|
247391
|
9.8 |
CRITICAL
Network
|
pingidentity
|
ldapsdk
|
UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, where the issue was reported and fixed contains an Incorrect Acc…
|
CWE-521
Weak Password Requirements
|
CVE-2018-1000134
|
2024-11-21 12:39 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247392
|
9.1 |
CRITICAL
Network
|
debian canonical haxx redhat oracle
|
debian_linux ubuntu_linux curl enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_manager_ops_center peoplesoft_enterprise_peopletools co…
|
A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage
|
CWE-125
Out-of-bounds Read
|
CVE-2018-1000122
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247393
|
7.5 |
HIGH
Network
|
debian canonical haxx redhat oracle
|
debian_linux ubuntu_linux curl enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_manager_ops_center peoplesoft_enterprise_peopletools co…
|
A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-1000121
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247394
|
9.8 |
CRITICAL
Network
|
debian canonical haxx redhat oracle
|
debian_linux ubuntu_linux curl enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_manager_ops_center peoplesoft_enterprise_peopletools co…
|
A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-1000120
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247395
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10 windows_server_2016
|
Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects a…
|
NVD-CWE-noinfo
|
CVE-2018-0983
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247396
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10 windows_server_2016
|
The Windows kernel mode driver in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how objects a…
|
NVD-CWE-noinfo
|
CVE-2018-0977
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247397
|
8.8 |
HIGH
Network
|
microsoft
|
sharepoint_enterprise_server
|
Microsoft SharePoint Foundation 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Mi…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0947
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247398
|
8.8 |
HIGH
Network
|
microsoft
|
project_server sharepoint_enterprise_server
|
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsof…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0944
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247399
|
2.6 |
LOW
Network
|
microsoft
|
internet_explorer
|
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Serv…
|
NVD-CWE-noinfo
|
CVE-2018-0942
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247400
|
5.5 |
MEDIUM
Local
|
microsoft
|
exchange_server
|
Microsoft Exchange Server 2016 Cumulative Update 7 and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how data is imported, aka "Microsoft Exc…
|
NVD-CWE-noinfo
|
CVE-2018-0941
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|