|
247601
|
5.3 |
MEDIUM
Network
|
electrum
|
bitcoin_wallet
|
Electrum Technologies GmbH Electrum Bitcoin Wallet version prior to version 3.0.5 contains a Missing Authorization vulnerability in JSONRPC interface that can result in Bitcoin theft, if the user's w…
|
CWE-862
Missing Authorization
|
CVE-2018-1000022
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247602
|
5.0 |
MEDIUM
Network
|
git-scm
|
git
|
GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be explo…
|
CWE-20
Improper Input Validation
|
CVE-2018-1000021
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247603
|
6.1 |
MEDIUM
Network
|
open-emr
|
openemr
|
OpenEMR version 5.0.0 contains a Cross Site Scripting (XSS) vulnerability in open-flash-chart.swf and _posteddata.php that can result in . This vulnerability appears to have been fixed in 5.0.0 Patch…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000020
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247604
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
OpenEMR version 5.0.0 contains a OS Command Injection vulnerability in fax_dispatch.php that can result in OS command injection by an authenticated attacker with any role. This vulnerability appears …
|
CWE-78
OS Command
|
CVE-2018-1000019
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247605
|
3.6 |
LOW
Local
|
python canonical
|
python ubuntu_linux
|
Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 may also be vulnerable and it appears that Python 2.7.17 and prior may also be …
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2018-1000030
|
2024-11-21 12:39 |
2018-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247606
|
7.8 |
HIGH
Local
|
gnu canonical redhat
|
glibc ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server virtualization_host enterprise_linux_server_tus enterprise_linux_server_eus en…
|
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-1000001
|
2024-11-21 12:39 |
2018-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247607
|
8.8 |
HIGH
Network
|
atom
|
electron
|
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that…
|
CWE-78
OS Command
|
CVE-2018-1000006
|
2024-11-21 12:39 |
2018-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247608
|
9.8 |
CRITICAL
Network
|
haxx debian canonical redhat fujitsu
|
curl debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus m10-1_firm…
|
libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of headers first to the hos…
|
NVD-CWE-noinfo
|
CVE-2018-1000007
|
2024-11-21 12:39 |
2018-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247609
|
9.1 |
CRITICAL
Network
|
haxx debian canonical
|
libcurl debian_linux ubuntu_linux
|
libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pull/2231) that reading an HTTP/2 trailer could mess…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-1000005
|
2024-11-21 12:39 |
2018-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247610
|
7.8 |
HIGH
Local
|
ovirt
|
ovirt-hosted-engine-setup
|
An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-1000018
|
2024-11-21 12:39 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|