|
247701
|
4.8 |
MEDIUM
Network
|
fxc
|
fxc5210_firmware fxc5218_firmware fxc5224_firmware fxc5426f_firmware fxc5428_firmware fxc5210pe_firmware fxc5218pe_firmware fxc5224pe_firmware ae1021_firmware ae1021pe_firm…
|
Cross-site scripting vulnerability in multiple FXC Inc. network devices (Managed Ethernet switch FXC5210/5218/5224 firmware prior to version Ver1.00.22, Managed Ethernet switch FXC5426F firmware prio…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0679
|
2024-11-21 12:38 |
2018-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247702
|
8.1 |
HIGH
Network
|
cybozu
|
garoon
|
Directory traversal vulnerability in Cybozu Garoon 3.5.0 to 4.6.3 allows authenticated attackers to read arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2018-0673
|
2024-11-21 12:38 |
2018-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247703
|
5.9 |
MEDIUM
Network
|
openssl canonical debian nodejs netapp oracle
|
openssl ubuntu_linux debian_linux node.js cn1610_firmware cloud_backup oncommand_unified_manager steelstore santricity_smi-s_provider snapcenter storage_automation_store…
|
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in Ope…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2018-0734
|
2024-11-21 12:38 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247704
|
5.9 |
MEDIUM
Network
|
openssl canonical debian nodejs netapp oracle
|
openssl ubuntu_linux debian_linux node.js cn1610_firmware cloud_backup oncommand_unified_manager steelstore santricity_smi-s_provider element_software snapdrive smi-s…
|
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in O…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2018-0735
|
2024-11-21 12:38 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247705
|
7.5 |
HIGH
Network
|
cisco
|
wireless_lan_controller_software
|
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker t…
|
CWE-20
Improper Input Validation
|
CVE-2018-0443
|
2024-11-21 12:38 |
2018-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247706
|
7.5 |
HIGH
Network
|
cisco
|
wireless_lan_controller_software
|
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol component of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker t…
|
NVD-CWE-noinfo
|
CVE-2018-0442
|
2024-11-21 12:38 |
2018-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247707
|
7.4 |
HIGH
Adjacent
|
cisco
|
access_points
|
A vulnerability in the 802.11r Fast Transition feature set of Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-0441
|
2024-11-21 12:38 |
2018-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247708
|
6.5 |
MEDIUM
Network
|
cisco
|
wireless_lan_controller_software
|
A vulnerability in the web-based interface of Cisco Wireless LAN Controller Software could allow an authenticated, remote attacker to view sensitive information. The issue is due to improper sanitiza…
|
CWE-22
Path Traversal
|
CVE-2018-0420
|
2024-11-21 12:38 |
2018-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247709
|
7.8 |
HIGH
Local
|
cisco
|
wireless_lan_controller_software wireless_lan_controller
|
A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to perform certain operations within the GUI that are not norma…
|
NVD-CWE-noinfo
|
CVE-2018-0417
|
2024-11-21 12:38 |
2018-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247710
|
6.8 |
MEDIUM
Adjacent
|
cisco
|
aironet_access_points
|
A vulnerability in the Cisco Aironet Series Access Points (APs) software could allow an authenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of s…
|
CWE-667
Improper Locking
|
CVE-2018-0381
|
2024-11-21 12:38 |
2018-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|