|
247801
|
5.9 |
MEDIUM
Network
|
canonical debian
|
ubuntu_linux advanced_package_tool
|
The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verification for the InRelease file of a fallback mirror, …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2018-0501
|
2024-11-21 12:38 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247802
|
6.7 |
MEDIUM
Local
|
cisco
|
web_security_appliance
|
A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate wi…
|
CWE-269
Improper Privilege Management
|
CVE-2018-0428
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247803
|
8.8 |
HIGH
Network
|
cisco
|
application_policy_infrastructure_controller_enterprise_module
|
A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability …
|
CWE-78
OS Command
|
CVE-2018-0427
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247804
|
7.5 |
HIGH
Network
|
cisco
|
email_security_appliance
|
A vulnerability in certain attachment detection mechanisms of Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affecte…
|
CWE-20
Improper Input Validation
|
CVE-2018-0419
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247805
|
8.6 |
HIGH
Network
|
cisco
|
ios_xr
|
A vulnerability in the Local Packet Transport Services (LPTS) feature set of Cisco ASR 9000 Series Aggregation Services Router Software could allow an unauthenticated, remote attacker to cause a deni…
|
CWE-20
Improper Input Validation
|
CVE-2018-0418
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247806
|
6.8 |
MEDIUM
Adjacent
|
cisco
|
wap121_firmware wap125_firmware wap131_firmware wap150_firmware wap321_firmware wap351_firmware wap361_firmware wap371_firmware
|
A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series Wireless Access Points and Cisco Small Business 300 Serie…
|
CWE-388
7PK - Errors
|
CVE-2018-0415
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247807
|
5.3 |
MEDIUM
Adjacent
|
cisco
|
wap121_firmware wap125_firmware wap131_firmware wap150_firmware wap321_firmware wap351_firmware wap361_firmware wap371_firmware
|
A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series Wireless Access Points and Cisco Small Business 300 Serie…
|
NVD-CWE-noinfo
|
CVE-2018-0412
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247808
|
8.6 |
HIGH
Network
|
cisco
|
web_security_appliance
|
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-0410
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247809
|
7.5 |
HIGH
Network
|
cisco
|
telepresence_video_communication_server unified_communications_manager_im_and_presence_service
|
A vulnerability in the XCP Router service of the Cisco Unified Communications Manager IM & Presence Service (CUCM IM&P) and the Cisco TelePresence Video Communication Server (VCS) and Expressway coul…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-0409
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247810
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_communications_domain_manager hosted_collaboration_solution
|
A vulnerability in Cisco Unified Communications Domain Manager Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on an affected system. The vulne…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0386
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|