
CVE-2018-10657
|
2024-11-21 12:41 |
2018-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247056
|
7.2 |
HIGH
Network
|
combodo
|
itop
|
Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-…
|
CWE-94
Code Injection
|
CVE-2018-10642
|
2024-11-21 12:41 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247057
|
9.8 |
CRITICAL
Network
|
meross
|
mss110_firmware
|
Meross MSS110 devices through 1.1.24 contain an unauthenticated admin.htm administrative interface.
|
CWE-287
Improper Authentication
|
CVE-2018-10544
|
2024-11-21 12:41 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247058
|
8.8 |
HIGH
Network
|
hrsale_project
|
hrsale
|
A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.
|
CWE-20
Improper Input Validation
|
CVE-2018-10260
|
2024-11-21 12:41 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247059
|
7.8 |
HIGH
Local
|
safervpn
|
safervpn
|
SaferVPN 4.2.5 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "SaferVPN.Service" service. The "SaferVPN.Service" service executes "openvpn.exe" using OpenVPN config files…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10647
|
2024-11-21 12:41 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247060
|
7.8 |
HIGH
Local
|
cyberghostvpn
|
cyberghost
|
CyberGhost 6.5.0.3180 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "CG6Service" service. This service establishes a NetNamedPipe endpoint that allows arbitrary ins…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10646
|
2024-11-21 12:41 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|